ISC2 Reveals AI Demands New Human Accountability in Cybersecurity: Validate, Govern, and Don't Blindly Delegate

ISC2 Reveals AI Demands New Human Accountability in Cybersecurity: Validate, Govern, and Don't Blindly Delegate

  • 21/Jul/2026
  • ForgeNEX by ForgeNEX
  • AI

Artificial intelligence is redefining the role of cybersecurity teams, but not in the way many feared. Far from replacing professionals, AI is raising the bar for human judgment, oversight, and accountability. This is revealed by a new study from ISC2, the global association of cybersecurity professionals, which surveyed 856 industry specialists.

The report, titled AI and Cybersecurity: The New Human Accountability, shows that security teams no longer just fight threats; they now must dedicate a significant portion of their time to validating what AI suggests. 65% of respondents said that over the past year they have increased the time spent deciding when to trust AI-generated recommendations, while 63% said they now invest more hours reviewing or validating the results of these systems.

la-ia-plantea-nuevas-exigencias-en-materia-de-resp-0.jpg

AI Errors: Accountability Remains Human

One of the most striking findings is that AI still makes mistakes frequently. 89% of respondents reported having received AI recommendations that led to incorrect outcomes. And more importantly: 50% believe that ultimately, humans must be held accountable when these failures occur. This reinforces the idea that AI does not eliminate responsibility but transforms it.

Scott Beale, CEO of ISC2, stated clearly: “AI is not replacing cybersecurity professionals; it is changing what the profession demands of them. As AI takes on more repetitive tasks, cybersecurity roles are shifting toward higher-value work, from asking the right questions to validating results, interpreting data, and applying human judgment.”

Stress, Dependence, and New Risks

The impact of AI on workplace well-being is ambivalent. While 48% of respondents say AI has reduced stress at work, 32% acknowledge it has increased it. The main concerns revolve around over-reliance on AI recommendations (cited by 62%) and undetected errors that could spread rapidly through systems (61%).

Furthermore, nearly a quarter of professionals (24%) indicate that they are often or very often expected to act based on AI-generated results without fully understanding how they were obtained. This is alarming, as without transparency in AI processes, informed decision-making becomes impossible.

la-ia-plantea-nuevas-exigencias-en-materia-de-resp-1.jpg

Governance and Oversight: Keys to Success

Despite the challenges, respondents are clear about the path forward. Around 80% believe that governance frameworks, knowing when to trust AI results and when to ignore recommendations, are fundamental for effective use of artificial intelligence. This implies that companies must invest in clear policies, validation processes, and continuous training.

In this regard, configuring secure VPNs and firewalls remains a basic skill, but now it is complemented by the ability to audit and correct automated decisions. As Beale notes, “this evolution is not limited to entry-level positions. It changes how work is distributed across security teams, making ongoing investment in governance, validation practices, mentoring, and skills development essential at all levels.”

Impact on Professional Careers

Opinions on the effect of AI on cybersecurity careers are mixed. More than half (56%) believe AI has reduced the need for entry-level positions, but 53% think it is creating new types of entry roles. Nearly half (48%) feel more optimistic about their long-term professional future in the sector.

What is clear is that core cybersecurity skills remain essential. 62% of respondents say AI has not reduced the need for these skills. In fact, abilities such as determining when to trust AI (82%), when to ignore its recommendations (80%), and establishing governance frameworks (80%) are now more important than ever.

la-ia-plantea-nuevas-exigencias-en-materia-de-resp-2.jpg

The Future: More Responsibility, Not Less

The ISC2 study makes it clear that AI is not a magic solution that eliminates the need for cybersecurity professionals. On the contrary, it demands a higher level of responsibility, judgment, and oversight. Companies that want to leverage AI safely must invest in governance, training, and rigorous validation processes.

For industry professionals, the recommendation is clear: update their skills in AI governance, model validation, and critical analysis of results. As we have seen in other areas, such as the bottleneck of AI agents, the context layer and human oversight are critical to success.


Original source: ComputerWorld. Analysis and adaptation by ForgeNEX.

Share: