There's a super disappointing trend happening as a result of AI. It's the lack of judgement and taste. If your AI agent does everything for you, analyzes everything for you, interprets everything for you, writes everything for you.... then what is it you're actually doing? Reviewing the output of some(thing)one else's work? Babysitting a cron job?
I think this matters greatly in some areas and virtually not at all in others.
I don't necessarily care how my AI agent writes a quick powershell script to do some small task or even a full blown tool to do some thing, so long as it does the thing I need it to do, correctly.
But I certainly don't want it replacing my judgement and opinions and thoughts and perspectives on things that could materially impact an organization. Like say, the specifics of a pentest finding. Or the potential impact of that finding in the context of the environment and everything else I've found and discussions I’ve had with the client.
Why would I want to leave that up for interpretation by an AI agent that has incomplete data no matter how much I try and feed it.
Thats the ugly trend of offshoring all thinking and judgement and calling it "ok" because we're "reviewing the output."
The review is likely just going to be as agreeable as the AI that fed the answers. The way you would write up a risk or a finding is not at all how an AI agent would right it up.
I think that difference really matters.
I don’t say this as a condemnation for using AI but more so of the complete offshoring of all thinking and judgment and taste and perspective.
It’s a trap I’ve fallen into myself. In an effort to speed things up. So I write this even as a reminder to myself and to hold myself accountable to that.
In a race to speed everything up and be more efficient we’re sacrificing so much of our judgment and perspective and our expertise.
In the end I think it just makes everyone all sound the same and come to all the same conclusions.