In July 2026, ISC2 published its latest paper in its range of Peer-Sourced Technical Guidance, Making Automated Security Decisions Defensible, investigating how the adoption of Artificial Intelligence (AI) is growing much faster than the maturity – or even basic existence – of the governance around how AI is used within organizations. The content is based on the output of an ISC2 Technical Guidance workshop held in May 2026 and made up of members across the ISC2 community.

How to govern AI – and the pitfalls many organizations are experiencing trying to do it themselves – is a major consideration for cybersecurity professionals. The workshop tackled this head on, with a focus on governance challenges about using AI for security operations automation and, particularly, to make security decisions. Rather than discussing the security of general business AI, it examines the corporate and personal impact of AI being allowed to “do security”.

AI is already heavily used to support cybersecurity efforts. In particular, to identify potential threats and help find useful information that is hiding in the depths of large quantities of logging and monitoring data. More recently, though, it is being used more and more to initiate security decisions, which means that the evolving risk of AI is not that it misses an alert it should have spotted, but that it takes an action that has a detrimental effect on businesses’ ability to trade.

One of the stark attributes of the paper is that its conclusions are based on largely unequivocal responses. For example, almost everyone in the group said they had experienced negative outcomes when their security AI made a decision; at the other end, almost nobody could honestly claim to have their processes fully documented and defensible.

The paper looks at the increased risk that results from the attitude of the “C Suite” to AI – namely that it increased operational efficiency, makes good things happen more quickly, reduces the need for multiple layers of approval and generally causes fewer people to be aware of an action before it happens. In short, agility gives way to risk – and the speed at which AI can make decisions is, of course, far greater than would be the case with human-influenced decision-making.

The flexibility – or lack of it – in AI-influenced security tools is also investigated. All security tools have an element of configurability which allows engineers and cybersecurity specialists to tune them to fit the company’s requirements. In many cases, it was noted that with AI tools, it was common for functional parameters to be configured before and during deployment. It was far less usual for continuous revision and adjustment to be done on tools once they were in operation.

Understandably, the paper also considers the ethics of allowing AI to make decisions on security matters. Many reading this will have fallen victim to an automated defense system – not even necessarily an AI-based one – detecting a false positive and quarantining a file, an application, a PC or even a server. But what about considerations of the fairness and personal impact of, for example, AI wrongly isolating a user’s login and alerting security teams and potentially others that suspicious activity had been seen under that user ID? Service outages affect businesses, but some security actions impact people.

Regarding the advice the paper gives, the outputs are split into six key categories. Each defines the context of the subject area, describes the challenge we face, elucidates the risk derived from the situation, and then presents practical advice on the types of action we can take.

The list begins with governance and accountability (the latter of which is often assumed rather than explicitly defined), which leads neatly into the second area – documentation and auditability. Area three investigates the challenge of identifying and defining the boundary between where AI can be allowed to make decisions and where human input needs to be part of the process. Next is a problem that many, many organizations' security teams face – “Shadow AI,” where users and departments adopt AI without consulting the IT or security teams at all. A discussion of threat modeling comes next, before the list is completed with some comment and guidance on ethical decision making.

Making Automated Security Decisions Defensible is available to all ISC2 members at https://www.isc2.org/members/Peer-Sourced-Guidance. Be sure to log in to your member or associate account to access this paper, as well as the other peer-sourced documents that have been released.

From Our Members and their Peers

This paper, as with the others ISC2 publishes, comes entirely from thoughts, ideas and observations of ISC2 members – in this case primarily via a workshop but also often through surveys and/or direct interaction. The members involved work in a variety of markets and organizations.

Papers are available by signing into your account, visiting the Member Benefits link and selecting the Resources filter at the top of the page. Alternatively, you can go to the Peer-Sourced Guidance Documents page to view this and the collection of other papers in the series.

Related Insights