Skip to main content

The AI Reality Gap: Adoption is Rising Faster than Control

September 14, 2026

For business and technology leaders, the issue is no longer whether AI will enter the organization. In most cases, it already has. 

Employees are using AI to improve productivity, vendors are embedding new capabilities into existing platforms, and security teams are testing AI-assisted approaches to attack detection and response. As Dr. James Stanger, Chief Technology Evangelist at CompTIA noted, "AI is already here. It's embedded, it's being used and sometimes chaotically." 

That reality creates a new challenge for leaders: understanding how to govern these systems as they become part of day-to-day operations. It was a central theme in a recent CompTIA-hosted webinar featuring Dr. Stanger and Simone De Luca, Chief Information Security Officer at Blastness, and Bob Morel, CEO of AIRTA Systems. 

As De Luca observes, organizations are adopting AI "much faster than previous technologies," creating new opportunities while exposing gaps in governance, security, and workforce readiness. 

“The better AI becomes, the more valuable human judgment becomes.”

—Simone De Luca, Chief Information Security Officer at Blastness

AI is becoming part of the operating model 

AI is often framed as a productivity tool, but that understates the shift underway. In cybersecurity especially, AI is beginning to influence how organizations detect threats, investigate incidents, assess risk, and manage operational complexity. 

De Luca describes AI as a “force multiplier” because it can help focus security teams on the issues that matter most, correlate threat intelligence from multiple sources, and process large amounts of security data more quickly than human teams could manage on their own. 

That matters because many security teams are already dealing with too much data, too many alerts and too little time. De Luca points to three familiar challenges in incident response, especially for small to midsize enterprises:  

  • Too much data 
  • Limited ability to scale analysis 
  • Insufficient time 

AI can help by summarizing incidents, identifying possible root causes, prioritizing threats and recommending remediation actions.  

From the perspective of security operations, Morel points out that AI is affecting security automation and response by improving anomaly detection, processing larger volumes of data, and reducing false positives. That helps position incident response as the outcome of a stronger operational pipeline, not a standalone activity.  

AI is changing the role of security professionals, not removing the need for them.  

“I don’t believe that AI will replace cybersecurity professionals,” De Luca said. “But it will definitely change how we work.”  

Tasks such as log analysis, alert triage, report generation, and data correlation are increasingly suited to automation. Higher-value work, however, still depends on people who can apply judgment, understand business context, and make risk-based decisions.  

That distinction matters for leaders under constant pressure to do more with less. AI may help scale security capability, but only if organizations understand which work should be automated, which work should be augmented, and which decisions still require human review.  

Human judgment is more valuable, not less 

As AI systems become better at generating outputs, the role of the people involved shifts. The challenge becomes determining whether the information found is accurate, relevant and appropriate. 

“Critical thinking becomes more important, not less,” De Luca said. “The better AI becomes, the more valuable human judgment becomes.” 

Many organizations still assume that more automation will naturally lead to better decisions. The reality is more complicated. Better tools can generate more output, identify patterns, and accelerate analysis, but they can't replace context, experience, or accountability. Organizations still need people who can question results, interpret tradeoffs, and understand the consequences. 

Morel frames this challenge through three increasingly common approaches to human involvement in AI systems: 

  • Human in the loop – people review and approve decisions before action is taken 
  • Human on the loop – people supervise the AI system while it operates 
  • Human out of the loop – autonomous agents review data and take action without direct human intervention 

As Morel notes, increasing autonomy does not eliminate responsibility. The further an organization moves toward autonomy, the more important ownership becomes. If an AI system creates risk, exposes sensitive data, or produces an unintended outcome, a clear line of responsibility is still needed. 

This becomes especially important in cybersecurity, where attackers are using AI to increase the speed and scale of their activity. Defenders need to move faster without surrendering decision-making entirely to automation. 

Organizations don't need fewer people involved in decisions. They need people focused on the decisions where experience, context, and judgment matter most. 

Governance can't just be added at the end 

De Luca’s advice is direct: AI shouldn’t be treated only as a technology project. Governance, security, data protection, and risk management need to be considered from the beginning.  

That starts with visibility. 

Before organizations can manage AI risk, they need to know where AI is being used, what data it can access, who owns the system and what level of risk it introduces. De Luca emphasized the need for an AI inventory that includes both software already in use and AI systems being built internally.  

This foundation then makes other control decisions possible. It helps organizations define acceptable use, evaluate data exposure, assign ownership, and determine which systems require stronger oversight. 

The most immediate governance priorities include: 

  • Maintaining an inventory of AI-enabled tools and systems 
  • Establishing companywide AI policies and employee education 
  • Applying identity and access management controls to AI systems and agents 
  • Adapting data classification, encryption, and data loss prevention controls for AI use cases 

Governance succeeds when it becomes part of day-to-day operations rather than a separate compliance exercise. AI can support that effort by helping teams review policies, identify gaps, summarize assessments, and prepare documentation.  

Morel cautions against turning governance into a purely automated exercise. As he puts it, "the process is more important than the accreditation." Organizations learn by evaluating their security posture, identifying weaknesses, and challenging assumptions. If AI removes that learning process entirely, they may appear compliant without becoming more secure. 

For leaders, the takeaway is that AI governance is now part of responsible operations. Leaders need enough fluency to understand risk, ask better questions, and ensure that innovation doesn't move faster than accountability. 

AI literacy may be the missing piece 

Organizations often focus on platforms and policies when discussing AI readiness. But successful adoption also depends on people understanding how to use AI responsibly, evaluate outputs critically, and apply the technology appropriately within their roles. 

That learning curve is real. Some employees are experienced AI users while others may be just beginning to experiment. Morel notes that "everyone is learning AI on the go," making it important for organizations to create an environment where employees feel comfortable experimenting, asking questions, and learning from mistakes. Over time, the goal shifts from using AI only to generate an output to using it as part of a workflow where people still evaluate, challenge and ultimately own the result. 

For many organizations, building that capability starts with AI literacy. Programs such as CompTIA AI Essentials help employees develop a practical understanding of AI concepts, risks, and responsible use. For cybersecurity professionals, CompTIA SecAI+ extends those concepts into areas such as securing AI systems, using AI in security operations, and governing AI-enabled environments. 

Effective training develops the judgment needed to work alongside rapidly evolving technologies. As AI becomes more deeply integrated into business operations, organizations that only invest in tools may find themselves with more technology than expertise. Organizations that invest in workforce development are better positioned to use AI with purpose, discipline, and confidence. 

AI readiness is becoming a leadership responsibility 

Organizations are moving quickly to adopt AI because the value is increasingly visible. AI can help security teams process more data, reduce repetitive work, accelerate incident response, support governance activities, and make complex operations more manageable. 

But adoption and preparedness are not the same thing. 

Morel emphasizes that successful AI adoption is not about adding more technology. The organizations that gain the most value are likely to be the ones that integrate AI thoughtfully into existing processes, understand their exposure, establish clear ownership, protect sensitive information, and give employees the skills to challenge outputs rather than simply accept them. 

AI can improve efficiency by helping people see patterns faster. But it doesn’t remove the need for leadership, accountability, or human understanding.  

Most organizations won’t have every answer before they move forward. What matters more is having clear ownership, practical guardrails, and people who understand both the opportunities and the risks. As AI becomes more deeply embedded in business operations, those organizational capabilities will matter as much as the technology itself. 

 

Watch the full recording to hear more from James Stanger, Simone De Luca and Bob Morel on AI governance, cybersecurity and workforce readiness.  
 
Then contact us for practical guidance on building the skills, judgment and operational discipline needed for responsible AI adoption.