PwC asked security leaders if they would use fully autonomous AI for cybersecurity. Twenty-two percent said yes. The other 78% have apparently sat through a model that was very confident about a very wrong ticket. That same survey put quantum-resistant work at 21%, which is a polite way of saying most PKI still looks like last decade with better branding. You can brief both threats in the same quarter. Owning them is a different job.

The survey just told on us

Leaders can recite AI-enabled attackers, stolen identities, and a quantum timeline that keeps sliding left. What they will not do is hand production privileges to a system they cannot interrogate when incident response starts. That is a sane instinct. Autonomous threat-protection that can isolate hosts, rewrite firewall policy, or close tickets without a human in the loop is a privileged identity with a product name.

You already struggle to revoke service principals you issued on purpose. Giving a model a kill switch you cannot explain in the post-incident review is a career choice, not a maturity badge. PwC’s 22% is the honest number. Treat it as such.

Quantum sits in the same honesty gap. Twenty-one percent implementing quantum-resistant measures means most of you have a working group, a vendor briefing, and a certificate estate nobody wants to inventory. Cyber security programs love future threats because they do not page you at 2 a.m. Brute-force noise on the VPN does. So the future work slips, and the current work stays loud.

That stance is operational. The failure mode is an action that looks like a valid admin change, lands in the same logs as your change window, and only looks wrong after a customer is down. Your SOC will argue with the ticket. The model will have already moved on.

Cover graphic for the 2026 Microsoft Digital Defense Report
Microsoft’s 2026 Digital Defense Report describes a security environment that keeps getting more interconnected. Interconnected is a polite word for blast radius.

They’re shipping agents while we won’t grant them privileges

Microsoft’s 2026 Digital Defense Report is not subtle about the shape of the problem. More identities. More SaaS. More machine-to-machine paths that never wait for a human to click approve. Attackers already live in that mesh. Your threat detection has to as well, or you are watching yesterday’s perimeter while the session tokens commute without you.

Into that mess, Cloudflare is shipping Clef and Clef-flash: open-source decision models aimed at high-speed classification and agentic workflows, plus a reinforcement-learning platform so you can fine-tune those decisions on your own data. Fine. The interesting part is the assumption underneath. Vendors now treat classify-and-act as a default shape for software. Your estate will grow another decision layer whether the CISO voted in PwC’s survey or not.

Launch graphic for Cloudflare Clef open-source decision models
Clef is a decision model product. Treat the principal it runs as like any other admin account that can classify and then act.

Here is the collision. The market is productizing autonomy. Operators are refusing to grant it production teeth. That mismatch is where bad automation hides. A classifier that tags phishing, brute-force retries, or anomalous admin API calls is useful. A classifier allowed to mutate identity, routing, or backups without a two-person rule is an unowned admin.

Fine-tuning on “your own data” makes this worse before it makes it smarter. Tickets, detections, and the password someone pasted into a prompt become training material. That is a data-handling problem. Solve it before you argue about model quality.

Defense in depth still applies. A model is another control, not a substitute for the ones you skipped. If your threat-protection story is that the agent will sort it, write the design first.

Cybersecurity chores that beat another AI pilot

If you want less risk this quarter, skip the autopilot RFP. Do the work that makes both AI misfires and quantum surprises smaller. This is security hardening as operations, not as a slogan.

Start with identities that think. Every copilot, decision model, webhook, and assistant that can read tickets or touch infrastructure gets an owner, a scope, and a revocation path. Put them in the same inventory as service accounts. If you cannot answer who can disable MFA or punch a firewall hole, you are not ready to add a model that might try.

  • Immediate: Inventory every agent, classifier, and automation principal. Strip unused API keys. Require human approval for isolation, routing changes, and mass disable. Alert on those actions even when a “trusted” workflow performs them. Confirm brute-force lockouts and MFA-fatigue detections actually fire on a test account this week.
  • Immediate: Pull a crypto inventory for anything that signs, terminates TLS, or encrypts backups. Flag long-lived RSA, forgotten code-signing certs, vendor VPN concentrators, and device identities that never rotate. That list is your quantum-resistant program.
  • Ongoing: Prove threat detection with last-fired evidence. Tabletop an incident response path for a wrong autonomous action: who pauses the model, who restores the change, who talks to the business. Rehearse it like ransomware, because the outage looks the same to the help desk.
  • Ongoing: Keep defense in depth boring. Segment admin planes. Rate-limit authentication. Monitor bulk exports. Treat model fine-tuning data as sensitive, and ship model actions into the same log stream as human admins so you can see who did what without a special console.

Notice what is missing. There is no mandate to buy a new brain. You can improve outcomes with inventories, approvals, and tests you already know how to run. The AI vendors will still be there next quarter. Your unowned principals will not wait.

If your crypto inventory is a guess, sit down

Post-quantum migration is certificate hygiene with a deadline rumor attached. You do not need a physics seminar to start. You need to know where keys live, which vendors still only speak classical algorithms, and which systems will break if a handshake changes. Twenty-one percent implementing means most teams have not finished that list. Microsoft’s interconnected environment makes the list longer: more SaaS, more machine identities, more places a leftover signing key can mint trust.

This is a bad look for board reporting that lists quantum preparedness as green while the PKI ticket queue is empty. Green is a color. An inventory is a control.

Pair the two threads. Do not grant a decision model broad production rights until you can revoke it. Do not claim quantum readiness until you can name the systems that still terminate old crypto. Both are the same discipline: know what is privileged, know how it fails, and keep a human in the loop for irreversible actions.

The 22% who would let the model drive are allowed to be early. For everyone else, this is an operations shortage, and you can start paying it down on Monday without a new platform.

Sources

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.

Stay up to date with the latest news, releases and more.

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.