Will cybersecurity be replaced by AI? The short answer
AI can change particular cybersecurity tasks without establishing that it will replace cybersecurity as a field or leave any particular role unchanged. The defensible claim sits between those poles: specific tasks inside security work can be automated or augmented, and how far that goes in any organisation depends on documented capability evidence for the specific tool applied to the specific task.
Cybersecurity is not a single job. It is a bundle of tasks — watching logs, reading alerts, writing reports, deciding whether to take a payment system offline at 3am, explaining to a board why a control failed — attached to decisions and to responsibility for those decisions. The U.S. Bureau of Labor Statistics describes the core occupation in almost exactly those terms, listing monitoring networks, investigating incidents, checking for vulnerabilities and developing security standards among the duties of information security analysts. Automation acts on tasks. Whether it changes who is answerable for the outcome is a separate question.
NewsForge analysis, informed by the governance practices set out in NIST’s AI Risk Management Framework: where responsibility for an automated decision sits is a matter for an organisation’s own governance arrangements, which the framework describes in terms of assigned roles, accountability structures and continuous monitoring (NIST AI RMF 1.0). That framework is guidance rather than a universal legal rule; applicable obligations depend on jurisdiction and context. Where formal obligations apply to you — sectoral rules, regulator guidance, contractual commitments — the binding text is the applicable rule.
Cybersecurity as a field versus individual cybersecurity tasks
NewsForge analysis: fields persist as long as the underlying problem persists, while individual tasks can be absorbed by software without anyone announcing it — the way spell-check absorbed part of proofreading without ending editing as an occupation. The underlying problem in cybersecurity is adversarial: people who adapt to whatever defenders do. The FBI’s warning that criminals are already adopting AI to improve phishing, social engineering and synthetic media is a reminder that the adversary side of the equation is adapting too.
Automation, augmentation, and replacement are different outcomes
Three outcomes are routinely collapsed into one word:
- Automation: a task is performed end to end by a system, with no human in the loop for the routine case.
- Augmentation: a system does part of the work — drafting, ranking, summarising — and a person reviews, corrects and signs off.
- Replacement: demand for the human role itself falls far enough that fewer people are employed to do it.
NewsForge analysis: automating a task does not mechanically produce replacement of a role. It can also produce more work, if outputs must be verified, or if cheaper analysis leads organisations to analyse more. Which outcome occurs is an empirical question for a specific employer and implementation.
What can and cannot be concluded from current evidence
On demand for the question itself: a DATAFORSEO keyword record (source record identity 09f1f11b3baa55f8a591d5acfcd68501a0147dcdc51c01d7e3d54d62990afddd, provider data updated 15 July 2026 at 10:00:23 UTC, retrieved 9 August 2026 at 20:15:24.488 UTC, freshness classified FRESH) gives the query “will cybersecurity be replaced by ai” a search volume of 880, organic difficulty 0, competition 0.04, and CPC $3.56. Those four figures come from that record and no other.
A Google Search Console record for newsforge.net covering 8 July to 6 August 2026 shows 0 related clicks, 0 related impressions and no related queries for this topic. That is a record of what this site has surfaced for; it is not evidence about whether an audience exists, which the DATAFORSEO record addresses separately.
NewsForge analysis: product accuracy, employer-level job changes and longer-term outcomes depend on evidence specific to the tool, workplace and time period.
Which cybersecurity tasks could AI change first?
Adoption is not hypothetical. ISC2’s 2024 Cybersecurity Workforce Study — an international survey of 15,852 participants — reports that 45% of respondents said their cybersecurity teams were already using generative AI tools, and that respondents generally described AI as changing roles rather than eliminating human work. That is self-reported adoption from a survey population, not a measurement of what those tools achieve; ISC2’s own framing of the finding is available in its workforce study summary.
NewsForge analysis: the tasks most exposed to automation tend to share three properties — high volume, a well-defined input, and a verifiable output. The least exposed involve incomplete information, competing interests, or consequences someone must answer for. The sections below apply that lens to duties the BLS actually lists for the analyst occupation. The lens is ours; the duties are sourced.
Monitoring, alert triage, and anomaly review
Monitoring networks for security breaches and investigating violations are named duties of the analyst role in BLS occupational data.
NewsForge analysis: this is the category where the structural fit with automation looks strongest, because much of the work is classification and prioritisation over machine-readable data. The open question is not whether software can rank alerts at all, but whether a statistical system’s mistakes are of a kind a team can detect and absorb. Establishing that for a given product requires its evaluation methodology, dataset and test conditions. Ask for the evaluation methodology, dataset, scope and test conditions.
Threat intelligence collection and summarization
NewsForge analysis: collecting and condensing large volumes of text is a task with the properties that suit automation — high volume, a well-defined input — and ISC2 respondents reported using AI in common security-team workflows (2024 ISC2 Cybersecurity Workforce Study). The plausible failure mode is not unreadable summaries but fluent, subtly wrong ones, which are harder to catch than obvious errors. Teams adopting this should require that summaries remain traceable to their sources, so claims can be checked rather than trusted.
Vulnerability identification and prioritization
Two different jobs sit under one heading. Checking systems for vulnerabilities is a listed analyst duty in BLS data. Prioritisation is a business problem — which of these matters here, given what this system does and who depends on it.
NewsForge analysis: the second looks harder to delegate, because prioritisation requires context about the organisation and the affected system. Where identification produces a list, prioritisation produces a decision with an owner, and that is a different kind of output.
Incident investigation and response workflows
Investigating security violations is another duty the BLS attributes to the role (BLS). Investigation means assembling a narrative from available evidence under time pressure; response means acting on it, often at operational cost.
NewsForge analysis: assistive uses — building timelines, drafting queries, suggesting next steps — are structurally easier than autonomous action, because autonomous action carries the risk of a wrong containment decision that itself causes an outage. NIST’s AI Risk Management Framework treats monitoring and assigned human roles as core to managing that kind of risk, rather than optional extras (NIST AI RMF 1.0).
Reporting, documentation, and compliance support
Developing security standards and reporting is among the duties listed for the occupation (BLS).
NewsForge analysis: the caution here is that compliance documents are assertions an organisation makes about itself, and a fluent draft is not an accurate one. Whether a given document may be machine-drafted depends on the rules binding a particular jurisdiction and sector; check the applicable rule rather than generalising from any article, including this one.
Where human cybersecurity judgment may remain important
This framing is conditional. These boundaries should be reassessed as tools and evidence change. They are the areas where the case for removing human review looks weakest.
NIST’s AI Risk Management Framework is explicit that managing AI risk depends on assigned human roles, accountability structures, ongoing monitoring, and governance sensitive to the context of deployment (NIST AI RMF 1.0). That is a framework, not a universal legal mandate — but it is the reference point most of the following rests on, and the analysis in this section is ours, informed by it.
Interpreting incomplete or conflicting evidence
NewsForge analysis: investigations can involve evidence that is partial or ambiguous, and resolving that requires knowing what the organisation actually does — as well as being willing to say “I don’t know yet.” The AI RMF’s emphasis on context-sensitive governance points the same way: the meaning of a signal depends on the deployment context, which is exactly what a general-purpose tool does not carry (NIST AI RMF 1.0).
Making risk decisions within an organization
Accepting a risk, spending money, or interrupting revenue are decisions with owners. NewsForge analysis, informed by the framework’s governance practices: a system can inform such decisions, but the AI RMF describes mapping accountability to named roles as part of managing AI risk, which implies a person holds the mandate rather than the tool (NIST AI RMF 1.0). Whether any legal duty applies in your setting is a question for the applicable rule, not for this framework.
Managing incidents involving people and business operations
Serious incidents have a technical component and an organisational one: who is told, in what order, with what wording, and what the business does while systems are down.
The FBI’s Internet Crime Complaint Center documents substantial reported complaint volumes and reported losses from cyber-enabled crime in 2024 (2024 IC3 Annual Report). That report records complaints and losses but does not attribute those totals to AI. Related reading from NewsForge: Beyond the Code: The FBI’s 2025 Report and the Dominance of the Human Element in Cybercrime Losses. Readers should consult the underlying law-enforcement reporting directly.
Validating AI-generated findings and recommendations
If an output will be acted on, someone must be able to check it. NewsForge analysis: this creates a practical ceiling — automation only saves effort if verification is cheaper than doing the work, and that is not automatically true. It is also something an organisation can measure for itself, which beats any general claim, including ours.
Assigning responsibility when automated systems fail
When an automated action causes harm, “who is answerable” still needs an answer. NewsForge analysis, informed by NIST AI RMF governance practices: on the evidence available, this is the strongest argument that security roles change rather than disappear, because the framework’s model of AI risk management assumes identifiable people are accountable for systems and their outputs (NIST AI RMF 1.0). That is a governance argument, not a statement about what any legal system requires or how it allocates liability.
How AI could strengthen cyber defenses
NewsForge analysis: the following mechanisms are potential defensive uses whose performance must be established through tool-specific evaluations with stated datasets, scope and test conditions.
Finding patterns in security data
NewsForge analysis: the appeal of statistical methods is coverage — surfacing correlations across sources a person would not have time to compare. The corresponding weakness is that a surfaced correlation is a lead, not a conclusion, and a system that produces many leads can consume more analyst time than it saves. Whether that trade works in a given environment is measurable there and nowhere else.
Accelerating investigation and response
NewsForge analysis: the theory of value is time — shorter gaps between detection, understanding and action. This is measurable in principle, and organisations should measure it in their own environment rather than accept it as given.
Supporting analysts without removing oversight
ISC2 respondents described AI as reshaping roles rather than removing human work, and reported using it in common security-team workflows (2024 ISC2 Cybersecurity Workforce Study).
NewsForge analysis: the design pattern carrying the least risk is assistance with review — the system proposes, a person disposes. Its value should be measured through decision quality and review effort rather than assumed employment effects. When a vendor makes both at once, ask which one the product is actually optimised for.
Limits, errors, and verification requirements
Any claim about accuracy, error rates or comparative performance needs the original study, including its scope and test conditions, and results from one evaluation should not be generalised to another setting. When evaluating a tool, ask the vendor for the evaluation, its dataset and its conditions, and treat marketing copy as marketing copy.
How attackers could use AI
Labelling matters most here. There is a wide gap between demonstrated in a lab, observed in the wild and documented by an investigator, and forecast by someone with an interest in the answer.
Scaling malicious content and social engineering
This one is documented by a national authority. The FBI has warned that criminals are using AI to make phishing and social-engineering campaigns more convincing, and to generate synthetic voice, video and other content with greater speed and at greater scale (FBI San Francisco, May 2024). That is a warning about observed criminal use patterns; it does not quantify how much fraud is AI-assisted. The 2024 IC3 Annual Report separately documents reported complaint volumes and reported losses from cyber-enabled crime in 2024, and does not attribute those totals to AI.
Assisting reconnaissance or technical workflows
NewsForge analysis: reconnaissance involves reading and correlating information, much of it public — structurally similar to defensive threat intelligence, which is why assistance is plausible on both sides of the contest. This is reasoning about the shape of the task, not a report of observed use. Be sceptical of accounts of observed attacker use that do not name an incident report, advisory or piece of research.
Lowering barriers to some malicious activities
NewsForge analysis: capability that can be bought or prompted rather than learned tends to widen the pool of people who can attempt an attack, without necessarily raising the ceiling of what the most capable attackers achieve. The FBI’s warning about greater speed and scale is consistent with that direction of travel, though the warning itself concerns criminal use of AI rather than the structure of criminal markets (FBI). Related reading from NewsForge: The Commercialization of Malice: Understanding Subscription Cybercrime and Evolving Digital Threats.
Why defensive automation may not eliminate human adversaries
NewsForge analysis: attackers respond to defences. A defence that is automated is also a defence that can be studied, probed and worked around — potentially more systematically than a human defender whose behaviour is less predictable. That is the core reason to treat “AI ends the problem” claims sceptically in either direction.
Could AI create new cybersecurity risks?
Adopting AI systems expands what an organisation has to defend, and this is the part of the debate with the most authoritative published material behind it. NIST’s adversarial machine learning taxonomy catalogues attack classes against both predictive and generative AI systems, including evasion, poisoning, privacy attacks and misuse (NIST AI 100-2e2025). Naming a class is not a statement about how often it occurs; no prevalence or cost figures were available.
Manipulated inputs and unreliable outputs
If a system acts on text or data it retrieves, that text becomes part of the attack surface. NIST’s taxonomy treats evasion and related manipulation of inputs as recognised attack categories against AI systems (NIST AI 100-2e2025).
NewsForge analysis: this is a genuinely awkward class of problem, because the boundary between “data” and “instruction” is less crisp than in traditional software. A control that assumes those two categories are separable may not hold when the system’s input is free text drawn from an untrusted source.
Sensitive-data exposure
Privacy attacks against AI systems are among the categories NIST identifies (NIST AI 100-2e2025), and joint international guidance treats data handling, logging and monitoring as security concerns across the AI lifecycle (Guidelines for Secure AI System Development).
NewsForge analysis: every new system that processes security telemetry, source code or customer data is another place that data can be logged, retained longer than expected, or shared further than intended — a familiar risk in a new location, which is why the inventory question comes before the tuning question.
Model, application, and supply-chain security
AI features arrive as dependencies: models, libraries, hosted APIs, plugins. The UK NCSC, CISA and international partners frame secure AI as a lifecycle problem spanning secure design, supply-chain security, deployment, logging, monitoring and ongoing operation (Guidelines for Secure AI System Development). The NSA, CISA, FBI and partner agencies address the deployment side specifically, covering configuration, data, model and operational security for organisations running externally developed AI systems (Deploying AI Systems Securely).
NewsForge analysis: the practical consequence is that “we don’t build models” is not an exemption — the joint guidance is explicitly written for organisations deploying systems developed by someone else. Related reading from NewsForge on individual model launches and the debate around them: Kimi K3: Threat or Menace? Unpacking Moonshot AI’s Global Impact.
Overreliance on automated decisions
NewsForge analysis: the practical hazard is quiet degradation — a team that stops checking because the system has been right often enough, and loses the ability to tell when it is wrong. Teams can test for this risk by monitoring review quality and retaining independent validation practices.
Governance and accountability
The questions to answer before deployment are boring and decisive: who owns this system, who can turn it off, what happens when it is wrong. NIST’s framework treats exactly that kind of assigned accountability and continuous monitoring as central to AI risk management (NIST AI RMF 1.0), and the joint secure-AI guidelines extend the same expectation through operation (NCSC/CISA). Where formal obligations apply — sectoral rules, regulator guidance, contractual commitments — the binding text is the applicable rule for your jurisdiction, and neither framework substitutes for it.
What AI may mean for cybersecurity jobs and career paths
The career intent behind this query is visible in the search results. The supplied SERP snapshot for “will cybersecurity be replaced by ai”, checked 9 August 2026 at 20:15:26 UTC, lists Reddit at rank 3, Boise State University at rank 7, the University of West Florida at rank 8, Wiz at rank 9, Spiceworks at rank 10 and PurpleSec at rank 11, and records four People Also Ask questions: “Which 3 jobs will not survive AI?”, “Which tech jobs can’t AI replace?”, “Is cybersecurity a dead-end job?” and “Can you make $500,000 a year in cyber security?”. Those questions describe the search-result snapshot rather than evidence about cybersecurity employment.
The most authoritative employment evidence available comes from the U.S. Bureau of Labor Statistics, which projects 29% employment growth for information security analysts from 2024 to 2034 and about 16,000 openings per year over that decade, and which identifies AI among the new technologies increasing demand for security analysts (BLS Occupational Outlook Handbook). That is a projection for one U.S. occupation, produced by a statistical agency — not a guarantee, and not a global figure.
Roles versus tasks: what exactly might change?
NewsForge analysis: a role is a portfolio of tasks. If some tasks become cheaper, the plausible first-order effect is that the mix shifts — more time on tasks that resisted automation, less on those that did not. ISC2’s respondents described AI as affecting roles rather than removing human work (2024 ISC2 Cybersecurity Workforce Study), which is consistent with that reading without proving it. Survey self-report tells you what practitioners believe is happening to their jobs; it does not measure what happened to the jobs.
Skills that may become more useful
NewsForge analysis, offered as reasoning rather than forecast: the skills that pair with automation are the ones automation does not supply — understanding a specific business well enough to prioritise, verifying a machine’s output rather than accepting it, and explaining a decision to the people affected by it.
Understanding how AI systems fail is plausibly becoming part of the security skill set, because those systems are becoming part of the estate that must be defended — which is precisely what the NIST taxonomy of attacks and the joint secure-AI guidance describe (NIST AI 100-2e2025; NCSC/CISA).
How students and career changers can prepare
NewsForge analysis: fundamentals travel well. Networking, operating systems, identity, logging, and how software is built and deployed are what let someone judge whether a tool’s output makes sense. On top of that, hands-on familiarity with AI systems — including their failure modes — looks more useful than either avoiding them or treating them as oracles. This is practical guidance rather than a claim about employer hiring patterns.
Is cybersecurity a dead-end job?
A question present in the SERP snapshot. The strongest evidence available on the direction of the occupation is that BLS projects 29% employment growth for information security analysts from 2024 to 2034, with about 16,000 openings per year, and identifies AI among the technologies increasing demand (BLS). That is growth rather than contraction, for one occupation in one country, over one projection window.
No earnings claim is made here, and readers should be wary of any article that answers pay questions with a confident number and no dated, authoritative source.
How organizations can prepare for AI-driven security changes
A framework, not a set of rules. Each item is a question to answer with your own evidence. The structure below is NewsForge analysis, informed by the governance and lifecycle practices in the cited guidance.
Identify suitable and unsuitable automation use cases
Sort candidate tasks by volume, how well-defined the input is, and how bad the worst error would be. NewsForge analysis: high volume plus low blast radius is where to start; low volume plus high blast radius is where to be slowest. The sorting exercise is cheap and produces a defensible order of adoption, which is more than most tool selections start with.
Keep humans responsible for consequential decisions
Write down which decisions require a named person to approve them, before deploying anything that could make those decisions on its own. Assigned roles and accountability are foundational to the NIST framework rather than an afterthought (NIST AI RMF 1.0). NewsForge analysis: doing this in advance is what distinguishes a governance arrangement from an argument after an incident.
Test outputs and monitor failure modes
Evaluate in your own environment, on your own data, and keep monitoring after deployment — a practice the joint secure-AI guidance builds into the operation phase (NCSC/CISA), and one the deployment-focused guidance addresses for externally developed systems (Deploying AI Systems Securely). NewsForge analysis: vendor evaluations, even honest ones, ran under conditions that are not yours.
Secure AI systems as part of the broader attack surface
Inventory them. Apply the same access control, logging, dependency management and review you apply to other software, and work from published guidance on secure deployment and operation of AI systems (Deploying AI Systems Securely; Guidelines for Secure AI System Development), checked against the attack classes NIST catalogues (NIST AI 100-2e2025).
Train teams to evaluate both AI capabilities and limitations
NewsForge analysis: a team that can only use a tool depends on it; a team that can interrogate it can decide when to ignore it. The second is what oversight actually requires, and it is the difference between a human in the loop and a human on the approval screen.
What changes next?
The following NewsForge analysis identifies signals teams can observe without assigning dates, probabilities or market projections.
Signals that automation is affecting specific tasks
Watch for changes in how junior work is structured, whether job descriptions shift from performing tasks to supervising them, and whether teams report that verification is genuinely cheaper than the work it replaced. Each of those is observable inside an organisation without waiting for industry-level data.
Signals that human oversight remains essential
Watch for incidents caused by automated action, disputes over responsibility when a system fails, and organisations quietly reintroducing human approval steps after removing them. The third is the most informative and the least announced.
Questions employers and practitioners should revisit
What evidence would change our mind about this tool? Who is accountable when it is wrong? What can we no longer do ourselves because we stopped doing it?
NewsForge analysis: teams evaluating automation should define which decisions need contextual human review and named accountability, consistent with the governance practices in NIST AI RMF 1.0.
The practical takeaway is a review, not a position. Go through your own security work and sort it: which parts could be safely automated, which decisions require an accountable human reviewer, and what evidence — not marketing material — you would need before adopting an AI security tool. That exercise produces a better answer for your organisation than any general claim about whether cybersecurity will be replaced by AI, including broad industry claims.
Frequently asked questions
Will AI replace cybersecurity jobs? The U.S. Bureau of Labor Statistics projects 29% growth for information security analysts from 2024 to 2034 and about 16,000 annual openings, and names AI among the technologies increasing demand (BLS). That is a projection for one occupation in one country. NewsForge analysis: the defensible framing is that AI acts on tasks and roles are bundles of tasks, so the first effect worth examining is a change in what security work consists of.
Which cybersecurity jobs are hardest for AI to replace? NewsForge analysis, informed by NIST AI RMF governance practices and not a finding: work that depends on organisational context, judgement under incomplete information, communication with affected people, and formal responsibility for a decision — the areas where the framework places named human accountability and context-sensitive governance (NIST AI RMF 1.0). No role is claimed here to be safe from change.
Is cybersecurity a dead-end career? One of the People Also Ask questions in the supplied SERP snapshot (checked 9 August 2026, 20:15:26 UTC). The available evidence on direction is the BLS projection of 29% growth and about 16,000 annual openings for information security analysts over 2024–2034 (BLS) — growth rather than decline, for that occupation, in that country, over that window.
Should cybersecurity students learn AI? NewsForge analysis: yes, in two senses — as tools whose output you must be able to verify, and as a category of system you may be asked to defend, given the attack classes NIST catalogues (NIST AI 100-2e2025) and the lifecycle security expectations in joint government guidance (NCSC/CISA; Deploying AI Systems Securely). Learning either without security fundamentals underneath is the weaker option.
Sources
- National Institute of Standards and Technology, Artificial Intelligence Risk Management Framework (AI RMF 1.0), 26 January 2023. Accessed 9 August 2026.
- National Institute of Standards and Technology, Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations, 24 March 2025. Accessed 9 August 2026.
- UK National Cyber Security Centre, CISA and international partners, Guidelines for Secure AI System Development, 27 November 2023. Accessed 9 August 2026.
- National Security Agency, CISA, FBI and international partners, Deploying AI Systems Securely, 15 April 2024. Accessed 9 August 2026.
- U.S. Bureau of Labor Statistics, Information Security Analysts, Occupational Outlook Handbook, 28 August 2025. Accessed 9 August 2026.
- ISC2, 2024 ISC2 Cybersecurity Workforce Study, 31 October 2024. Accessed 9 August 2026.
- Federal Bureau of Investigation, FBI Warns of Increasing Threat of Cyber Criminals Utilizing Artificial Intelligence, 8 May 2024. Accessed 9 August 2026.
- FBI Internet Crime Complaint Center, 2024 IC3 Annual Report, 23 April 2025. Accessed 9 August 2026.
