AI is reshaping cybersecurity, but humans still have to stay in the loop: IBM’s Gaurav Agarwal

/ 3 min read
AI Hub

The World Economic Forum’s Global Cybersecurity Outlook 2026 found that 94% of respondents expect AI to be the biggest driver of change in cybersecurity this year, while 87% identified AI-related vulnerabilities as the fastest-growing cyber risk in 2025.

Gaurav Agarwal, vice president, Technology for IBM India & South Asia
Gaurav Agarwal, vice president, Technology for IBM India & South Asia

Artificial intelligence is changing cybersecurity on both sides of the fight, helping defenders process more data while giving attackers faster ways to find vulnerabilities and run social engineering attacks.

ADVERTISEMENT

The World Economic Forum’s Global Cybersecurity Outlook 2026 found that 94% of respondents expect AI to be the biggest driver of change in cybersecurity this year, while 87% identified AI-related vulnerabilities as the fastest-growing cyber risk in 2025. Separately, 77% of organisations have adopted AI for cybersecurity, mainly for phishing detection, anomaly response and user-behaviour analytics.

For Gaurav Agarwal, vice president, Technology, IBM India & South Asia, the starting point is the amount of data that security teams now have to process.

ADVERTISEMENT

AI moves from finding threats to deciding what matters

“Cybersecurity is all about looking at data,” Agarwal said, adding that defenders now have to look at data “at scale”. The old idea of a fixed security perimeter has changed with cloud, mobile devices and work-from-anywhere.

He gives an example. A user logs in from Bengaluru and then appears to connect from Delhi half an hour later. AI can flag the anomaly and either block the access or ask the user to reconfirm it.

The larger challenge, he said, is avoiding a flood of false positives. Security systems can produce so many alerts that teams end up reducing the sensitivity of detection. “AI can do that filtering very effectively,” Agarwal said. “You don’t have to dial down.”

That becomes more important as AI itself increases the number of vulnerabilities being found. Referring to Mythos, Agarwal said vulnerabilities are now being discovered at a “velocity and volume” that did not exist earlier. But not every vulnerability has the same impact in every environment.

Recommended Stories

The problem, therefore, is not only finding vulnerabilities but putting them in context and deciding what needs to be fixed first. That is where IBM’s Concert platform fits into Agarwal’s argument, helping prioritise vulnerabilities and fixes.

The WEF’s findings point in the same direction: AI is being used to accelerate detection, triage and response, but 54% of organisations cite insufficient knowledge or skills as a major hurdle to deploying AI for cybersecurity.

ADVERTISEMENT

AI agents bring machine speed to cybersecurity

The next shift comes with AI agents. As more machines interact with other machines, the security problem also moves beyond human identities and passwords.

“Even in tomorrow’s world with agentic, more and more machines will talk to machines,” Agarwal said. “So, you have to have these machine IDs secure in a manner that they can’t get leaked.”

Most Powerful Women In Business 2026
View Full List >

“Imagine a set of 100 agents acting at a crazy speed and then they’re doing something wrong,” Agarwal said. “The damage that can cause to reputation can be a lot larger.”

His answer is not to remove humans entirely. In a 10-step process, eight steps could be handled by an agent while a human remains involved in two steps to enforce policies and guardrails.

Agarwal expects roughly 30% of work could eventually be autonomous and rule-based, another 20-30% could be heavily AI-assisted, while 20-30% would remain primarily human. Today, he estimates the split is closer to 70-75% human work, with the remainder receiving some help from agents or bots.

Governance becomes the security layer

For enterprises, Agarwal said the bigger problem is increasingly not whether AI can do something, but how it is deployed and who remains responsible when it goes wrong.

ADVERTISEMENT

IBM’s 2025 Cost of a Data Breach report found that the average cost of a data breach in India reached ₹220 million, up 13% from 2024. Only 37% of organisations reported having AI access controls, while nearly 60% either had no AI governance policy or were still developing one. Shadow AI added an average ₹17.9 million to breach costs. 

Agarwal said clients are also worried about token costs, reputation and whether an AI decision can be explained years later. “AI is not a deterministic system. AI is a probabilistic system,” he said, pointing to the risk that even a small percentage of inaccurate outputs can create reputational damage.

ADVERTISEMENT

His concern is that companies can rush into individual AI use cases without first building a governance platform around them. “The value of platform is what clients are missing and still rushing into deploying use cases,” he said.

That governance also determines where models can run, what data they can access and whether their decisions can be traced. IBM’s watsonx.governance platform, Agarwal said, is designed to control model and agent usage and provide traceability around why an AI system made a particular choice.

ADVERTISEMENT

Ultimately, he puts accountability with the business, not the model provider. “The business has to be accountable and responsible,” Agarwal said. AI adoption, he added, is about “people, process, and technology”.

The human role, therefore, does not disappear as agents become more capable. “Human intelligence in saying this output of AI is good, bad, or ugly, is still human,” Agarwal said. “You can’t allow that judgment to be with AI.”

NEXT STORY