If an AI agent is attesting your controls, who’s attesting the agent?
I’ve watched engineers lose a week before an audit collecting screenshots no one will ever look at again. I’ve seen incident response plans that exist on paper but have never been tested, and vendor questionnaires completed once and filed away while the risk quietly changed underneath them.
Security teams are under more pressure than ever to prove they can be trusted by customers and boards alike. Yet the frameworks they rely on to demonstrate security are increasingly disconnected from how risk actually shows up in practice.
This gap between appearing secure and being secure isn’t new, but AI is making it impossible to ignore. As AI systems become more complex, traditional compliance-first approaches are struggling to keep pace. The result is a growing reliance on what many security leaders now describe as security theatre: activities that prove a control existed at a point in time but say nothing about whether...
Copyright of this story solely belongs to www.techradar.com. To see the full text click HERE