AI Won't Save You (But It Might Save Meaning)
AI Won’t Save You (But It Might Save Meaning)
By Julian Brownlow Davies | Meaning In the Signal, Week 8 | 20 May 2026
The most interesting thing about AI in cybersecurity is not what it can do. It is what we are choosing to use it for.
If you attend the major security conferences, read the vendor briefings, or follow the investment flows into the security market, you will encounter a remarkably consistent narrative: AI is transforming security by making detection faster, broader, and more precise. The threat surface is expanding. The adversaries are evolving. The attack volume is increasing. AI, in this telling, is the answer - the force multiplier that allows defenders to keep pace with a threat environment that human capacity alone cannot match.
I believe this narrative is partially correct and, in its current dominant form, actively harmful - not because the technology is wrong, but because we are deploying it against the wrong constraint.
The constraint, as I have argued across this series, is not detection. We crossed the inflection point on detection some years ago. The evidence that generated this series - five independent talks at [un]Prompted 2026 that converged, without apparent coordination, on the same observation - was not that we are failing to find threats. It was that the volume of what we find, including the genuine threats amongst the noise, has exceeded our capacity to act on it meaningfully. AI deployed to accelerate detection is adding fuel to a fire whose problem is not the fuel supply. It is making the input richer, faster, and more voluminous whilst leaving the bottleneck - comprehension, prioritisation, the extraction of meaning from signal - entirely intact.
The question worth asking is not “can AI detect better?” It demonstrably can. The question is “can AI comprehend better?” - and the answer to that question, I think, is far more interesting, far more genuinely uncertain, and far more consequential than the industry’s current conversation suggests.
Why More Detection Accelerates the Wrong Constraint
Eliyahu Goldratt’s central insight in The Goal, which I have returned to repeatedly in this series because its application to security operations is uncomfortably direct, was that improving the performance of any non-bottleneck element of a system does not improve the system’s overall throughput - it merely creates more inventory in front of the actual constraint. In manufacturing, this means work in progress accumulating before the slowest machine in the line. In security operations, it means findings accumulating in a remediation backlog that already exceeds the capacity of the organisation to address it.
When we deploy AI to improve detection - and the results are, genuinely, impressive; modern AI-driven security tooling finds things that rule-based systems miss, correlates patterns across timescales and data volumes that human analysts cannot hold in working memory, and operates continuously without the cognitive fatigue that degrades human performance over a twelve-hour shift - we are improving the first part of a two-part problem. More findings enter the top of the pipe. The pipe itself - the analytical, human process of understanding which findings matter, why they matter, and what to do about them - remains the same width it was. The water pressure builds. The analysts, as I discussed last week, disengage. The pile grows.
This is not an argument against using AI for detection. Detection matters, and better detection is a genuine improvement over worse detection. It is an argument against the assumption, largely unexamined in current deployment practice, that detection improvement is the primary value AI brings to security. It is the value AI brings to the part of security that is no longer the constraint.
What AI Deployed Against the Right Constraint Looks Like
At [un]Prompted 2026, I had the opportunity to observe several presentations that I have been returning to in the weeks since, because they illustrate something about where AI’s genuine contribution to security might lie that the mainstream conversation has not yet caught up with.
Girnus and Chen presented something that caught my attention precisely because it inverted the standard deployment logic. Rather than treating AI as a detection tool that feeds a human triage process, their approach positioned AI as the final step in a pipeline that begins with human contextual framing. The human analyst - with their knowledge of the environment, the business, the threat actors relevant to the sector, the crown jewels that warrant protection - defines the question. The AI operates against that question, using its pattern recognition and correlation capacity to surface what is relevant to a pre-specified meaning frame rather than generating signal for subsequent human classification.
This is, in Goldratt’s terms, addressing the constraint rather than the pre-constraint. The bottleneck is not finding things. It is finding the right things for the right reasons, given what we know about this specific environment and this specific adversary context. AI that is given that context as its operating frame - rather than AI that generates output and then asks humans to provide the context retrospectively - is AI deployed where it can actually move the system.
Rudis and Thorpe’s work on preference tuning, which I referenced in the first essay in this series, is another illustration of the same principle from a different angle. The insight that motivated their research was the observation that a model consuming threat intelligence in its raw, undifferentiated form is doing exactly what an overwhelmed analyst does: treating all signal as equivalent and applying a generic classification schema to determine relevance. The innovation was to tune the model’s intake against a specific threat context - in their case, the ability to separate conflict-related intelligence from the background noise of commodity ransomware - so that what the model attends to, and what it surfaces, reflects a prior understanding of what matters. The meaning frame precedes the signal, rather than being applied to it after the fact.
This is a subtle but consequential distinction, and I think it represents the most important design principle for AI in security that is not yet widely understood: AI that is meaning-directed generates comprehension. AI that is detection-directed generates more signal. The technology is the same. The deployment architecture is the decision that determines which problem you are solving.
The Human-in-the-Loop Imperative, and Why It Is Not What You Think
The phrase “human in the loop” has become something of a compliance gesture in AI-augmented security: a way of saying that the AI does not make final decisions without implying any serious commitment to the conditions that make human oversight meaningful. A human who is in the loop but receives AI output faster than they can evaluate it, in a volume that exceeds their capacity to interrogate, with feedback cycles too attenuated to calibrate their judgement, is not meaningfully in a loop. They are providing the appearance of human oversight whilst the system operates on its own logic.
Rittinghouse and Huang’s work on human-AI teaming in complex decision environments, presented at [un]Prompted, made a point that I consider underappreciated in security deployments specifically: that the value of human oversight is not a function of its presence but of its quality, and that quality is a function of the human’s ability to genuinely evaluate what the AI is proposing, which in turn requires that the AI’s output be comprehensible, contestable, and accompanied by enough explanatory context for the human to apply their own judgement independently.
Most current AI deployments in security fail this test, not because the outputs are wrong - they are frequently quite right - but because the explanatory layer is thin. The model says this is high priority. The confidence score is 94%. The analyst closes it or escalates it, and the feedback loop that would tell them whether that confidence score was warranted is, for the reasons I described last week, largely absent. What we have built, in many cases, is an AI that moves fast and a human who rubber-stamps it - which is not an oversight architecture but a liability transfer mechanism.
The meaningful human-in-the-loop, by contrast, is a human who can see what the AI saw, can interrogate the inference it made, can add environmental context the AI does not have access to, and can correct its output when their knowledge of the specific situation overrides the general pattern the model has learned. That is a different design challenge, and it is one that the industry has not yet taken seriously as a product requirement.
The AI That Should Worry Us Is Not the One We Are Worried About
There is a productive anxiety in the security community about AI-enabled offence: the prospect of adversaries who use language models to improve phishing at scale, automated vulnerability research to find novel attack paths, or AI-generated deepfakes to compromise human authentication. These are real concerns, and I do not dismiss them. But I observe that the most prominent anxieties about AI in security have been directed at the adversarial use case, whilst a quieter and in some respects more consequential risk has received rather less attention.
The AI that concerns me most is not the AI that is attacking us. It is the AI that is generating findings we cannot comprehend, at a rate we cannot absorb, in a volume that crowds out the human reasoning capacity that the findings were generated to support. Every additional AI-driven detection layer that an organisation adds to its stack - without a corresponding investment in the comprehension capacity required to make use of what that layer produces - is an organisation investing in the intensification of its own meaning problem.
The detection AI is efficient. It does not fatigue. It scales horizontally. It finds things. It will continue to find things in increasing volume as the threat environment evolves and the models improve. And every finding it generates will join the queue that an analyst with finite time, limited context, and an institutional environment that discourages deep investigation will eventually process - or not process - in a way that may or may not reflect the actual risk the finding represents.
This is not an argument for deploying less AI. It is an argument for deploying AI in a way that is honest about what the current constraint is, and directs the technology’s considerable capabilities against that constraint rather than the one we solved five years ago.
What Good Looks Like: A Sketch
I want to be careful here not to prescribe a specific architecture, partly because the implementation details matter enormously and vary by context, and partly because the practical application of this series’ argument is the subject of later essays. But the broad shape of an AI deployment oriented toward meaning rather than detection volume has, I think, some identifiable characteristics.
It begins with context, not with signal. The AI is given an explicit representation of what the organisation has that is valuable, who the relevant adversaries are, and what the most plausible attack paths look like - before it processes alerts, not after. The meaning frame is an input to the AI, not an output it is asked to generate.
It returns to the human something that the human can actually evaluate. Not a score and a category, but an argument: here is what I observed, here is why I believe it is significant given the context I was given, here is what I do not know and cannot determine without additional investigation. The output is designed to support human judgement, not to replace it.
And it closes the feedback loop - capturing what happens to AI-generated findings, whether the escalations proved warranted, whether the deprioritisations proved safe, and using that information to improve both the model’s performance and the analyst’s calibration over time. The AI learns. The human learns. The system, across sufficient iterations, gets better at the thing that actually matters: distinguishing, from the torrent of technically valid signal, the subset that represents a genuine and immediate threat to the things that cannot be replaced.
The Question the Industry Has Not Yet Asked
The security AI market, measured by investment and by vendor announcement volume, is one of the most active in the technology industry. The pace of capability development is genuine and significant. Models that could not perform meaningful security reasoning two years ago are performing it today, and the trajectory is not slowing.
But the question I rarely see asked in investor briefings, vendor presentations, or CISO panel discussions is this: if we deploy this technology at scale, and it works as advertised, what does the security operations environment look like in three years? How many findings will an organisation with a full AI-augmented detection stack be generating per day? How many of those will be true positives? And what, precisely, is the plan for the humans who must decide what to do with them?
If the answer to that last question is “the AI will handle it,” then we have not solved the meaning problem. We have delegated it to a system that cannot, on its own, understand what matters to this specific business, with these specific assets, facing these specific adversaries, in this specific regulatory and operational context. Meaning is not a computation. It is a judgement, grounded in context that is partly tacit, partly institutional, and partly the kind of nuanced environmental knowledge that experienced practitioners carry and that no training dataset has yet captured fully.
Consider the concrete version of the point. A tool surfaces an internal privilege-escalation issue and rates it a medium; on its own, it reaches nothing that matters. The same tool rates an externally exposed interface a critical, because it touches sensitive data directly. Read in isolation, you remediate the critical and queue the medium behind a thousand others. Read with context - knowing the two sit on the same path to the same irreplaceable database - they are not two findings of differing severity at all; they are one attack, and the medium is simply its cheaper half. The scanner told you their scores. Only the context told you they were the same story. That is the work the model cannot yet do alone, and it is precisely the work that decides whether you are safe.
AI is a genuinely powerful tool for meaning amplification - for helping experienced human analysts extend their reach, improve their recall, and interrogate their environment faster than unaided cognition allows. It is a poor substitute for the meaning-making judgement it is being asked, in too many current deployments, to replace.
The formulation I keep returning to is the plainest one I can find: AI signal, human context. The model supplies the signal, in ever greater volume; the human supplies the context that turns signal into meaning. Neither half is sufficient on its own, and the organisations - and the platforms - that come through this era well will be the ones that hold both in the same loop, rather than betting everything on the model and hoping the meaning takes care of itself.
The signal from the AI will be abundant. Whether it generates meaning depends on what we ask it to do, and for whom.
We are spending considerable energy debating whether AI will replace security analysts. We are spending rather less energy on the prior question: if we deploy AI to accelerate detection in environments already drowning in findings, are we building tools that serve the analyst or tools that will make the analyst’s eventual replacement feel inevitable? And are those two things, in the end, the same conversation?