Enterprises clamp down on AI autonomy with human guardrails
The gist
Enterprises are slamming the brakes on open-ended AI in cybersecurity, letting machines handle the grunt work while humans keep their hands on the big red button.
What to know
- By September 2026, 59% of UK CISOs say attackers have the upper hand, and just 32% of organizations allow AI to remediate critical vulnerabilities without human sign-off.
- Most enterprises now restrict AI to low-risk tasks like asset discovery (55%) and vulnerability prioritization (49%), but require human approval for anything high-stakes.
- Lack of trust, compliance headaches, and the fear of AI 'hallucinations' are keeping humans firmly in charge of consequential security decisions.
Guardrails Over Autonomy
Enterprises are racing to automate security but refuse to cede control, demanding vendor accountability, auditability, and regulatory clarity before trusting AI with critical decisions.
By September 2026, the market’s center of gravity had shifted toward AI adoption with explicit guardrails rather than open-ended autonomy, a posture captured in Kai’s Sept. 21, 2026 State of Autonomous Defense Report. The report says “a growing gap is emerging between the speed of AI-powered attacks and the ability of security teams to respond” and warns that “security operations built around human speed may not be able to keep pace,” framing a mid-2026 urgency gap that pushed CISOs toward machine-led security bounded by governance and trust controls.
Kai’s survey of 100 UK CISOs showed why that guarded posture was becoming default: 59% said attackers already hold the advantage, while 94% said they were prepared but only 33% described themselves as very prepared. That caution was reinforced by operational drag—67% take more than a week to remediate critical vulnerabilities and 54% say vulnerability and exposure management is at least half manual—making automation attractive, but not enough to erase concerns about control and accountability.
The strongest evidence that guardrails had become the norm was not enthusiasm for autonomy, but the conditions enterprises attached to it. Kai found only 32% currently permit automated remediation without human approval, while the main barriers were lack of trust in automated decisions at 51%, governance or compliance concerns at 45%, and skills or talent gaps at 45%; confidence rose only when vendor accountability and liability protections (54%), auditability and explainability (53%), and regulatory clarity (52%) were present, matching the broader vendor emphasis seen in Peraton’s September guardrail contracts.
AI’s Role: Helper, Not Hero
Organizations are letting AI handle low-risk security chores while humans retain veto power over anything that could disrupt core systems or expose them to compliance risks.
Enterprises are not handing cyber operations to unconstrained agents; they are defining narrow zones where AI can act alone and wrapping the rest in configurable approval rules. Organizations set rules for what AI agents may do autonomously, while requiring a person to approve highly sensitive or dangerous acts, because AI can hallucinate and because someone must still give the green light or red light when production systems or other consequential assets could be affected.
That division of labor is already visible in workflow design: Kai’s 2026 survey found 55% of organizations allow automated asset discovery and inventory, 49% allow automated vulnerability prioritization, and 32% already permit remediation actions without human approval, while 45% of CISOs expect vulnerability and exposure management to become mostly or primarily machine-led within 12 to 18 months. At the same time, 52% of CISOs cite lack of trust in automated decisions as the biggest barrier, 43% name governance and compliance concerns, 65% of organizations have already adapted security strategy, and over 70% of respondents believe attackers currently have the advantage, reinforcing a trusted-advisor model where AI assembles evidence and handles minor, reversible tasks while humans keep final authority over high-impact decisions.

