* [![perspectives](https://www.paloaltonetworks.com/perspectives/wp-content/uploads/2025/02/prespective-icon.png)](https://www.paloaltonetworks.com/perspectives)
* Why CISOs Need to Fully Embrace AI

English

* [English](https://www.paloaltonetworks.com/perspectives/why-cisos-need-to-fully-embrace-ai)
* [Français (French)](https://www.paloaltonetworks.fr/perspectives/why-cisos-need-to-fully-embrace-ai/)
* [日本語 (Japanese)](https://www.paloaltonetworks.jp/perspectives/why-cisos-need-to-fully-embrace-ai/)
* [简体中文 (Chinese -Simplified)](https://www.paloaltonetworks.cn/perspectives/why-cisos-need-to-fully-embrace-ai/)
* [繁體中文 (Chinese -Traditional)](https://www.paloaltonetworks.tw/perspectives/why-cisos-need-to-fully-embrace-ai/)
* [Deutsch (German)](https://www.paloaltonetworks.de/perspectives/why-cisos-need-to-fully-embrace-ai/)
* [한국어 (Korean)](https://www.paloaltonetworks.co.kr/perspectives/why-cisos-need-to-fully-embrace-ai/)

# Why CISOs Need to Fully Embrace AI

![Why CISOs Need to Fully Embrace AI](https://www.paloaltonetworks.com/perspectives/wp-content/uploads/2024/06/why-cisos-need-to-fully-embrace-ai.png)  
**By [Ali Khan](https://www.paloaltonetworks.com/perspectives/author/ali-khan/ "Posts by Ali Khan")** | **6 min read** |  
![share icon](https://paloaltonetworks.com/content/dam/pan/en_US/cxo-perspectives/images/cxo-share.svg)

* LinkedIn button ![linkedin-icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/microsite/cortex/images/share-linkedin.svg)
* Twitter share button ![twitter-icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/microsite/cortex/images/share-twitter-x-black.svg)
* \[Email share button ![email-icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/microsite/cortex/images/share-email.svg)\](mailto:?subject=Why CISOs Need to Fully Embrace AI\&body=Check out this article https%3A%2F%2Fwww.paloaltonetworks.com%2Fperspectives%2Fwhy-cisos-need-to-fully-embrace-ai%2F "Share in Email")
* ![copy-icon](https://www.paloaltonetworks.com/perspectives/wp-content/themes/csp2025/dist/images/icons/icon-share.svg)
  [](https://www.paloaltonetworks.com/perspectives/why-cisos-need-to-fully-embrace-ai/?pdf=download&lg=en&_wpnonce=e93479fd0d "Click here to download") MEET THE AUTHOR  
  ![](https://www.paloaltonetworks.com/perspectives/wp-content/uploads/2025/02/panw_master-twitter-profile-pic-400x400-1.png)  
  Ali Khan is the former Chief Information Security Officer at Better. Better is a pioneer in using digital technology to make home ownership simpler, faster, and more accessible....

[Learn more](https://www.paloaltonetworks.com/perspectives/author/ali-khan/)

## IN THIS ARTICLE

I'm not the first to say it, but it's a statement worth repeating: Artificial Intelligence (AI) is a game-changer for cybersecurity. If we trust AI and use it well, it will be a vital addition as a technologically advanced partner to the humans on our cybersecurity teams. If we fail to fully embrace AI, bad actors will use it as a weapon to overwhelm us.

AI is a double-edged sword in cybersecurity. Right now, the edge seems to be on the side of the cybercriminals. They use AI to accelerate and scale attacks, making many tactics, techniques, and procedures (TTPs) far more effective.

For example, by using off-the-shelf tools like ChatGPT, scammers can make their business email compromise (BEC) and phishing attacks more targeted and realistic. Would-be criminals with lower levels of expertise are using AI to launch far more sophisticated attacks than they would be if left to their own devices. What we're seeing now is just the tip of the iceberg.

Although AI has been around for a long time, it is still in its relative infancy in cybersecurity. Remember, ChatGPT has only been available since November 2022. Much of AI learning will be around the application stack as it evolves. It's only a matter of time before hackers use AI extensively to exploit software code.

## What AI Can Do to You

Cybercriminals are always searching for innovation and new attack methods. It's a simple business model: Whatever works. They already use AI effectively and are eager to use it more extensively.

Given these challenges, many CISOs are already wary of what AI may do **to** them instead of what AI may do **for** them. A London-based cybersecurity consulting company conducted a recent survey of 250 CISOs. Eighty percent of respondents said they believe AI is the most significant cyber threat to their businesses---and a whopping 81% believe the [risks of AI](https://diginomica.com/why-80-cisos-see-ai-biggest-threat-their-business) outweigh the advantages.^1^

This thinking, while understandable, is also short-sighted. We can't control the tools and technologies used by cybercriminals. And they will use AI exponentially---especially if we don't build strong defenses against AI-generated and AI-based attacks. If we rely solely on humans to defend against AI-based attacks, we are fighting with one hand tied behind our backs.

How do we build those defenses? In my opinion, the only way is to fight AI with AI.

## What AI Can Do for You

The reality is that AI can do specific jobs faster and more accurately than humans can. It can iterate more quickly than any human; it can craft code in less time than a human would. A single AI can do the job of 10 people if used for the right functions. AI is becoming more capable with each passing day.

In today's environment, we use AI to get alerts, monitor, and react to threats. Within the next year, we will use AI to monitor alerts and take independent actions.

Why? Because humans are not fast enough to keep pace with the threat landscape. We have to allow AI to do what it does with appropriate limitations. To allow AI to take independent actions, we must define its rights and responsibilities. Perhaps most importantly, we must trust it to do its job, just as we place trust in the humans on our cybersecurity teams.

## Another Member of the Team

If you don't use AI right, it's a useless tool that could make your organization less secure. As CISOs, I think one of our most important responsibilities is to create and nurture the culture of our organizations. If we embrace AI as a necessary tool, our teams are much more likely to embrace it.

I suggest an interesting way to think about AI---as another employee, a co-worker on the cybersecurity team with a lot of autonomy and the ability to execute important tasks comprehensively, accurately, and with enormous speed.

CISOs and our teams must be willing to trust AI to do many of the rote tasks that can bog down human workers. That means carefully evaluating what AI can do effectively, now and into the future, as the technology continues to evolve. Where does it supplement our humans, where can it take over the work of humans, and where can humans use it to be more effective? What tasks may be susceptible to human error that can be performed faster, better, and with less risk by AI?

We also must ensure that we are using AI responsibly. That means carefully crafting audits to expose errant actions. For companies in highly regulated markets, as we are at Better, we must take extra precautions when using AI. The same goes for other companies in finance or fields like healthcare. There are nuances to using AI. In our field, for example, we are concerned with potential discrimination. In healthcare, a medical misdiagnosis can have devastating consequences.

## Time to Join the Bandwagon

The ideas and even the cautions I've raised in this article are all factors to consider in determining how to use AI most effectively as a proactive, preventive, and, in many cases, defensive tool in the arsenal of our cybersecurity teams. The key point is that we should be thinking about how to use AI and not whether to use AI.

Fortunately, as CISOs, we are not alone. We have a community of support and shared knowledge. We have solid and innovative partners in the vendor community who have the resources---and the motivation---to invest in AI-powered solutions that can help us all.

We already see AI being used positively in real-time threat intelligence and response, automated incident response, behavioral analytics, security information and event management (SIEM), fraud detection, and more.

Looking ahead, I see tremendous opportunities to use AI in code patching and code generation, identifying bad code and fixing vulnerabilities automatically, completing those tasks faster and more accurately than the humans on our team. Humans free from those tasks have more time to build features that can generate revenue.

There will be a learning curve in using AI to strengthen our defenses, just as there is a learning curve for cybercriminals exploiting our vulnerabilities. We can't afford to let the bad guys get too far ahead of us on the curve. If they do, they will use AI to overwhelm us.

Now is the time for CIOs and our teams to embrace AI, recognize that AI is a game-changer in cybersecurity, and build a culture around securely adopting and trusting it.

*Better is a pioneer in using digital technology to make home ownership simpler, faster, and more accessible.*

*** ** * ** ***

*1. Chris Middleton, "[Why 80% of CISOs see AI as the biggest threat to their business,](https://diginomica.com/why-80-cisos-see-ai-biggest-threat-their-business)" Diginomica, October 11, 2023.*

* [AI](https://www.paloaltonetworks.com/perspectives/all-articles/?cat=ai)
* [Cyber as a Boardroom Topic](https://www.paloaltonetworks.com/perspectives/all-articles/?cat=cyber-as-a-boardroom-topic)

## Related Content

![](https://www.paloaltonetworks.com/perspectives/wp-content/uploads/2026/03/Why-Cybersecurity-KPIs-Are-Changing-featured.jpg) BLOG

### AI

**Why Cybersecurity KPIs Are Changing (And What This Means for Security Leaders)**

True cyber resilience is impossible to achieve without strategic and tactic...

[Helmut Reisinger](https://www.paloaltonetworks.com/perspectives/author/helmut-reisinger/ "Posts by Helmut Reisinger")
[](https://www.paloaltonetworks.com/perspectives/why-cybersecurity-kpis-are-changing-and-what-this-means-for-security-leaders/)  
![](https://www.paloaltonetworks.com/perspectives/wp-content/uploads/2026/03/Weaponized-Intelligence-featured.jpg) BLOG

### AI

**Weaponized Intelligence**

We are building the foundation that makes defense possible....

[Nikesh Arora](https://www.paloaltonetworks.com/perspectives/author/nikesh-arora/ "Posts by Nikesh Arora")
[](https://www.paloaltonetworks.com/perspectives/weaponized-intelligence/)  
![](https://www.paloaltonetworks.com/perspectives/wp-content/uploads/2026/03/RFP-Bottleneck-featured.jpg) BLOG

### AI

**From Weeks to Minutes: How We Applied an AI-First Transformation to the RFP Bottleneck**

Understanding why manual efforts burn hundreds of hours and are bottlenecki...

[Sandeep Uttamchandani](https://www.paloaltonetworks.com/perspectives/author/sandeep-uttamchandani/ "Posts by Sandeep Uttamchandani")
[](https://www.paloaltonetworks.com/perspectives/from-weeks-to-minutes-how-we-applied-an-ai-first-transformation-to-the-rfp-bottleneck/)  
STAY CONNECTED

## Connect with our team today

Job Level  
Sign me up to receive news, product updates, sales outreach, event information and special offers about Palo Alto Networks and its partners.  
By submitting this form, I understand my personal data will be processed in accordance with Palo Alto Networks [Privacy Statement](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown) and [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown).  
This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.
Reach out  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security?ts=markdown)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security?ts=markdown)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs?ts=markdown)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security?ts=markdown)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions?ts=markdown)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention?ts=markdown)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering?ts=markdown)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire?ts=markdown)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security?ts=markdown)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security?ts=markdown)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution?ts=markdown)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall?ts=markdown)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations?ts=markdown)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls?ts=markdown)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager?ts=markdown)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription?ts=markdown)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os?ts=markdown)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama?ts=markdown)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase?ts=markdown)

* [Prisma SASE](https://www.paloaltonetworks.com/sase?ts=markdown)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration?ts=markdown)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem?ts=markdown)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access?ts=markdown)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser?ts=markdown)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan?ts=markdown)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation?ts=markdown)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex?ts=markdown)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security?ts=markdown)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security?ts=markdown)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security?ts=markdown)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud?ts=markdown)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex?ts=markdown)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam?ts=markdown)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr?ts=markdown)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar?ts=markdown)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse?ts=markdown)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response?ts=markdown)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam?ts=markdown)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira?ts=markdown)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management?ts=markdown)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management?ts=markdown)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager?ts=markdown)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance?ts=markdown)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management?ts=markdown)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic?ts=markdown)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management?ts=markdown)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance?ts=markdown)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery?ts=markdown)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access?ts=markdown)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42?ts=markdown)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/frontier-ai-defense?ts=markdown)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses?ts=markdown)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy?ts=markdown)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence?ts=markdown)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond?ts=markdown)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us?ts=markdown)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales?ts=markdown)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility?ts=markdown)

* [Customers](https://www.paloaltonetworks.com/customers?ts=markdown)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations?ts=markdown)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom?ts=markdown)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/?ts=markdown)

* [Communities](https://www.paloaltonetworks.com/communities?ts=markdown)

* [Content Library](https://www.paloaltonetworks.com/resources?ts=markdown)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia?ts=markdown)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z?ts=markdown)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications?ts=markdown)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure?ts=markdown)

* [Sitemap](https://www.paloaltonetworks.com/sitemap?ts=markdown)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center?ts=markdown)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown)

* [Documents](https://www.paloaltonetworks.com/legal?ts=markdown)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector?ts=markdown)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language
