Systems are deterministic, people are probabilistic – AI is both, and that's a headache for cyber teams
AI combines both the risks associated with IT systems and the people using them, creating headaches for practitioners
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
You are now subscribed
Your newsletter sign-up was successful
Security practitioners have traditionally looked at cyber risk through a “deterministic lens”, but with AI the rules have changed and that will require a tactical rethink.
That’s according to Dean Sysman, executive chairman and co-founder of Axonius, who told attendees at the RSAC 2026 Conference that enterprise security teams need to shake up practices for an era of AI-related risks.
The technology is accelerating both offensive and defensive cyber operations globally, he noted, with bad actors now capitalizing on flaws in minutes, rather than weeks.
Similarly, unsecure AI systems mean there are more entry points for bad actors to pounce on, and enterprises are now awash with agents that have deep access to internal datasets.
With this in mind, treating AI like humans will be critical for assessing and managing risk, Sysman noted.
There is one caveat. Currently, security teams focus on deterministic behavior for IT systems and probabilistic behavior for humans. AI, however, behaves in a probabalistic and deterministic way.
This means managing risk is going to split their attention.
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
“We’ve always looked at cybersecurity through two different lenses,” he said.
“We have the deterministic lens, where we look at systems and compute and storage and memory, and those things behave in a way that we can determine, we can forecast, we can understand and react to or respond to in a deterministic way as well.
“And yet, we have people who are probabilistic. Nobody ever knows what somebody is going to do, or how they’re going to ask, or what kind of risk they’re going to introduce.”
Sysman's voice adds to a growing chorus of security and IT professionals calling for AI systems – and agents in particular – to be treated as human in the context of security.
A host of tech industry figures have urged enterprises to view agents as “digital co-workers” and thereby apply the same security standards. Efforts are being made to improve identity management and observability to keep tabs on agents working away in the background.
Sysman told attendees that visibility isn’t enough, though, saying they need to shift their attention toward “actionability”.
“We need to start by seeing what we have, what exists in our environment,” he explained. “Then there’s this understanding of the organizational context of those things. We can’t fix everything and we don’t have unlimited resources, so there is always an element of prioritizing.”
Ultimately, actionability places the emphasis on ownership and accountability of AI risk in the enterprise - a key talking point during an earlier talk by Tenable co-CEO Stephen Vintz.
“The biggest question that is the hardest one to answer today [is] who owns this? Who will make this decision? Who needs to be accountable for the action and the decision that needs to be taken?”
FOLLOW US ON SOCIAL MEDIA
Follow ITPro on Google News and add us as a preferred source to keep tabs on all our latest news, analysis, views, and reviews.
You can also follow ITPro on LinkedIn, X, Facebook, and BlueSky.

Ross Kelly is ITPro's News & Analysis Editor, responsible for leading the brand's news output and in-depth reporting on the latest stories from across the business technology landscape. Ross was previously a Staff Writer, during which time he developed a keen interest in cyber security, business leadership, and emerging technologies.
He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.
For news pitches, you can contact Ross at ross.kelly@futurenet.com, or on Twitter and LinkedIn.
-
Tenable co-CEO Stephen Vintz says enterprises need to get serious about tackling the AI “responsibility gap”News The Tenable chief wants a serious conversation on AI ownership and accountability
-
HP delivers AI-powered updates to the Workforce Experience Platform (WXP) designed to help IT leaders and MSPs navigate the current memory shortage and moreNew features help IT teams turn insight into action and really derive maximum value from the tech investments they have made
-
Tenable co-CEO Stephen Vintz says enterprises need to get serious about tackling the AI “responsibility gap”News The Tenable chief wants a serious conversation on AI ownership and accountability
-
The key risks security teams face in 2026From AI-related flaws to supply chain risks, cyber professionals now contend with overlapping challenges
-
Observability will be key to agentic AI safety, says Microsoft Security execNews Agentic AI adoption will require a re-evaluation of enterprise risk management, according to Microsoft corporate VP
-
Enterprises need to think of agents as ‘digital co-workers’ – and that means implementing the same security safeguardsNews Practices such as zero trust and least privilege will be needed as agents gain access to sensitive enterprise data
-
Safe AI adoption rests on cybersecurity professionals, says RSAC chairmanNews With AI security a key talking point at RSAC 2026, executive chairman Hugh Thompson believes the industry can lead by example
-
AI agents are creating new identity security risks: 1Password wants to solve thatNews The Unified Access system from 1Password will help enterprises manage AI agent access across different devices and users
-
CISOs are keen on agentic AI, but they’re not going all-in yetNews Many security leaders face acute talent shortages and are looking to upskill workers
-
Trend Micro issues warning over rise of 'vibe crime' as cyber criminals turn to agentic AI to automate attacksNews Trend Micro is warning of a boom in 'vibe crime' - the use of agentic AI to support fully-automated cyber criminal operations and accelerate attacks.