Last week's room at SCIF Summit DC had physical security operators, cyber defenders, AI policy people, and counterintelligence veterans sitting at the same table. That almost never happens. For most of my career those disciplines have run in parallel, each with its own conference, its own vocabulary, its own blind spot about what the others actually see.

That's the real finding from the trip. Not a new threat. A new geometry. The frontiers between domains are closing, and the professionals who used to guard them separately are now guarding the same terrain without a shared map.

Signal vs. Noise

Signals in the Noise argues that the hardest fraud to catch is the one built from true facts arranged to produce a false conclusion. Nobody in that room disagreed. What surprised me was how fast the conversation moved from "detecting bad actors" to "detecting bad patterns," because the actor doing the arranging is increasingly a machine, not a person.

Ask any operator in that room what worries them most and the answer converges fast: social engineering, amplified by AI. Not malware. Not zero-days. A voice clone of a CFO authorizing a wire. A pretext email written in a target's own syntax after a model trained on six months of their public posts. The attack surface hasn't changed. The cost of a convincing lie has collapsed to nearly zero.

Human Element of Tech

The second thread was harder to sit with. Insider threat programs are built to watch people. Access logs, behavioral baselines, disgruntlement indicators. Every one of those tools assumes the insider is human and has motive.

The room's consensus was that the next insider threat won't have motive. It will be an AI system operating inside the perimeter with real permissions and no governance wrapped around it, doing exactly what it was told, badly, at scale, before anyone notices the pattern. An ungoverned agent doesn't need malicious intent to cause the same damage a malicious insider would. It just needs unsupervised authority.

That's a governance gap, not a technology gap. Most insider threat frameworks were never built to ask "does this account have a face."

Operational Reality

Here's the piece that should worry boards more than either of the above: the decision cycle is compressing faster than the governance cycle can follow. Detection, verification, and action used to have daylight between them. That daylight was where human judgment did its work.

AI collapses that daylight. A model can recommend and execute in the same second a human would still be reading the alert. When decision compresses into action, the checkpoint has to move earlier, into the design of the system, because there is no longer a pause downstream where a person catches the mistake.

Boards that treat AI governance as a policy document to review annually are governing a decision cycle that no longer exists.

Monday Morning Takeaway

Pull the list of AI systems and agents with standing access in your environment and ask one question of each: if this system acted on bad information right now, with no human in the loop, how long before someone would notice. If the honest answer is longer than you'd like, that's not a technology problem. That's your next insider threat, and it already has credentials.

Reply

Avatar

or to participate