ComputerWeekly

The loop nobody’s checking the size of


AI is now doing a growing share of the frontline work inside security operations, triaging alerts, correlating signals across systems, drafting the first read on what’s happening and, in some cases, taking the first containment action itself. That shift was inevitable. No team of analysts can work at the speed or volume attackers now operate at, and pretending otherwise helps nobody. What hasn’t changed, and shouldn’t, is who’s accountable if that first action turns out to be wrong.

The UK’s National Cyber Security Centre (NCSC) set out what accountability requires in its May 2026 guidance on agentic AI. Organisations deploying an AI agent must name, in advance, who owns the system, who approves its access, who monitors what it does and who can stop it if something goes wrong. An agent nobody can understand, monitor or contain, the guidance states plainly, “… isn’t ready for deployment”. That’s specific and checkable. It’s also a different standard to the one now doing most of the talking across the industry, which has settled on saying a human is simply “in the loop” somewhere, without describing what that person knows or is responsible for.

That gap matters because two different jobs have quietly started sharing one description. The first is checking that an AI reached the right technical conclusion, whether it correctly read the signal and drew a sound inference from the data in front of it. The second is understanding a specific business well enough to decide what happens as a result, whether isolating an account stops a genuine attacker or locks out someone mid-way through a same-day payment run, whether a device can safely come offline for an hour or needs to stay live until a shift ends. The first is a technical check anyone competent can perform. The second depends on knowing the organisation in question, and it’s the harder one to verify from outside, which is exactly why it deserves more scrutiny than it currently gets.

Two recent UK cases show what’s at stake here. In April 2025 the Information Commissioner’s Office (ICO) fined a law firm £60,000 after a breach traced back to a dormant admin account nobody was actively engaged with, a failure of ongoing attention rather than of detection. In October 2025 the Cyber Monitoring Centre (CMC) assessed the cyber attack on Jaguar Land Rover as the most economically damaging cyber event in UK history, an estimated £1.9bn impact affecting over 5,000 UK organisations, following a shutdown that halted production for five to six weeks. Neither had anything to do with AI, and nothing here suggests either organisation made the wrong call. The first shows what happens when nobody is engaged with an account closely enough to notice something wrong. The second shows that even a reasonable, well-judged response carries a cost that scales directly with how much of the business sits behind the systems being contained, which is exactly why understanding that business in advance, rather than reconstructing it during an incident, matters as much as it does. JLR still reported a £485m loss for the quarter and needed a £1.5bn government-backed loan guarantee just to keep its supply chain solvent through the recovery. A mid-market business facing the same category of decision, with a fraction of that resourcing and no comparable cushion, has far less leeway if it gets the initial response wrong.

For a mid-market organisation deciding how detection and response should work, context isn’t a quality a provider either happens to have or doesn’t. It’s a specific, answerable list: who holds emergency access to your systems, which dormant accounts are legitimate and which aren’t, who has the authority to sign off a given action and under what circumstances. It’s entirely fair to ask whether a provider is working from that picture of your business, built and kept current, or from a more general sense of your sector. It’s just as fair to ask what happens to that understanding when the person who built it changes role or leaves, since knowledge that only exists in one person’s head rarely survives them.

Most of this information already exists somewhere inside the business, in identity and access records, approval chains and change logs, rather than needing to be written up specially for a security team’s benefit. The practical test isn’t whether this could theoretically be documented. It’s whether whoever is watching your systems day to day is working from it or reconstructing a rough guess each time something happens. One direct way to check: ask when that picture was last reviewed, and by whom. A slow or vague answer tells you more about the service than any brochure will.

The SOC’s frontline work is moving to AI faster than the standard for accountability is keeping up with it. What matters is not whether a human is involved, which should be true for every credible MXDR service, but instead what that person knows, and whether it’s built to last longer than their current shift or their current job. That’s a harder thing to promise than a person in a workflow, and a much more useful one for a mid-market business to ask for before the next serious incident exposes the gap.

Matt Smith is chief technology officer at Softwerx, a Microsoft security specialist working with mid-market organisations across the UK.



Source link