AI is reshaping security organizations along three fronts: securing the business's growing AI use, security's own adoption of AI in its operations, and adversaries' use of offensive AI. Where agent capability is proven, most visibly in vulnerability discovery and AppSec, a small team backed by agent fleets now produces the output of a much larger one, and the structures built for human-scale throughput, queues and approval chains especially, become the binding constraint rather than the safeguard. This paper's central finding is that the resulting reorganization is differential rather than uniform. Each of eleven security functions experiences a different mix of the three drivers and transforms differently: some consolidate (vulnerability management into a unified VulnOps pipeline), some split, some automate deeply behind a narrow human gate, and some barely change shape. What converges across all of them is the human role, from doing the work to validating agent output and owning decisions that cannot be delegated. The paper sets out a governance-in-the-loop model for decision rights, addresses the workforce and career-path consequences of the transition (particularly for entry-level roles), catalogs common failure modes, and recommends restructuring before resizing, starting with a bounded AppSec/VulnOps pilot.
Key Takeaways
- Three forces reshape security orgs: adversarial AI, security's own AI adoption, and the business's AI adoption — and the mix differs by function, so transformation is differential, not uniform.
- Agent fleets decouple team capacity from headcount; structures built for human throughput (queues, approval chains) become the binding constraint.
- Eleven functions map to seven transformation types: consolidation (VulnOps), bifurcation (AppSec, IAM), elevation in place (SOC/IR), heavy automation (GRC, TPRM, training), orchestration over tooling, net-new (platform/AI engineering, securing business AI), and slow/differently-shaped (OT/ICS).
- The human role converges everywhere on validation judgment and accountability, even as career tracks diverge.
- Recommended posture: restructure before resizing — redeploy existing staff into validation/fleet-management roles first, then let evidence drive headcount.
- Entry-level roles are most at risk of hollowing out, threatening the pipeline that produces future senior staff; deliberate rotation and mentorship paths are needed.
- Executive ask: charter differential restructuring, starting with a bounded AppSec/VulnOps pilot, with team size decided by results.
Contribute to Peer Review
Premier AI Safety Ambassadors

Premier AI Safety Ambassadors play a leading role in promoting AI safety within their organization, advocating for responsible AI practices and promoting pragmatic solutions to manage AI risks. Learn more about how your organization could participate and take a seat at the forefront of AI safety best practices.




