The fundamental principle behind the concept of enterprise cybersecurity has long been based on a simple principle: humans monitor; humans make decisions; humans take action, usually after the damage has occurred. But today this principle is no longer true. Not because companies are reluctant to act but because adversaries are far ahead of the defence teams. Applications of generative and agentic AI have enabled cybercriminals to automate their attacks like implementing targeted phishing campaigns and using adaptive malware in real time.

The economics of cybercrime asymmetry
The financial consequences are overwhelming. A report on the Cost of Data Breaches for 2026 by IBM indicates that now 25% of malicious attacks are AI-powered, an increase of 56% compared to the previous year. Worldwide, the typical cost of such sophisticated attacks equals $6 million. The average cost of a data breach in India has reached an unprecedented level – INR 25.5 crore. The economics of cybercrime are changing in favour of criminals since they can develop exploits in a few seconds at a low price but businesses have to spend millions to recover from them. The traditional human-centred perimeter is not merely weak. It is completely outdated.
Millennial advancements made in technology notwithstanding, enterprise technology leaders must embrace an essential change from conventional security operations that rely heavily on human input to proactive automated security operations.
The Persistent Vulnerability: Human Factor
Even though organizations invest significantly in advanced security solutions and programs aimed at raising cyber security awareness, the human factor remains one of the main risks. According to the 2026 Verizon Data Breach Investigations Report (DBIR), 62% of data breaches are a result of human actions, be it a malicious click, a socially engineered phone call, or misconfigured credentials.
This vulnerability has only been exacerbated by the rise of AI. Cybercriminals are evolving from traditional email phishing to using large language models (LLMs) to conduct hyper-realistic voice and SMS-based social engineering campaigns that bypass human scepticism. It’s a losing battle to ask a human analyst to sift through thousands of alerts a day, find a subtly compromised credential, and contain a threat before lateral movement occurs.
The Rise of Machine Autonomy and Pre-emptive Defence
Artificial Intelligence is not merely a tool for threat actors; it is a defensive force multiplier. We are witnessing a critical transition in enterprise cyber from legacy Detection and Response (DR) frameworks to pre-emptive, autonomous defence systems.
Gartner predicts a seismic shift in enterprise resource allocation, estimating that pre-emptive cybersecurity solutions will account for over 50% of IT security spending by 2030- up from less than 5% in 2024. The development of the Autonomous Cyber Immune System (ACIS) has come about as a result of this change. AI-powered ACIS employs predictive threat intelligence to predict, alter and neutralize attacks without human intervention. Autonomous cyber defence makes good business sense for a couple of reasons. According to IBM Report, companies that use the technology can save on average $2 million for every cyber-attack. Industry estimates put the average time for AI-led detection at 108 days. This is a big number considering that the current response time in the industry is about 277 days.
Addressing the Challenges: Shadow AI and Adversarial Risks
The emergence of machine autonomy has opened up a new array of difficulties that Chief Information Officers (CIOs) must manage:
- Shadow Artificial Intelligence Problem: The introduction of generative AI hasincreased the level of risk of insider threats. According to the Verizon Data Breach Investigations Report, 2026, about 67 percent of employees use AI technology through non-business accounts on business devices, creating data leakage risks.
- Adversary Artificial Intelligence and Data Poisoning: The AI models will become a target for attackers. Security frameworks need to be modernized to guard against prompt injection, model evasion and data poisoning aimed at duping autonomous defences.
- Gaps in Explanation:An autonomous system can malfunction at times and create false alarms or take serious action (like, isolating an important server) that can impact a business. Teams require knowledge of “explainable AI” to gain insight into the reasons and triggers behind each of these automated actions.
Future Strategies: The Human-Machine Partnership
The future of corporate cybersecurity will be based on the best possible alliance between machines and humans. This means three important actions:
- Agentic AI in everylifecycle:To stay ahead, AI needs to be “agentic”. It should be capable of analysing, prioritizing and performing remediation workflows on its own in real time. This will reduce the attacker’s window of opportunity.
- Implement AI supervision:Companies must implement stringent regulation of AI usage internally. To reduce the risks of Shadow AI and credential theft, businesses could use Single Sign-On (SSO) on their corporate generative AI instruments and proceed to implementing Zero Trust architectures.
- Adapt the role of the human analyst: As AI takes over approximately 80% of routine processing and response functions, the role of human analysts must change. People should not just suffer from “alert fatigue,” but engage in more strategic threat hunting, manage AI, and oversee challenging infrastructure operations.
Authored by Dr Jaydeep Mukherjee, Prof. of Economics at Great Lakes, Chennai
