By Gerhard Eschelbeck
If you have run a security program at scale, you know this feeling: you have more data than you can act on, more alerts than you can triage, more vendors sending you more signals than you could ever meaningfully consume. And yet the work is still not getting done.
This is not a visibility problem. We solved visibility. The security stack has been generating increasingly good signals for years. The problem is the gap between knowing and doing.
Think about what actually happens after a critical finding lands. Someone has to pick it up, understand the context, find the right owner, create a ticket, follow up when it goes stale, verify that the fix was actually deployed, and confirm closure. That chain is almost entirely manual in most organizations. And because it is manual, it is slow, inconsistent, and the first thing to collapse when the team is stretched.
No security tool addresses this. SOARs automate what your tools already know, inside predefined workflows. AI copilots help you ask better questions faster to know the best next steps to take. Neither one runs the coordination and execution layer that sits between signal and verified resolution.
That is the capacity gap, and it is the actual ceiling on most security programs today.
Why more tools do not solve it
I have watched organizations add tool after tool over the past decade and emerge from each procurement cycle no less overwhelmed than before. The capability improves. The noise increases proportionally. The team stays the same size and tries to absorb both.
The implicit assumption behind every tool purchase is that human capacity is infinite, or at least elastic enough to absorb more input. It is not. At some point, adding more signals without adding execution bandwidth is actively counterproductive.
The framing that finally clicks for most security leaders is this: your tools tell you what is wrong. They do not fix it. Everything between the signal and the verified resolution is a human workload, and that workload multipies with every tool you add.
What changes when you add AI workforce capacity
The right question is not "can AI make my existing tools smarter." It is "can AI carry the work between my tools."
When AI acts as a genuine workforce member, not a query interface, several things change. Remediation follow-through happens reliably, not when someone has a moment. Vendor review cycles run on schedule, not when someone remembers. Ticket state reflects reality rather than what was last manually updated. The security program does not fall behind during a busy week.
This is not replacing human judgment. The decisions that require expertise, organizational credibility, or accountability still belong to the team. What changes is that humans are no longer spending their scarce time on the coordination and execution work that accumulates underneath every decision they make.
The leverage question
Here is the practical implication. A senior security analyst who spends 40 percent of their time on follow-through and coordination work has a very different leverage profile than one who can direct that work to an AI and focus on what actually requires their expertise. The organizational productivity gain is not marginal. It is structural.
The programs that will operate most effectively in the next few years are not necessarily the ones with the best detection or the most comprehensive tooling. They are the ones that figure out how to multiply the impact of the humans they have.
That requires treating AI workforce capacity as a real variable in how you staff and structure a security program, not as a feature you evaluate on a checklist.
Security has had enough tools for a while. What it has needed is capacity. That gap is now closeable.
__________________________________________________
Gerhard Eschelbeck is a former VP of Security Engineering and Privacy at Google and an advisor to Axari.