Torna alle notizie
SicurezzaAI Understanding briefing

Cognizant avverte che l'intelligenza artificiale accelera la scoperta delle vulnerabilità ma la risoluzione è ritardata

Il responsabile della sicurezza informatica globale di Cognizant afferma che l’intelligenza artificiale sta accelerando l’identificazione dei difetti informatici, ma le aziende faticano a risolverli abbastanza velocemente, creando un crescente divario di rischio.

4 min readRead the linked source
Source-provided image accompanying Cognizant warns AI speeds vulnerability discovery but remediation lags
Riferimento alla fonteFonte registrata
Editore
newindianexpress.com
Collegamento alla fonte
newindianexpress.comhttps://www.newindianexpress.com/business/2026/Sep/28/ai-speeds-up-vulnerability-discovery-but-enterprises-struggle-to-fix-risks-cognizant
Tipo di fonte
Fonte collegata: lo stato di fonte primaria non è stato stabilito.
ContestoComprendilo in 60 secondi

Inizia qui

Termini chiave

Intelligenza Artificiale (AI)
L’ampio campo dei sistemi di costruzione che svolgono compiti che richiedono il riconoscimento di modelli, il ragionamento, il linguaggio o il processo decisionale.
Iniezione rapida
Un modello di attacco in cui istruzioni dannose vengono inserite negli input del modello o nel contenuto recuperato.
Richiedi
Le istruzioni di input e il contesto forniti a un modello generativo.
Mettiti alla provaQuiz sull’etica dell’intelligenza artificiale

Cosa è successo

Cognizant’s global cybersecurity head Vishal Salvi told The New Indian Express that artificial intelligence is now enabling enterprises to discover cyber‑security vulnerabilities at “machine‑speed,” but the remediation process remains constrained by traditional business cycles, testing procedures and operational bottlenecks. Salvi described the situation as a “machine‑speed offence versus calendar‑speed defence,” noting that the gap between detection and fix is widening. He also warned that AI itself is becoming a new attack surface, with risks tied to models, prompts, agents and autonomous actions. While AI tools are already being used for vulnerability discovery, threat detection and incident investigation, Salvi emphasized that final decisions still require human judgement. He projected that the next major shift will be applying AI to remediation, helping organisations prioritise, validate and resolve vulnerabilities more quickly. Salvi highlighted a broader move from pure vulnerability management toward “exposure management,” where the focus is on reducing overall risk exposure rather than fixing individual flaws. For AI agents, he said enterprises are treating them as digital employees, applying zero‑trust principles, identity controls and runtime monitoring to curb potential misuse.

In a recent interview with The New Indian Express, Vishal Salvi, Cognizant’s global head of cybersecurity, explained that AI tools now enable organisations to scan codebases, configurations and network assets far faster than manual methods. He cited the ability of AI to correlate disparate signals, reduce noise and surface hidden relationships between vulnerabilities, technical debt and software dependencies.

Despite these advances, Salvi said that the remediation side remains hampered by legacy processes. Business approvals, testing cycles, and operational constraints often stretch the time needed to deploy patches from days to weeks, creating a “calendar‑speed defence” that lags behind the “machine‑speed offence” of AI‑driven discovery.

Salvi also warned that AI introduces its own security challenges. Models, prompts, and autonomous agents can become new vectors for exploitation if they are granted excessive permissions or lack robust safeguards. He highlighted the need for identity management, zero‑trust controls and continuous runtime monitoring for AI agents, treating them as digital employees rather than static tools.

Looking ahead, Salvi predicts that AI will not only discover vulnerabilities but also assist in remediation—prioritising fixes, validating patches and even automating certain remediation steps. However, he stressed that ultimate decision‑making must remain human‑led to ensure accountability and governance.

Dettagli della fonte: newindianexpress.com ↗

Perché è importante

The interview underscores a pivotal tension in the AI era: while AI can dramatically accelerate the discovery of security weaknesses, the slower pace of remediation can leave organisations exposed to attacks that exploit newly identified flaws. This dynamic has practical implications for any enterprise that relies on large, complex IT stacks, especially those that have accumulated technical and security debt. If remediation cannot keep up, the speed advantage of AI may paradoxically increase overall risk, as attackers can also leverage AI‑driven tools to exploit unpatched vulnerabilities. Salvi’s remarks also flag the emergence of AI‑specific attack vectors—such as malicious prompts or rogue agents—that extend traditional threat models. Understanding these new vectors is essential for policymakers and security teams as they craft guidelines for responsible AI deployment. Moreover, the shift toward exposure management suggests a strategic re‑orientation that could influence budgeting, staffing and vendor selection across the cybersecurity industry.

The speed disparity between AI‑driven detection and slower remediation creates a window of heightened exposure that attackers can exploit, especially as AI tools become more widely available to both defenders and adversaries.

AI‑specific attack surfaces—such as malicious or rogue autonomous agents—expand the traditional threat landscape, requiring new security controls, policy frameworks, and audit mechanisms.

The shift toward exposure management reflects a broader industry trend to assess risk holistically rather than patching individual flaws, which could reshape how security budgets are allocated and how success is measured.

If AI‑assisted remediation does not materialise as promised, enterprises may face escalating costs and reputational damage from repeated breach incidents, underscoring the urgency of developing practical, scalable solutions.

Interactive Mechanism

Meccanismo interattivo: come funziona realmente

Esplora la tecnologia alla base di questo sviluppo in modo interattivo.

Agent Lifecycle Stage:
1
User Intent & Planning: "Audit customer refund request #4092 and settle payment."
2
Tool Calling: Emits structured JSON call crm_get_transaction(id='4092').
3
Guardrail & Verification:🛡️ Paused: High-value action requires human operator sign-off.
4
Final Settlement: Refund recorded, email receipt dispatched, and audit log stored.
Core takeaway: An AI agent is not just a language model—it is a closed loop of planning, tool invocation, and environment feedback. Production systems require self-healing retries and strict human approval guardrails.
Verifica concettuale interattiva+10 Points
AI Ethics Quiz

Why can ethical evaluation not be reduced to one model score?

Cosa guardare dopo

Key indicators to monitor include: (1) adoption rates of AI‑assisted remediation platforms and any measurable reductions in patch‑time metrics; (2) emergence of industry standards or regulatory guidance addressing AI‑driven attack surfaces, especially around model and agent governance; (3) reports of incidents where AI agents with excessive permissions cause operational disruptions; and (4) corporate announcements of zero‑trust frameworks specifically extended to AI agents. Tracking these developments will reveal whether the promised AI‑accelerated remediation gains materialise and how quickly enterprises can close the detection‑remediation gap.

Vendor announcements of AI‑powered remediation suites and any disclosed metrics showing reduced mean‑time‑to‑patch (MTTP).

Regulatory bodies releasing guidelines or standards for AI model security, hygiene, and agent governance.

Incident reports where AI agents with over‑privileged access cause data leaks, service disruptions, or other operational harms.

Adoption of zero‑trust architectures that explicitly incorporate AI agents, including identity‑as‑a‑service (IDaaS) solutions tailored for autonomous systems.

Guide e quiz correlati

Etica dell'IAAgenti dell'intelligenza artificialeFuturo dell'IAMetti alla prova ciò che sai: prova un quiz gratuito sull'intelligenza artificialeCerca un termine AI nel nostro glossarioSegui il tracker della regolamentazione dell'IA
Lo hai trovato utile?