AI Reshapes Cybersecurity but Humans Remain Essential
The integration of Artificial Intelligence (AI) in cybersecurity is transforming the way threats are detected and responded to. According to IBM's Gaurav Agarwal, vice president for Technology in India & South Asia, AI is changing the game on both sides - helping defenders process vast amounts of data while giving attackers faster ways to find vulnerabilities and launch social engineering attacks.
The World Economic Forum's Global Cybersecurity Outlook 2026 found that 94% of respondents expect AI to be a major driver of change in cybersecurity this year, with 87% identifying AI-related vulnerabilities as the fastest-growing cyber risk in 2025. Already, 77% of organisations have adopted AI for cybersecurity, mainly for phishing detection, anomaly response, and user-behaviour analytics.
Cybersecurity is now about looking at data 'at scale', said Agarwal, who cited an example where a user logs in from Bengaluru and then appears to connect from Delhi half an hour later. AI can flag the anomaly and either block access or ask the user to reconfirm it.
The challenge lies in avoiding false positives - security systems produce so many alerts that teams reduce detection sensitivity. Agarwal said AI can filter effectively, 'you don't have to dial down'. However, with AI increasing vulnerability discoveries at a 'velocity and volume' not seen before, prioritizing fixes becomes crucial.
IBM's Concert platform helps prioritize vulnerabilities and fixes, while the Watsonx.governance platform controls model and agent usage, providing traceability around AI decisions. Agarwal emphasized that accountability lies with businesses, not model providers, as AI adoption requires 'people, process, and technology'. He predicted 30% of work could eventually be autonomous and rule-based, with 20-30% heavily AI-assisted and the remainder primarily human.