Future-Proof Your Security: AI-Powered Detection and Response
Jay Sarwate, Alok Tongaonkar, Prutha Parikh, Ketan Nilangekar
BSidesSF 2025 — Here Be Dragons · Day 1 · Main
Overview
AI in cybersecurity is not new, but the arrival of generative AI has fundamentally changed who can use it and what it can be applied to. A panel of practitioners from Cohere, Palo Alto Networks, and a cross-section of security leadership explored the pre- and post-ChatGPT landscape, assessed the gap between AI hype and production readiness, and offered concrete guidance on the skills, ethics, and automation decisions that will define security work in the coming years. ---

Key moments
- 4:00 Pre-vs-post ChatGPT split: ML anomaly detection vs GenAI workflow automation
- 10:00 Enterprise GenAI challenge: hallucinations and precision gaps block production adoption
- 17:59 Unresolved: who is responsible when AI security agents take autonomous actions
- 31:59 Critical gap: moving AI security tools from demo-ware to production systems
- 34:00 GenAI unlocks unstructured data providing richer context in security alerts
- 39:59 Real use cases: AI code review and DDQ automation at Cohere security team
- 42:00 Alarming finding: hallucinations produce fake dependencies exploited for malware
Future-Proof Your Security: AI-Powered Detection and Response
Speakers: Jay Sarwate, Alok Tongaonkar, Prutha Parikh, Ketan Nilangekar
Conference: BSidesSF 2025 — April 26-27, 2025, San Francisco
YouTube: Watch on YouTube
Reading time: ~7 minutes
TL;DR
AI in cybersecurity is not new, but the arrival of generative AI has fundamentally changed who can use it and what it can be applied to. A panel of practitioners from Cohere, Palo Alto Networks, and a cross-section of security leadership explored the pre- and post-ChatGPT landscape, assessed the gap between AI hype and production readiness, and offered concrete guidance on the skills, ethics, and automation decisions that will define security work in the coming years.
Introduction
When the Ford Model T rolled off the assembly line in 1908, it was not just a car — it was a reorganization of labor, logistics, and society. Jay Sarwate, the panel moderator, opened with that analogy to frame the AI moment in cybersecurity: a technological shift so broad that it will change not just the tools but the structure of the work itself.
The BSidesSF 2025 panel brought together four practitioners positioned at the intersection of AI and security: Prutha Parikh, head of security at Cohere; Alok Tongaonkar, leading GenAI initiatives for cloud security at Palo Alto Networks; Ketan Nilangekar, a product leader helping customers navigate AI adoption; and Sarwate as moderator. Over 44 minutes, they covered the AI taxonomy as it applies to security, assessed the current state of the hype cycle, addressed ethical concerns including bias and accountability, outlined the skills that will matter most, and tackled the fundamental question of how to balance AI automation with human judgment.
Pre- and Post-ChatGPT: Two Eras of AI in Security
▶ Watch: AI categories and day-to-day change (04:00)
The panel consistently returned to a dividing line: AI in cybersecurity before and after the public release of ChatGPT.
Before ChatGPT, AI in security meant machine learning — anomaly detection, classification models, behavioral baselines. Data scientists worked largely in silos, often without deep security context, and had to pair with security practitioners to build useful products. Executives were skeptical, experiments required lengthy justification cycles, and AI capabilities were invisible to most end users.
After ChatGPT, the landscape shifted on multiple dimensions simultaneously. Generative AI made AI accessible to non-data-scientists, enabling security practitioners to experiment directly without waiting for a data science team. Executive skepticism flipped to executive mandate — suddenly there is organizational backing for AI investment rather than resistance to it. And new frameworks and tooling reduced the time from idea to working prototype from months to days.
Tongaonkar, drawing on his experience building cybersecurity analytics at Symantec, Boeing, and RedLock (acquired by Palo Alto Networks), described GenAI's most important new capability for security as handling unstructured data. "Previously, a lot of security products would stick to structured data sources because it was just easier to query them. GenAI has opened up a world of possibilities," he said. Alert enrichment is one example: rather than generating a bare alert, a GenAI-augmented system can pull in threat intelligence, vulnerability context, and historical behavior to provide a rich narrative around each finding — something that was impractical when every data source required structured schemas.
Parikh, at the AI-security intersection as head of security at a model provider, added that she now uses AI to parse complex AI and ML research papers on arXiv — a capability that did not exist before large language models. She also noted the use of AI for go-to-market activities, sales enablement, and internal operational work across security teams.
Hype vs. Reality: What AI Actually Solves Today
▶ Watch: Assessing the hype around AI security products (08:00)
The panel was direct about the gap between AI's promise and its current production performance in enterprise security contexts.
Nilangekar described two categories. First, there are problems where AI works well today: document summarization, explaining complex security findings to non-technical audiences, drafting policy language, automating due diligence questionnaire responses using RAG (retrieval-augmented generation) over knowledge bases, and generating detection rules or cloud security policies at scale. Second, there are problems where enterprise requirements outpace current capabilities: the margin for error is thin, hallucinations remain a material risk, and the precision required for autonomous security decision-making is not yet reliably achieved.
Tongaonkar observed that the market has moved through an initial hype peak and is now settling into more realistic expectations. The most promising near-term signal, he said, is the democratization of AI experimentation: security practitioners no longer need data science skills or data science partnerships to prototype AI-driven solutions. The barrier has dropped from months of setup to hours of tinkering.
The panel also flagged a deployment risk specific to AI in security tooling: AI-assisted code review and code generation can introduce vulnerabilities. Nilangekar cited real examples of AI coding tools inserting actual malware into applications. "Use with caution" was his summary.
Ethical Concerns: Bias, Privacy, and Accountability
▶ Watch: Ethical challenges in AI adoption (14:01)
Parikh led the ethics discussion with three imperatives for responsible AI deployment in security contexts:
Representativeness and explainability. Training datasets must be diverse and representative. Systems must be explainable — practitioners and customers need to understand not just what the AI decided but why. For GenAI tools specifically, the question "where are the citations?" is a practical proxy for trustworthiness.
Privacy by design. For security practitioners evaluating AI products, Parikh recommended prioritizing solutions with private deployment options, where the model runs in the organization's own environment. For teams building AI-augmented security systems, embedding privacy controls from the design stage — including zero-data retention options and opt-out mechanisms for individuals — is essential rather than optional.
Agentic accountability. As AI agents take actions autonomously — executing playbooks, modifying configurations, sending communications — the question of who is legally and operationally responsible becomes unresolved. "If the agents are taking action on your behalf, who's responsible? Is it the user? Is it the AI? Is it the company building the application? Is it the company building the models?" Tongaonkar framed this as one of the critical questions that must be resolved for enterprise adoption to accelerate.
The dual-use dimension also received attention. The same GenAI capabilities that help defenders automate threat detection help attackers lower the bar for launching attacks. Unit 42 at Palo Alto Networks, Tongaonkar noted, is already using AI to generate threat intelligence and find patterns across new attack campaigns — but adversaries are doing the same on the offensive side.
Skills for the AI Era
▶ Watch: Skills cybersecurity professionals need to stay relevant (22:02)
Asked what skills security professionals need to remain relevant, the panel converged on two themes: cross-functional collaboration and deliberate hands-on experimentation.
Tongaonkar observed that working on AI security products has required him to collaborate far more deeply with legal and InfoSec teams than in previous data science roles. AI is new enough to everyone — including legal, compliance, and executive functions — that building AI-augmented security systems requires explaining the technology, working through its implications, and reaching shared understanding across functions that previously operated independently.
Parikh recommended building a conceptual foundation in AI even for practitioners who will not train models. Cohere's LLM University is freely available; she also pointed to the "Applied Gen AI in Security" newsletter and TLDR AI as practical mechanisms for staying current in a field moving too fast for comprehensive coverage.
For the technical core, Tongaonkar enumerated the relevant concepts: prompt engineering, zero-shot and few-shot learning, fine-tuning, retrieval-augmented generation, and agentic AI architectures. But he emphasized that deep mastery is less important than getting started: "Pick a problem, pick a technology, pick a framework, and start playing around with it."
Nilangekar's Zoom note-taker example grounded the conversation in practice: AI tools are already embedded in everyday workflows, varying in quality, and practitioners are already making real-time judgments about when to trust and when to verify. The skill is not learning AI in the abstract — it is developing judgment about AI reliability in context.
Human Judgment in an AI-Augmented SOC
▶ Watch: Balancing AI automation with human oversight (28:02)
The panel's most practically-oriented exchange covered the human-in-the-loop question: as AI automation expands, where do humans remain essential?
▶ Watch: The challenge of moving from demo to production (32:02)
Parikh's framing: use AI for speed and scale on routine tasks, and keep humans in the decision loop for consequential actions. AI as a "force multiplier" for work that is repetitive, high-volume, and lower-stakes; human oversight for decisions with significant operational or legal consequences.
Tongaonkar identified the key litmus test for AI in security as the system's ability to incorporate human supervision feedback into the model — at the model level or the application level. "As these systems get better at incorporating human oversight, the amount of human oversight required gradually decreases." The path to more autonomous security operations runs through systems that learn from human corrections rather than operating in open loop.
The panel also addressed the remediation gap — one of the most concrete current limitations of AI in security. Many tools can identify vulnerabilities and misconfigurations, but the gap between "here is the problem" and "here is the script to fix it, deployed across your cloud environment" remains wide. Closing that gap with AI-driven remediation, with appropriate human checkpoints, was cited as one of the highest-value near-term applications.
Notable Quotes
"Prior to ChatGPT, a lot of focus on using AI was on machine learning techniques for anomaly detection or classification. Post-ChatGPT, now there is a lot of focus on using generative AI for automating workflows, getting explanations about security issues, and exploring data using domain-specific query languages." — Alok Tongaonkar ▶ 04:00
"If the agents are taking action on your behalf, who's responsible? Is it the user? Is it the AI? Is it the company building the application? Is it the company building the models? These are important questions we will have to resolve for enterprise adoption to pick up." — Ketan Nilangekar ▶ 18:01
"Pick a problem, pick a technology, pick a framework, and start playing around with it. You don't have to learn everything that is happening. Just start with the problem you have." — Ketan Nilangekar ▶ 28:02
Key Takeaways
- The pre/post-ChatGPT divide is real and structural. Generative AI democratized AI experimentation for security practitioners, shifted executive sentiment from skepticism to mandate, and unlocked unstructured data as a usable security resource — all simultaneously.
- AI works well today for specific tasks, not general autonomy. Document summarization, due diligence questionnaire automation via RAG, alert enrichment, detection rule generation, and secure code review assistance are areas with demonstrated value. Fully autonomous decision-making remains limited by hallucination rates and precision requirements.
- Agentic accountability is an unresolved enterprise blocker. As AI agents take consequential actions, the legal and operational responsibility framework has not kept pace. Organizations adopting agentic AI for security workflows should define human oversight checkpoints explicitly.
- Cross-functional fluency is as important as technical AI knowledge. Working on AI security products now requires collaboration with legal, compliance, and business teams in ways that did not apply to traditional data science roles.
- The path to more automation runs through better human feedback loops. AI systems that incorporate human corrections improve over time and progressively require less oversight — making the investment in structured human-in-the-loop processes an investment in future automation capacity.
Reviews
Dr. Zero (Offensive Security Researcher) — WEAK
Four people from Cohere and Palo Alto Networks discussing the pre- and post-ChatGPT security landscape for 44 minutes. If you need someone to explain what RASP, RAG, and anomaly detection are in a panel format, this delivers. If you already know what year it is, you'll walk out with one good quote about agentic accountability and 43 minutes of your life spent.
Heather Calloway (CISO) — SOLID
The pre/post-ChatGPT structural divide in AI security is real and the panel names it accurately. The agentic accountability question — who is legally and operationally responsible when an AI agent takes a consequential security action — is the governance gap that will define enterprise AI adoption in security for the next several years. The panel surfaces the question without resolving it.