The Growing Role of AI in Cyber Defence

Estimated reading time: 11 minutes

AI is creating new opportunities to strengthen cyber defence.

The executive challenge is ensuring that faster decisions also remain reliable, accountable and aligned with business risk.

Artificial intelligence is changing both sides of cybersecurity. Malicious actors are increasingly using AI to accelerate reconnaissance, vulnerability discovery and other cyber activities. At the same time, cybersecurity teams can use the same advances to analyse information faster, prioritise risks, identify threats and support incident response.

On 12 August 2026, New Zealand's National Cyber Security Centre published Opportunities for AI in Cyber Defence, guidance co-authored with cybersecurity authorities in Australia, Canada and the United Kingdom. The guidance describes how AI can support six cybersecurity functions: Govern, Identify, Protect, Detect, Respond and Recover.

The underlying multinational guidance was first published by Australia's Cyber Security Centre on 27 May 2026. New Zealand's publication in August adds further international endorsement and reinforces the practical relevance of the recommendations for organisations across the region.

This creates an important opportunity. Cybersecurity teams already face large volumes of alerts, vulnerabilities, data and competing priorities. Used appropriately, AI may help them make sense of that information and act more efficiently. The leadership challenge is ensuring that faster security decisions also remain reliable, accountable and aligned with business risk.

AI can strengthen cyber defence, but its value depends on where it is applied, how it is governed and whether the cybersecurity foundations beneath it are already strong.

Source: New Zealand National Cyber Security Centre, Opportunities for AI in Cyber Defence, 12 August 2026. ncsc.govt.nz. The joint guidance was first published by the Australian Cyber Security Centre on 27 May 2026. cyber.gov.au

Where AI Can Strengthen Cyber Defence


The NCSC guidance provides an opportunity to move the AI conversation beyond seeing AI purely as a cybersecurity threat. AI can also become part of the defence.

The guidance identifies opportunities across the full cybersecurity lifecycle. AI can assist organisations with analysing supply chain risk, identifying assets, prioritising vulnerabilities, detecting suspicious activity, interpreting incident information and supporting recovery activities.

The practical value comes from augmentation rather than replacement. Security teams often need to process more information than people can reasonably assess manually. AI can help narrow that information, identify patterns and bring higher priority issues to attention sooner.

Cybersecurity FunctionHow AI Can Assist
GovernSupporting security decision making by analysing risk data, policy compliance and governance information at scale
IdentifyDiscovering assets, mapping dependencies and assessing where the organisation is exposed
ProtectStrengthening access controls, analysing configurations and identifying weaknesses before they are exploited
DetectMonitoring for suspicious activity, reducing alert fatigue and identifying patterns that human analysis may miss
RespondAccelerating incident analysis, summarising evidence and supporting faster response decisions
RecoverAssisting with recovery planning, impact assessment and restoring operations after a security event

The argument is not that every organisation should adopt AI across all of these areas immediately. The opportunity is to identify where AI can meaningfully improve an existing cybersecurity capability that the organisation already understands and manages. Organisations that start with a clear security problem and assess how AI might help are better positioned than those that introduce the technology simply because it is available.

The value of AI in cyber defence comes from augmentation rather than replacement.
The question is where it can genuinely improve an existing capability.

Speed Is Valuable, But So Is Judgement


One of AI's clearest advantages in cybersecurity is speed. That advantage matters because attackers are also becoming faster.

The Australian Cyber Security Centre notes that malicious actors are using AI to automate reconnaissance, develop attack tooling, analyse compromised data and accelerate vulnerability discovery. This can shorten the period between identifying a weakness and attempting to exploit it.

Australian guidance released on 5 August 2026 takes this further. The Australian Signals Directorate and the Australian Institute of Company Directors warn boards that frontier AI can identify vulnerabilities, combine smaller weaknesses into larger compromises and conduct malicious cyber activity with increasingly limited human involvement.

Source: Australian Signals Directorate and AICD, Frontier AI Cyber Threat Considerations for Boards of Directors, 5 August 2026. cyber.gov.au

That strengthens the business case for improving defensive speed. Organisations that can detect, analyse and respond faster are better positioned to limit damage when an incident occurs.

However, faster does not automatically mean better.

An AI system might prioritise one vulnerability over another, identify activity as suspicious, recommend an incident response action or determine that an alert deserves escalation. Those decisions may be useful. They may also be incomplete or incorrect. The more consequential the decision becomes, the more important human judgement becomes.

A system that accelerates vulnerability prioritisation is valuable. A system that autonomously isolates critical infrastructure based on a false positive is dangerous. The distinction between these two scenarios is not the technology itself. It is the level of consequence and the presence or absence of human oversight. This is exactly where AI governance becomes essential to how organisations adopt these capabilities.

The Speed and Judgement Balance

Before expanding AI across cybersecurity operations, leadership should consider a practical question:

For each activity where AI could increase speed, what is the consequence if the AI produces the wrong result?

Where the consequence is low, automation may be appropriate. Where the consequence could affect business operations, customer data, regulatory obligations or organisational reputation, human review should remain part of the process.


What Business Leaders Can Learn


Start with the cybersecurity problem. AI adoption should begin with a clear security outcome. Where is the organisation currently constrained? Perhaps vulnerability teams cannot assess findings quickly enough. Security monitoring produces too much information. Incident responders spend significant time gathering and summarising evidence. Risk teams struggle to connect technical findings with business priorities. The opportunity is to determine where AI can improve these existing processes rather than introducing AI simply because the capability is available.

AI should augment existing security capability. The ACSC guidance specifically recommends integrating AI to augment existing cybersecurity tools and processes rather than treating AI as a standalone security solution. This distinction matters. AI cannot compensate for weak access controls, poor vulnerability management, inadequate incident response or unclear governance. The technology may increase the speed of an existing process, but the organisation still needs confidence in the process itself. Organisations considering where AI fits within their security posture may find that a vCISO engagement helps clarify priorities before investment decisions are made.

Human oversight should reflect the consequence of the decision. Not every AI supported cybersecurity activity carries the same level of business risk. Using AI to summarise large volumes of security information is different from allowing a system to automatically change access, isolate systems or take another action that affects operations. The guidance recommends human approval for high impact actions, limiting autonomous actions to activities that are narrowly scoped and reversible, verifying AI generated outputs against evidence, and continuously monitoring AI behaviour.

The executive principle is straightforward. The greater the potential business consequence, the stronger the case for human oversight.

Accountability remains with the organisation. AI can support cybersecurity decisions, but responsibility for those decisions does not transfer to the technology. This connects directly to broader questions about AI incident governance and decision ownership that organisations are increasingly expected to address. Leadership should understand who owns AI supported security decisions, who can intervene, how unexpected outcomes are escalated and how the organisation learns when the technology produces the wrong result.

AI can support cybersecurity decisions.
Responsibility for those decisions does not transfer to the technology.

Questions Every Executive Should Ask


Executives should consider whether their organisation can confidently answer the following:

  • Where could AI meaningfully improve our existing cybersecurity capability?
  • What specific problem are we asking AI to solve?
  • What systems, information and permissions would the AI need access to?
  • Which decisions can AI support and which decisions should remain with people?
  • What happens when the AI produces an incorrect or unexpected result?
  • Who remains accountable for decisions supported by AI?
  • How will we measure whether AI is actually improving our cybersecurity outcomes?
  • Are our existing cybersecurity fundamentals strong enough to support greater automation?

If leadership cannot confidently answer these questions, the immediate priority may not be deploying more AI. It may be establishing the governance required to use it responsibly. An executive readiness review can help leadership teams identify where governance gaps exist before technology decisions are made.


From Security Automation to Defensive Capability


The broader shift is from thinking about AI as another cybersecurity tool to thinking about it as part of the organisation's overall defensive capability. This distinction matters.

A new AI capability has little value if it identifies vulnerabilities that remain unresolved. Faster threat detection provides limited benefit if escalation and incident response remain unclear. Automated analysis does not improve governance if leadership cannot understand or act on the information produced.

AI therefore creates the greatest value when it strengthens an organisation that already understands its assets, risks, responsibilities and priorities.

The Australian board guidance reinforces this point. While it identifies adopting AI for cyber defence as a medium term priority, it places immediate emphasis on cybersecurity fundamentals including reducing attack surfaces, addressing vulnerabilities and strengthening preparedness. It also states that defensive AI should be secure, controllable, human supervised, ethical and accountable.

Five Principles for Defensive AI

The Australian guidance recommends that AI adopted for cyber defence should be:

Secure in its own implementation and deployment

Controllable with clear boundaries on what it can do autonomously

Human supervised with oversight that matches the consequence of the decision

Ethical in how it processes information and affects people

Accountable with clear ownership of decisions and outcomes

The message for executives should remain balanced. AI presents a genuine opportunity to strengthen cyber defence. Realising that opportunity requires investment in the capability around the technology as well as the technology itself.

Through security leadership and vCISO advisory, SeComPass helps organisations understand how AI adoption fits within existing cybersecurity governance, risk and leadership structures. This includes assessing governance readiness, clarifying accountability, evaluating risk and ensuring that oversight keeps pace with the organisation's use of AI across business and cybersecurity processes.

AI will increasingly become part of cyber defence. The organisations that benefit most will not necessarily be those that automate the most. They will be those that understand where AI adds value, where people remain essential and how the two should work together.

Key Takeaways


  • AI can strengthen cyber defence by helping organisations analyse, prioritise and respond faster, but its value depends on strong cybersecurity foundations, clear governance and appropriate human oversight
  • Joint guidance from cybersecurity authorities in New Zealand, Australia, Canada and the United Kingdom identifies practical opportunities for AI across the full cybersecurity lifecycle, from governance through to recovery
  • The practical value of AI in cybersecurity comes from augmentation rather than replacement. AI should improve existing capabilities, not compensate for weak fundamentals
  • Speed is valuable because attackers are also becoming faster, but the more consequential the decision, the stronger the case for human oversight
  • AI can support cybersecurity decisions. Responsibility for those decisions does not transfer to the technology. Accountability, escalation and intervention must remain clearly defined
  • Before expanding AI adoption, organisations should assess whether their existing cybersecurity governance, processes and fundamentals are strong enough to support greater automation

Assess Your AI Governance Readiness

Is Your Organisation Ready to Use AI Responsibly?

The AI Governance Assessment helps leadership teams determine whether governance, accountability and oversight are keeping pace with the organisation's use of AI across business and cybersecurity operations. It includes:

  • Assessment of current AI governance maturity and accountability structures
  • Review of how AI decisions are supervised, escalated and documented
  • Identification of gaps between AI adoption and organisational readiness
  • Strategic priorities for responsible AI adoption aligned with business risk

Start by understanding whether your organisation is prepared to use AI safely and responsibly.

Start the AI Governance Assessment →

References


  • New Zealand National Cyber Security Centre. "Opportunities for AI in Cyber Defence," 12 August 2026. ncsc.govt.nz
  • Australian Cyber Security Centre. "Opportunities for AI in Cyber Defence," first published 27 May 2026. cyber.gov.au
  • Australian Signals Directorate and Australian Institute of Company Directors. "Frontier AI Cyber Threat Considerations for Boards of Directors," 5 August 2026. cyber.gov.au

This article is for general informational purposes only and does not constitute legal, technical, or professional cybersecurity advice. SeComPass recommends engaging a qualified adviser before making decisions based on this content. Guidance referenced above was current as at August 2026 and is updated periodically by relevant government and standards bodies.

Jatinder Oberoi

Founder and Principal Consultant at SeComPass, where he helps organisations across Australia and New Zealand strengthen cybersecurity, governance, risk management, and regulatory compliance. With extensive experience in information security strategy, ISO 27001, SOC 2, AI governance, privacy, and virtual CISO (vCISO) services, Jatinder works with executive teams to align cybersecurity with business objectives, improve organisational resilience, and build lasting customer trust.

https://au.linkedin.com/in/jsoberoi
Next
Next

Beyond Security: Protecting the Business