Reporting through 2025 records that the adoption of AI tooling in security functions has not resolved workforce shortages, which grew over the same period.
The Work Being Automated Is Not The Constrained Work
AI tooling is good at triage, correlation, summarising alerts and drafting. That is real and it removes genuine drudgery.
The failures in this corpus are not drudgery failures. Deciding that a support portal needs multi-factor at 25-0105, that connected applications require an inventory at 25-1207, that machine keys must be rotated as well as patched at 25-0723 — those are judgement and prioritisation, exercised against organisational resistance.
Automating the first category does not create capacity in the second, because the constraint was never analyst hours. It was people with standing to make a decision and time to follow it through.
And It Adds An Estate To Defend
Every AI system deployed is itself something to secure, with the properties recorded at 25-0224, 25-1009 and 25-1118: no boundary between instruction and data, tool access inheriting user authority, and hostile content reaching it through ordinary channels.
A security function that adopts these tools takes on new surface at the same time as it gains throughput. The corpus cannot say what the net effect is, and neither can anyone else yet.
The Honest Reading
This is not evidence that the tooling is useless — the workforce gap growing alongside adoption tells you nothing about the counterfactual, which is the same problem as the enforcement file at 25-1222.
What it does establish is that the expectation these tools would substitute for staffing has not been borne out in the reported figures. Graded medium.
Built on published workforce reporting, listed below, read against the AI files in this database. No counterfactual is available. Corrections: corrections@forensicpost.com.
- AI isn’t solving cybersecurity workforce woesCybersecurity Dive
- 2025 ISC2 cybersecurity workforce studyISC2