July 27, 2026

    If I Could Only Use AI for Three Things in Security

    If someone told me I could only use AI for three things, and everything else was off the table, I know exactly what I'd keep. And I want to point out something about the list before I get to it: not one of them is "go have AI do magic."

    That's what most AI conversations get wrong. The pitch is usually some autonomous thing that runs your security program while you sleep. My list is the opposite. Every item is about augmenting yourself or your team. That's the most valuable thing you can do first, and honestly it's the thing that pays off long before any fully autonomous anything is worth trusting with your environment.

    Here's what I'd keep.

    1. Build the one thing you never have time for.

    Every security person has a mental list of stuff they'd build if they had a free week. The script that diffs your firewall rules and flags what changed. The little tool that cross-references your MDM inventory against your identity provider. The Monday report you assemble by hand every single week.

    You never build it, because it's never the fire that's burning today.

    AI collapses the cost of the first working version. It doesn't have to be production-grade, and it doesn't have to be pretty. It has to remove a recurring chore from your week so you get that time back for the work only you can do. That is a real, compounding dent in the grind, and it's available to you right now.

    2. Audit the thing you assume is already true.

    This one is my favorite, because it goes straight at the scariest part of the job.

    Every one of us is carrying around a list of things we believe are true but have never actually verified. MFA is on for everyone. There are no dormant admin accounts. Every endpoint is actually reporting in. That legacy box really did get decommissioned. We assume these are closed, and we move on.

    The scariest gaps aren't the ones you're actively hunting. They're the ones you assumed were handled.

    Point AI at an API or a script against your identity provider, your MDM, your network controls, whatever it is, and pull the real data. Have it parse and cross-check the thing you need to be one hundred percent sure about. You either confirm it and sleep better, or you find out it's not true and you go fix it today. Either outcome is a win. The only losing move is continuing to assume.

    3. Brainstorming and thinking out loud

    This one is underrated, and I think it's because it doesn't produce an artifact, so people don't count it as real work.

    Having a huge amount of tokenized text at your disposal is genuinely useful for refining an idea or surfacing something you wouldn't have thought of on your own. Threat-model a new vendor before you sign. Pressure-test an incident runbook. Ask "what am I not considering before I open this port?" It never gets tired of the boring middle of a problem, which is exactly where you get tired and start cutting corners.

    It's not that it knows more than you. It's that it's a patient sparring partner who will go ten rounds on a question you'd otherwise answer with a shrug.

    The common thread

    Look at the three again. Build it. Verify it. Think it through. In every case, you are still in the driver's seat. You decide what to build, you decide what to trust, you decide what to do about what you find. None of it is "hand over the keys and hope."

    That's not an accident, and it's not caution for its own sake. It's that augmenting a sharp person or a good team is where the real, immediate value is. The magic-autonomy story might get there eventually. But the leverage you can grab this week is in making yourself and your team faster, more certain, and harder to surprise.

    Start there. Build the thing, verify the assumption, and use it to think. The rest can wait.

    Tag(s): Featured

    Mike Toole

    Mike Toole, Head of Security and IT at Blumira, has over a decade of experience in IT. Prior to joining Blumira, he managed IT for Duo Security and Censys. He has broad experience with a range of IT and security focus areas, including compliance, network design, log monitoring, project management, and cross-platform...

    More from the blog

    View All Posts