Key takeaways
- "Security for AI" isn't a distinct discipline. AI systems need the same governance, access controls, and monitoring as everything else in the stack.
- Adopting AI often functions as an unplanned pen test, exposing pre-existing weaknesses like excessive permissions, weak identity controls, and poor data classification.
- AI's real advantage for defenders isn't securing AI itself — it's using AI to finally process, prioritize, and act on security data at a scale humans never could.
AI adoption is forcing organizations to confront problems they've ignored for years, especially around data governance, identity management, and access controls. The real story isn't how to secure AI as its own category — it's how AI is exposing those long-standing gaps, and how it's finally giving defenders a way to keep up.
Varonis recently sat down with cybersecurity leaders Mike Privette, the mind behind Return on Security, and Matt Lock, former Field CTO at Varonis, to unpack how AI is reshaping both sides of that equation. Here are the key takeaways from their conversation.
Security for AI vs. AI for security
It boils down to this: Security for AI isn’t distinctive, it’s security. AI systems are simply another piece of an organization’s technology stack that require the same governance, access controls, monitoring, and protection as the rest.
When AI was first introduced, early security efforts took a narrow view: protecting chatbots and models, preventing leakage, securing system prompts. That didn't last. The industry quickly moved from protecting AI to using AI to supercharge cybersecurity.
It's the same trajectory cloud computing took. Companies once marketed themselves as cloud companies, but today, using the cloud is simply assumed. Matt expects AI to reach that same point, where the question isn't whether a product uses AI, but whether it delivers better security outcomes because of it.
Why AI exposes existing weaknesses
An organization adopting AI opens itself up to what Mike calls “unexpected pen tests," because they quickly face a reality check on the level of unintended access an agent could have. That's because deploying tools like Copilot or Claude reveal excessive permissions, weak identity controls, poor data classification, and other issues.
Agents accessing systems autonomously may also discover pathways security teams would not have otherwise anticipated. And for agents to do so in split seconds means that a sole bad actor with access to an organization’s unsecured AI can do serious damage in a short amount of time.
AI vs. AI: The new security arms race
Thanks to AI, attackers are seeing increases in both speed and scale. Matt points out that cybercriminals don’t care about compliance, governance, or guardrails. They’ll do whatever it takes to get what they’re after. In many cases, that’s data.
For decades, cybersecurity has largely been reactive. AI may offer the first technology that allows defenders to be proactive. With things like automated detection, 24/7 monitoring, preemptive phishing takedowns and automated investigations, the playing field has certainly leveled.
Matt and Mike also propose an interesting tactic: making attacks too expensive for attackers. Strategies like AI honeypots and AI labyrinths can waste attacker time, burn through an attacker’s tokens, and force attackers through useless paths.
Using AI to supercharge security
AI’s biggest impact is enabling defenders to operate at machine speed. Security teams generate enormous amounts of data but struggle to sort through it manually.
With AI, security teams can easily:
-
Investigate alerts
-
Correlate signals
-
Add context
-
Reduce false positives
-
Surface only meaningful threats
Rather than having SOC analysts review everything, AI can help ensure only prioritized incidents reach humans.
Vulnerability prioritization
Matt also argues that the hard part isn’t finding the vulnerabilities, it’s fixing and prioritizing them. Historically, cybersecurity has been constrained by human capacity. AI changes that by helping enterprise security teams process more data, analyze more signals, reduce response time, and scale expertise across the security team.
The future of cybersecurity, then, is about knowing which ones are important.
The backlog might be ten million vulnerabilities today and a hundred million tomorrow.
— Matt Lock on why there’s a growing need for AI in security.
Security fundamentals still win
Despite the excitement around AI security, the conversation repeatedly comes back to the same thing: organizations need to focus on the fundamentals. Every AI initiative relies on accurate permissions, clean identity models, and data governance.
Data and identity remain the core problems behind cybersecurity. An organization without control over their data, identity, and access opens themselves to immense risk. Matt has preached this to other cybersecurity professionals for over a decade, but he's only now hearing others say the same thing back to him.
The real AI security shift
For all the discussion around agents, autonomous systems, vulnerability discovery, and AI-powered attacks, Matt and Mike repeatedly return to the same conclusion: AI is changing cybersecurity, but it's not changing what cybersecurity is trying to accomplish.
The industry’s first reaction to AI was to ask: How do we secure AI? The more important question turned out to be: How do we use AI to solve security problems we've struggled with for decades?
If their predictions hold true, the future of cybersecurity won't be defined by who adopts AI first. It'll be defined by who uses it to solve the problems that have been there all along.
Watch their full conversation:
Ready to secure everything you build and run with AI?