AI Is Breaking Security Operations – Compliance Isn’t Helping

Security leaders are getting squeezed from two directions at once. AI is accelerating vulnerability discovery faster than teams can respond, while regulators and boards demand more proof that controls actually work. Something has to give.

In a recent Rapid7 podcast, VP of Global Government Affairs Sabeen Malik broke down the problem. The systems most security teams rely on were designed for human-led discovery. Disclosure processes, scoring systems, and prioritization frameworks all assume organizations have time to assess and respond. AI doesn’t respect that assumption.

The policy question is straightforward but hard to answer: if AI can find and chain vulnerabilities faster, can the ecosystem responsibly validate and act on what comes out? Access to powerful models helps. But access without governance just creates more noise for teams that are already overwhelmed.

There’s a compliance angle too. Organizations aren’t being asked to prove readiness once a year anymore. They need to provide evidence on shorter timelines across more requirements. Static reports don’t cut it. Leaders need to show what changed, what got fixed, who owns it, and what risk remains.

Malik’s take: the future is AI-driven but human-led. Automation handles the repetitive work – classifying alerts, compiling evidence, surfacing next steps. Humans focus on decisions that require judgment. That’s the balance most teams are trying to find right now.