AI is no longer simply being used to analyse security information.
It is increasingly becoming an active participant in identifying vulnerabilities, investigating threats, validating security controls, and supporting defensive operations.
For enterprises, this creates an important question.
How do organisations govern an AI system that itself has access to sensitive security environments?
Why AI Powered Cyber Defence Is Becoming Critical
Cyber attackers are increasingly using automation and AI to accelerate reconnaissance, vulnerability discovery, coding, and attack operations. OpenAI has warned that the window for defenders to prepare is narrowing as AI capabilities continue to advance.
Traditional security teams already face challenges including
• High volumes of security alerts
• Shorter attack timelines
• Increasing vulnerability disclosure rates
• Complex cloud environments
• Expanding identity ecosystems
• Shortages of skilled cybersecurity professionals
• Growing numbers of automated attacks
AI can help security teams respond at a scale that manual processes cannot easily achieve.
However, introducing AI into security operations also creates another layer that must be governed.
The defender itself is becoming an identity.
From Security Automation to Autonomous Defence
Earlier generations of security automation focused primarily on predefined workflows.
Modern AI systems can reason across multiple pieces of information and support complex security investigations.
GPT 5.6 has demonstrated stronger capabilities in areas such as vulnerability discovery, exploit related reasoning, secure code review, patching, threat modelling, and defensive security operations.
This enables security teams to use AI for activities such as
• Vulnerability triage
• Secure code analysis
• Malware investigation
• Threat detection
• Incident response
• Detection engineering
• Patch validation
• Security assessments
• Threat modelling
The value comes from reducing the time between identifying a potential weakness and taking defensive action.
The Identity Challenge Behind AI Security Agents
As AI moves from being an assistant to performing security tasks, identity becomes increasingly important.
An AI security agent may need access to
• Security platforms
• Source code repositories
• Cloud environments
• Vulnerability management systems
• SIEM platforms
• Threat intelligence
• Endpoint security tools
• Incident response systems
• Privileged infrastructure
This creates a new category of non human identity.
The AI agent needs an identity.
That identity needs ownership.
That identity needs appropriate privileges.
And every action performed by that identity needs to be attributable and auditable.
The Risks of Giving AI Security Privileges
AI can significantly strengthen defence, but excessive or poorly governed permissions can introduce new risks.
Organisations must consider
• Excessive privileges assigned to AI agents
• Uncontrolled access to sensitive systems
• Compromised AI credentials
• Unauthorised tool usage
• Autonomous actions outside intended workflows
• Data exposure through connected systems
• Difficulty attributing actions to specific AI agents
• Lack of clear ownership and accountability
The security question therefore changes from
Can AI detect the threat?
to
What is the AI allowed to do after it detects the threat?
Identity Governance for AI Powered Security
AI powered security operations require identity governance to extend beyond human users.
Organisations should establish clear controls around
AI Identity Ownership
Every AI agent should have a clearly defined business and technical owner.
Least Privilege
AI agents should receive only the permissions required for their specific security functions.
Continuous Verification
Access should be evaluated continuously based on context, risk, behaviour, and the sensitivity of the requested action.
Privileged Access Management
High risk actions should require stronger controls, approval mechanisms, or human oversight.
Auditability
Every action performed by an AI agent should be traceable and attributable.
Lifecycle Management
AI identities should be created, reviewed, modified, and decommissioned through controlled lifecycle processes.
The Importance of Human Oversight
The rise of AI powered security does not eliminate the need for human security professionals.
Instead, it changes their role.
AI can accelerate analysis and investigation while humans remain responsible for governance, accountability, risk decisions, and high impact actions.
This is particularly important because current AI systems can still produce incorrect conclusions or behave outside the precise intent of a user. OpenAI's GPT 5.6 system documentation also highlights the importance of safeguards, monitoring, trusted access, and stronger controls for higher risk cybersecurity capabilities.
A mature operating model should therefore combine
• AI driven analysis
• Automated investigation
• Human validation
• Risk based authorisation
• Privileged access controls
• Continuous monitoring
• Strong identity governance
The objective should not be to remove humans from security operations.
It should be to give security teams greater intelligence and speed while maintaining accountability.
AI Agents Are Becoming Part of the Enterprise Identity Fabric
The implications extend beyond cybersecurity teams.
As enterprises deploy AI agents across development, operations, customer service, finance, analytics, and security, organisations will increasingly operate environments where human and non human identities interact continuously.
This creates a new identity fabric consisting of
• Employees
• Customers
• Partners
• Applications
• Service accounts
• APIs
• Machines
• AI agents
• Autonomous workflows
Each identity can potentially access enterprise resources.
Each identity can potentially become compromised.
Each identity therefore needs governance.
Trevonix Perspective
At Trevonix, we see AI powered cybersecurity as an important evolution in how organisations defend their digital environments.
The opportunity is significant. AI can help security teams identify vulnerabilities faster, investigate incidents more efficiently, and respond to increasingly complex threats at scale.
But AI security cannot be separated from identity security.
When AI agents are given access to enterprise systems, they become part of the organisation's identity ecosystem.
They need
• Defined ownership
• Controlled privileges
• Continuous verification
• Lifecycle governance
• Behaviour monitoring
• Auditability
• Human accountability
The future of cybersecurity will not simply be AI versus attackers.
It will be an ecosystem of human and machine identities operating together to defend the enterprise.
The organisations that succeed will be those that combine AI capability with strong identity governance.
Conclusion
GPT 5.6 Cyber demonstrates how quickly AI is becoming a practical capability for cybersecurity teams. Its ability to support vulnerability discovery, malware analysis, detection engineering, incident response, and other defensive activities could significantly increase the speed and scale of cyber defence.
But greater capability also creates greater responsibility.
As AI agents gain access to security tools and enterprise environments, organisations must treat them as governed identities rather than simply software features.
The future of secure AI adoption depends on answering three fundamental questions
Who is the AI?
What can the AI access?
What is the AI allowed to do?
Identity governance provides the foundation for answering all three.
AI can strengthen cybersecurity.
Identity governance ensures it does so securely.
Reference
Source: Economic Times CISO, OpenAI launches GPT 5.6 Cyber for cybersecurity teams to combat AI cyberattacks.



