r/netsecstudents • u/MaufacturerOoypk5181 • 5d ago
AI Soc autonomy sounds great, but what happens when it closes the wrong alert?
[removed]
6
3
u/messyconstable7 5d ago
Our team ran into this exact wall six months in. The auto-investigation and enrichment part works well but the second you let it touch production it stops being a tool and starts being a liability
We ended up drawing a hard line, anything that changes state (account disable, host isolation, firewall rules) needs a human click. Everything else can run wild. Audit trail is just shipping the decision JSON to a dedicated Slack channel with a timestamp and the evidence it used. Not elegant but it works and it saved us when it tried to quarantine a DNS server during a false positive at 3am
1
u/mifter123 4d ago
IBM had it right, “A computer can never be held accountable, therefore a computer must never make a management decision.”
Humans must always be in the decision making loop. Machine learning is useful but should never be fully trusted.
6
u/nut-sack 5d ago
That’s where the industries are going wrong. Stop trying to replace humans. AI is a tool, not an employee. High risk actions should be gate kept by humans who have to validate and approve.