News

Why AI automation needs human judgement in cybersecurity

Cyprus Mail · 2026-08-03

AI SUMMARY

• What happened: A recent analysis by Shilpi Handa from IDC emphasizes the growing need for human oversight in verifying AI outputs, especially in cybersecurity, as AI systems take on more autonomous roles. • Why it matters: The reliance on AI in critical sectors raises concerns about the erosion of essential human skills and the potential risks associated with automated decision-making, highlighting the importance of human judgment in ensuring safety and accountability. • What to watch next: The development of new frameworks, such as "AI Validation-as-a-Service" and the "AI Judgement Quotient," alongside regulatory requirements like the EU AI Act, will shape the future of human oversight in AI-driven environments, with a compliance deadline set for December 2027.

**Why AI Automation Needs Human Judgement in Cybersecurity**

As artificial intelligence (AI) continues to permeate various industries, the conversation around its implications often centers on the risks of job displacement and revenue compression. However, a recent analysis by Shilpi Handa, associate research director at market intelligence firm IDC, highlights an equally critical aspect that is frequently overlooked: the increasing demand for human oversight in verifying AI outputs, particularly in the realm of cybersecurity.

Handa's analysis argues that while AI is indeed taking over routine tasks, it simultaneously creates a pressing need for skilled individuals who can evaluate the results produced by these systems. This duality of AI's impact is essential to understand, especially as industries adopt these technologies at scale.

Historically, discussions about automation have emphasized the potential for reduced headcounts and altered business models. Handa points out that this narrative is incomplete, as it fails to address the complexity that arises when humans are tasked with supervising automated systems. She references a 1983 study by cognitive psychologist Lisanne Bainbridge, which concluded that greater automation often leads to more demanding human roles. Bainbridge's research indicated that as systems become more automated, humans are left to manage rare and complex situations, which can lead to skill deterioration over time.

A poignant example of this phenomenon is the 1987 crash of Northwest Airlines Flight 255, which resulted in the deaths of 154 people. The accident was attributed to pilots relying on an automated system that failed, leaving them unaware of critical configuration errors. This incident underscores the dangers of over-reliance on automation and the erosion of essential skills among operators.

In today's context, similar trends are emerging in sectors such as law and software engineering. For instance, junior lawyers increasingly depend on AI for tasks like research and drafting, raising concerns that they may not be developing the necessary judgment to assess AI-generated work effectively. In software engineering, surveys indicate that junior developers often lack the foundational knowledge required to evaluate AI-generated code, leading to a reliance on outputs they cannot adequately assess.

This situation raises a critical question: who will validate AI outputs as automation expands? Handa emphasizes that this issue is particularly pressing in cybersecurity, where AI systems are already functioning autonomously in live environments. Security operations platforms are evolving from assistant models to fully autonomous systems that operate independently, often notifying human teams only after decisions have been made. This shift has led to security teams admitting that they frequently override AI-generated recommendations rather than act on them.

On the offensive side, AI-driven penetration testing tools are identifying vulnerabilities more rapidly than human testers, yet they inundate systems with reports that are challenging to verify. Some bug bounty platforms have even paused their programs due to an influx of AI-assisted submissions, while open-source projects have halted initiatives in response to a surge of low-quality reports.

To address this "validation gap," Handa proposes two concepts. The first is "AI Validation-as-a-Service," which involves independent human verification of AI decisions to ensure outputs align with reality and meet accountability standards. The second concept, "AI Judgement Quotient" (AJQ), is defined as an individual’s capability to discern when to trust or challenge AI outputs, distinguishing it from the ability to effectively prompt AI systems.

Regulatory frameworks are also anticipated to drive the demand for these capabilities. The EU AI Act, for instance, categorizes certain cybersecurity systems as high-risk when employed in critical infrastructure, mandating genuine human oversight. This oversight must extend beyond theoretical frameworks to practical applications, ensuring that humans can monitor, comprehend, and override AI decisions. Handa notes that regulators will not be satisfied with mere assurances of safety measures, such as the existence of a kill switch.

The compliance deadline for these regulatory requirements has been extended to December 2027, providing organizations with additional time to establish credible verification mechanisms. Handa concludes that a new market is emerging at the intersection of autonomous AI decision-making, declining human expertise, and regulatory scrutiny. As AI continues to make unsupervised security decisions in production environments, the race is on to determine who will develop the necessary human oversight capabilities first.

In summary, as AI technologies advance, the need for human judgment in verifying AI outputs becomes increasingly critical, particularly in cybersecurity. The balance between automation and human oversight will be crucial in ensuring the safety and reliability of systems that are integral to modern infrastructure.

Source: Cyprus Mail
RELATED NEWS

More Stories

All News
News

Deputy mayor accuses Polis municipality of negligence over fires

• What happened: Dervis Charalambous, deputy mayor of Kritou Terra, accused the Polis Chrysochous municipality of negligence regarding recent fire incidents, cl...

News

Eurobank spends over €2.4m on share buyback programme

• What happened: Eurobank S.A. executed a €2.46 million share buyback program from July 27 to July 31, 2026, repurchasing 556,717 shares at an average price of ...

News

Cyprus property valuation association warns against relying on online estimates

• What happened: The Cyprus property valuation association has issued a warning against relying solely on online property valuation tools, emphasizing that thes...

News

Rescuers search for 28 missing after ferry catches fire in Indonesia’s Madura island

• What happened: A ferry, the KM Mutiara Sentosa, caught fire off Indonesia's Madura island, leading to the confirmation of five deaths and 28 people still...

News

Leaked exams, dashed dreams: Why India’s ‘cockroach’ youth turned on Modi

• What happened: Protests erupted in India against Prime Minister Modi's government after the invalidation of national medical exam results for about 2 mil...

News

Record heatwave spreads across Korean peninsula, prompting emergency response

• What happened: A record heatwave is affecting the Korean peninsula, with temperatures soaring to nearly 40°C in North Korea and reaching 42.5°C in South Korea...