LIVE · cybersecurity feed
Live wire
ai

Companies want autonomous IT operations but hesitate to let AI act alone

Ninety percent of companies anticipate a shift toward autonomous IT operations within the next two years, envisioning agentic AI systems that independently plan and execute multi-step tasks. However, a significant majority, 77 percent, express hesitation in allowing AI to make operational decisions without human approval. This suggests that most organizations currently aim for a model where a…

ZeroDay News ·

Source: Help Net Security

Ninety percent of companies anticipate a shift toward autonomous IT operations within the next two years, envisioning agentic AI systems that independently plan and execute multi-step tasks. However, a significant majority, 77 percent, express hesitation in allowing AI to make operational decisions without human approval. This suggests that most organizations currently aim for a model where a human remains involved in the approval process, rather than fully autonomous systems.

Despite these aspirations, many companies are not yet prepared for such a transition. Only 41 percent report their IT environments are ready for autonomous operations, and a mere 19 percent of their IT operations are currently automated. This indicates a disconnect between strategic planning and current operational capabilities.

A key point of divergence exists between business and IT leaders and the technical specialists who implement these systems. While leaders are more optimistic about the adoption of autonomous IT, technical specialists are warier, particularly regarding the foundational groundwork. Specialists also tend to rate their organization's data readiness lower than leaders, suggesting a more realistic view of the challenges involved.

A critical obstacle to AI-driven IT is the lack of comprehensive visibility across the entire IT landscape. A vast majority of respondents, 96 percent, emphasize the importance of unified visibility across networks, applications, endpoints, and cloud environments for effective AI diagnostics. Yet, only 17 percent currently possess such unified visibility, with data often fragmented across silos. This issue is exacerbated by tool sprawl, which most companies acknowledge increases the need for system integration, despite also recognizing that consolidation would reduce operational friction.

Security and compliance concerns are the primary obstacles cited, with leaders weighing these issues most heavily. Technical specialists, on the other hand, more frequently highlight fragmented tools as a significant challenge. Other impediments include skills gaps and resistance to change within organizations.

Furthermore, many companies report insufficient oversight of AI agent performance and reliability, with 51 percent indicating a lack of adequate monitoring. There is also a general lack of understanding regarding employee AI usage and associated costs. Technical specialists express less confidence than leaders in the effectiveness of their AI governance, providing a concrete reason for maintaining human approval in operational decisions.

Looking ahead, nearly all respondents expect AI to transform the functions of frontline IT and service desk teams within two years. Anticipated changes include a reduction in overall service desk activity, a shift toward handling more complex issues, and a transition from reactive problem-solving to proactive prevention. Very few expect the service desk to remain largely unchanged. Already, a third of companies report their IT teams are highly effective at using AI to identify and resolve issues before employees notice them.

ai
ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

PCI SSC calls for human approval of AI agent actions involving cardholder data

The PCI Security Standards Council (PCI SSC) has released new guidance, "Security Considerations for AI Systems," aimed at securing artificial intelligence deployments within payment environments and defending against AI-assisted attacks. The advisory document, developed in collaboration with industry stakeholders, covers governance, deployment, access controls, testing, and the application of…

vulnerability

'AgentCorruption' Puts AWS Environments At Risk With Single Prompt

A recently disclosed vulnerability, dubbed 'AgentCorruption,' reportedly allowed attackers to compromise AWS environments through a single prompt directed at an AI chatbot. The flaw, now patched, was identified within AWS Bedrock AgentCore and could have enabled an attacker to gain control over an organization's entire fleet of AI agents.

ai

Lawmakers warn Google could expose Spirit Airlines data in $10 million AI training deal

More than 100 members of Congress have urged Google and Spirit Airlines to halt a proposed $10 million deal that would transfer Spirit's internal data to Google for the purpose of training artificial intelligence models. The lawmakers expressed significant concerns that even with de-identification safeguards, the data could still expose sensitive employee information.

security

Co-creator of Empire Market dark web marketplace given 40-year sentence

Raheim Hamilton, a co-creator of the dark web marketplace Empire Market, has been sentenced to 40 years in federal prison for his role in operating the platform. The 30-year-old Virginia native pleaded guilty earlier this year to a drug conspiracy charge and was ordered by U.S. District Judge Steven Seeger to forfeit over $100 million in Bitcoin and several properties in Virginia, in addition…

vulnerability

Hackers get $1,262,000 for 98 zero-days at Pwn2Own Ireland

The Pwn2Own Ireland 2026 hacking competition concluded with security researchers earning a total of $1,262,000 for demonstrating 98 unique zero-day vulnerabilities across various products. The three-day event, organized by Trend Micro's Zero Day Initiative (ZDI), saw 29 research teams targeting devices in seven categories, including mobile phones, AI infrastructure, and smart home devices.

breach

Thousands of wind and solar park systems sit exposed on the internet across Europe

A recent report by Modat and the Dutch government's cybersecurity center, NCSC-NL, has revealed that 8,547 industrial control systems at wind and solar energy facilities across 35 countries in and around the European Union are directly accessible from the internet. These systems, which should be isolated from public networks, range from basic login portals to turbine control interfaces…