Înapoi la Știri
SecuritateAI Understanding briefing

Cognizant avertizează că AI accelerează descoperirea vulnerabilităților, dar remedierea întârzie

Directorul global de securitate cibernetică al Cognizant spune că AI accelerează identificarea defectelor cibernetice, dar întreprinderile se luptă să le repare suficient de repede, creând un decalaj de risc tot mai mare.

4 min readRead the linked source
Source-provided image accompanying Cognizant warns AI speeds vulnerability discovery but remediation lags
Referință la sursăSursa înregistrată
Editor
newindianexpress.com
Link sursă
newindianexpress.comhttps://www.newindianexpress.com/business/2026/Sep/28/ai-speeds-up-vulnerability-discovery-but-enterprises-struggle-to-fix-risks-cognizant
Tip sursă
Sursă conectată — starea sursei primare nu a fost stabilită.
ContextÎnțelege asta în 60 de secunde

Începeți de aici

Termeni cheie

Inteligență artificială (AI)
Domeniul larg al sistemelor de construcție care îndeplinesc sarcini care necesită recunoaștere a modelelor, raționament, limbaj sau luare a deciziilor.
Injecție promptă
Un model de atac în care instrucțiuni rău intenționate sunt inserate în intrările modelului sau conținutul preluat.
Prompt
Instrucțiunile de intrare și contextul furnizate unui model generativ.
Testează-teTest de etică AI

Ce sa întâmplat

Cognizant’s global cybersecurity head Vishal Salvi told The New Indian Express that artificial intelligence is now enabling enterprises to discover cyber‑security vulnerabilities at “machine‑speed,” but the remediation process remains constrained by traditional business cycles, testing procedures and operational bottlenecks. Salvi described the situation as a “machine‑speed offence versus calendar‑speed defence,” noting that the gap between detection and fix is widening. He also warned that AI itself is becoming a new attack surface, with risks tied to models, prompts, agents and autonomous actions. While AI tools are already being used for vulnerability discovery, threat detection and incident investigation, Salvi emphasized that final decisions still require human judgement. He projected that the next major shift will be applying AI to remediation, helping organisations prioritise, validate and resolve vulnerabilities more quickly. Salvi highlighted a broader move from pure vulnerability management toward “exposure management,” where the focus is on reducing overall risk exposure rather than fixing individual flaws. For AI agents, he said enterprises are treating them as digital employees, applying zero‑trust principles, identity controls and runtime monitoring to curb potential misuse.

In a recent interview with The New Indian Express, Vishal Salvi, Cognizant’s global head of cybersecurity, explained that AI tools now enable organisations to scan codebases, configurations and network assets far faster than manual methods. He cited the ability of AI to correlate disparate signals, reduce noise and surface hidden relationships between vulnerabilities, technical debt and software dependencies.

Despite these advances, Salvi said that the remediation side remains hampered by legacy processes. Business approvals, testing cycles, and operational constraints often stretch the time needed to deploy patches from days to weeks, creating a “calendar‑speed defence” that lags behind the “machine‑speed offence” of AI‑driven discovery.

Salvi also warned that AI introduces its own security challenges. Models, prompts, and autonomous agents can become new vectors for exploitation if they are granted excessive permissions or lack robust safeguards. He highlighted the need for identity management, zero‑trust controls and continuous runtime monitoring for AI agents, treating them as digital employees rather than static tools.

Looking ahead, Salvi predicts that AI will not only discover vulnerabilities but also assist in remediation—prioritising fixes, validating patches and even automating certain remediation steps. However, he stressed that ultimate decision‑making must remain human‑led to ensure accountability and governance.

Detalii sursa: newindianexpress.com ↗

De ce contează

The interview underscores a pivotal tension in the AI era: while AI can dramatically accelerate the discovery of security weaknesses, the slower pace of remediation can leave organisations exposed to attacks that exploit newly identified flaws. This dynamic has practical implications for any enterprise that relies on large, complex IT stacks, especially those that have accumulated technical and security debt. If remediation cannot keep up, the speed advantage of AI may paradoxically increase overall risk, as attackers can also leverage AI‑driven tools to exploit unpatched vulnerabilities. Salvi’s remarks also flag the emergence of AI‑specific attack vectors—such as malicious prompts or rogue agents—that extend traditional threat models. Understanding these new vectors is essential for policymakers and security teams as they craft guidelines for responsible AI deployment. Moreover, the shift toward exposure management suggests a strategic re‑orientation that could influence budgeting, staffing and vendor selection across the cybersecurity industry.

The speed disparity between AI‑driven detection and slower remediation creates a window of heightened exposure that attackers can exploit, especially as AI tools become more widely available to both defenders and adversaries.

AI‑specific attack surfaces—such as malicious or rogue autonomous agents—expand the traditional threat landscape, requiring new security controls, policy frameworks, and audit mechanisms.

The shift toward exposure management reflects a broader industry trend to assess risk holistically rather than patching individual flaws, which could reshape how security budgets are allocated and how success is measured.

If AI‑assisted remediation does not materialise as promised, enterprises may face escalating costs and reputational damage from repeated breach incidents, underscoring the urgency of developing practical, scalable solutions.

Interactive Mechanism

Mecanism interactiv: cum funcționează de fapt

Explorați tehnologia care stau la baza acestei dezvoltări în mod interactiv.

Agent Lifecycle Stage:
1
User Intent & Planning: "Audit customer refund request #4092 and settle payment."
2
Tool Calling: Emits structured JSON call crm_get_transaction(id='4092').
3
Guardrail & Verification:🛡️ Paused: High-value action requires human operator sign-off.
4
Final Settlement: Refund recorded, email receipt dispatched, and audit log stored.
Core takeaway: An AI agent is not just a language model—it is a closed loop of planning, tool invocation, and environment feedback. Production systems require self-healing retries and strict human approval guardrails.
Verificare interactivă a conceptului+10 Points
AI Ethics Quiz

Why can ethical evaluation not be reduced to one model score?

Ce să urmărești în continuare

Key indicators to monitor include: (1) adoption rates of AI‑assisted remediation platforms and any measurable reductions in patch‑time metrics; (2) emergence of industry standards or regulatory guidance addressing AI‑driven attack surfaces, especially around model and agent governance; (3) reports of incidents where AI agents with excessive permissions cause operational disruptions; and (4) corporate announcements of zero‑trust frameworks specifically extended to AI agents. Tracking these developments will reveal whether the promised AI‑accelerated remediation gains materialise and how quickly enterprises can close the detection‑remediation gap.

Vendor announcements of AI‑powered remediation suites and any disclosed metrics showing reduced mean‑time‑to‑patch (MTTP).

Regulatory bodies releasing guidelines or standards for AI model security, hygiene, and agent governance.

Incident reports where AI agents with over‑privileged access cause data leaks, service disruptions, or other operational harms.

Adoption of zero‑trust architectures that explicitly incorporate AI agents, including identity‑as‑a‑service (IDaaS) solutions tailored for autonomous systems.

Ghiduri și chestionare conexe

Etica IAAgenți AIViitorul IATestați ceea ce știți — încercați un test AI gratuitCăutați un termen AI în glosarul nostruUrmați instrumentul de urmărire a reglementărilor AI
Ai găsit asta util?