Why AI and Automation Do Not Equal Better Security
DESIGNED TO DETECT THREATS: The National Security Authority (NSM) handed over the new Warning System for Digital Infrastructure (VDI) to the Norwegian Armed Forces in 2023. Then-NSM Director Sofie Nystrøm and Chief of Defence Eirik Kristoffersen attended the handover ceremony.
In 2023, Norway’s Chief of Defence Eirik Kristoffersen received an early Christmas gift from the National Security Authority (NSM): an intrusion detection system packaged in military-green boxes with a price tag amounting to 500 million kroner.
The intrusion detection system, known as “VDI” in Norwegian, consists of network sensors deployed in companies and organisations considered part of Norway’s critical infrastructure. VDI is a government-owned and operated tool to protect against attacks on digital networks and systems.
“These network sensors mainly work by flagging known threats, like identifying a familiar face in a crowd,” explains senior researcher Claudia Emilie Aanonsen (NUPI).
She lists several examples: “It could be new devices trying to log into a network, certain web searches, or someone persistently entering the wrong password.”
An idea of “total security” – not that simple
In the research article “Operationalising uncertainty: The automation of threat knowledge and situational awareness” (Security Dialogue), Aanonsen concludes that machine learning and automation do not naturally offer “better” security.
The senior researcher examined the systems, practices, and experiences related to cybersecurity by studying the Norwegian VDI. Today, such systems increasingly rely on machine learning to detect unusual or abnormal activity in a network – so-called anomalies. Machine learning is a branch of artificial intelligence (AI) that enables computers to learn from data and improve automatically, without being programmed for a specific task.
“For security work, the logic is simple: More data, better tools, and autonomous problem-solving will lead to fewer surprises and a safer digital world,” says Aanonsen.
But it is not quite that simple.
“A system that monitors everything going on in digital networks and automatically thwarts danger presents a worthy sales-pitch for absolute certainty. But reality is far less stringent and far more human than promises of emerging technologies suggest.”
Trusting a “gut feeling”
The idea is that machine learning should make it possible to monitor “everything”, detect all anomalies, and edge society closer to “total security”.
“The problem is that these systems do not eliminate uncertainty; they create new kinds. Network sensors generate vast streams of data and alerts, most of them false alarms,” says Aanonsen.
"Someone still has to decide what matters, when it matters, and why."
For her article, Aanonsen interviewed security analysts working with systems like VDI.
“Analysts sift through signals and lean on experience – trusting, as one put it, their ‘gut feeling’. Cybersecurity in practice is less about automated precision and more about continuous interpretation.”
When “everything” becomes suspicious
More strikingly, such systems do not only detect threats – they produce them, the NUPI researcher argues.
“When anything unusual is flagged, almost anything becomes suspicious. Danger is no longer a fixed category but something that shifts with interpretation. The boundary between normal and abnormal, safe and threatening, becomes porous. Security work turns into a constant search for patterns of difference, rather than a hunt for concrete or known enemies.”
This has significant consequences. Cybersecurity is not simply a technical challenge but shaped by human decisions, organisational priorities, and commercial interests. Engineers, analysts, policymakers, and companies all influence what counts as a threat and what falls beyond that scope. What is left out is rarely discussed.
“The idea of ‘total security’ – comparable to strategies for ‘total preparedness’ or ‘total defence’ – functions more as a political slogan than a realisable objective. Network sensors provide partial, moving snapshots rather than an omniscient view,” Aanonsen explains.
It depends on who is looking
“Knowing the threat – whether by machine or human – is always tied to perspective: who is looking, what tools they use, and what pressures they face. There is no all-knowing vantage point, only shifting positions within a landscape that constantly changes with new technologies.”
Analysts are well aware of this. But it challenges the common belief and trust in that more data and automation inevitably produce better security. Rather than accepting that more data, better data and the best AI model will deliver on this promise, cybersecurity should be understood as an ongoing negotiation between humans and machines, the NUPI researcher argues.
Understanding how advanced technology both creates new ways of detecting and handling threats, but also how it generates new problems, can lead to more realistic expectations of what “emerging technologies” actually do for us, she says:
“It can also bring attention to human judgement, critical thinking, and the messy, interpretive work that keeps systems running and makes the digital world legible. The broader lesson for current debates about AI is hard to ignore. Digital technology may be growing more powerful, but it does not replace humans. Predictions of smarter systems neatly solving complex problems deserves a healthy dose of scepticism.”