AI Security Analyst Cybersecurity Agents Tier 2 On-premise Updated September 2026
AI Security Analyst

AI Agent for Security Posture & Controls

Most security gaps are not unknown risks; they are controls everyone believes are in place. This agent compares what your framework claims against what your configuration and telemetry show, and reports the difference ranked by what an attacker could actually do with it.

Tested Controls checked against real configuration
Mapped Coverage traced to framework requirements
Ranked Gaps ordered by exploitable exposure
Evidenced Each finding cites the configuration read
Assesses
Identity configuration Network segmentation Endpoint coverage Logging completeness Backup posture Control frameworks

What is an AI security analyst?

An AI security analyst is a governed software worker that assesses security posture from observed evidence. It tests whether documented controls are operating using configuration and telemetry, enumerates the assets and accounts each control does not cover, maps coverage against a framework, and ranks the resulting gaps by exposure within the estate.

What it does

Tests controls against real configuration Enumerates the assets a control misses Maps coverage to framework requirements Collects and reviews granted exemptions Ranks gaps by estate-specific exposure

What it is not

Not a configuration change Not a penetration test or exploitation Not authority to accept a risk
The Posture Problem

The control was in the framework and not in the estate

Control assessments are mostly conducted by asking, and the answers are given by people describing the design rather than the deployment. Multi-factor authentication is enabled — except on the four service accounts that could not support it. Logging is comprehensive — except on the segment added during an acquisition.

Design is confused with deployment

A control is documented, approved and genuinely intended, and the exceptions that were granted to ship it are nowhere in the assessment.

Coverage is assessed in aggregate

Endpoint protection sits at ninety-four percent, and the six percent is the part that matters and is never enumerated.

Frameworks are answered, not tested

A control question is answered from the policy that requires the control rather than from evidence that it operates.

Gaps are ranked by severity label

Findings are ordered by a generic rating rather than by what an attacker could reach from where the gap actually sits.

The VDF AI Opportunity

What the estate shows, not what the framework claims

Verification

Read The Configuration, Not The Policy

Deployment over design.

Each control is assessed from the configuration and telemetry that would demonstrate it operating — enrolment records, policy assignments, log arrival, key rotation dates — rather than from the document stating that it is required.

  • Assessed from configuration and telemetry
  • Exceptions and exemptions enumerated
  • Coverage reported as the uncovered set
  • Evidence cited for every determination
Observed
Control State

Not documented state

EnrolmentAssignmentLog arrivalRotation

Coverage

The Six Percent, By Name

Aggregates hide the gap.

Coverage is reported as the specific assets, accounts and segments that fall outside a control rather than as a percentage, because the uncovered set is the finding and a percentage is a way of not stating it.

Enumerated
Uncovered Set

Named, not counted

AssetsAccountsSegmentsExemptions

Prioritisation

Ranked By What It Reaches

Not by a generic severity.

Gaps are ordered by what they would allow in your estate — what the affected asset can reach, what it holds, whether another control compensates — so remediation effort follows exposure rather than a label.

Contextual
Gap Ranking

Estate-specific

ReachabilityData heldCompensating controlBlast radius
Run sequence

How the AI Security Analyst runs a task

  1. STEP 01

    Establish the expected state

    The control baseline is taken from your framework, standards and policy so that assessment measures against what your organisation committed to rather than against a generic benchmark that nobody signed up to.

    Baseline extractionFramework mapping
  2. STEP 02

    Read the actual state

    Identity configuration, endpoint enrolment, network segmentation, logging pipelines, backup records and key rotation are read directly, because these show whether a control operates in a way that an attestation cannot.

    Configuration readTelemetry inspection
  3. STEP 03

    Enumerate the difference

    For each control the specific assets, accounts and segments outside it are listed by name together with any recorded exemption, replacing a coverage percentage with the set that a remediation plan can actually work through.

    Coverage differencingExemption collection
  4. STEP 04

    Weigh the exposure

    Each gap is assessed for what it would permit here — what the uncovered asset can reach, what data it holds, whether a compensating control limits the consequence — producing a ranking grounded in your topology.

    Reachability analysisCompensating controls
  5. STEP 05

    Report with the evidence

    Findings are issued with the configuration or telemetry that produced each determination cited, so a control owner can verify the finding directly instead of debating whether the assessment understood their environment.

    Evidence citationOwner routing
Integrations

Systems the AI Security Analyst connects to

Scoped, per-tenant credentials Every call written to the audit log No data copied to a third party
Specification

Inputs, outputs and runtime

Ingests
Control framework and baselineIdentity and endpoint configurationNetwork segmentation dataLogging pipeline stateGranted exemptions
Produces
Control determination with evidenceEnumerated uncovered setFramework coverage mapExposure-ranked gap listExemption review
Triggered by
Scheduled posture reviewPre-audit preparationAcquisition assessment
Human oversight
Control owners decide remediation and risk
Models
Open-weight LLMs you host — Llama, Qwen or Mistral class
Typical latency
Hours for a full control baseline pass
Deployment
On-premise or sovereign cloud with egress control
Data residency
Configuration evidence stays in your estate
Where it pays back

Where the Security Analyst pays back

Control Effectiveness Review

Test whether each documented control is actually operating across the estate it is supposed to cover.

Framework Coverage Mapping

Map each framework requirement to the evidence demonstrating it, and list the ones with no evidence.

Acquisition Posture Assessment

Compare an acquired environment against your control baseline and enumerate what is missing.

Logging Completeness Audit

Establish which systems are not sending the telemetry that detection rules assume is arriving.

Exemption Review

Collect every control exception granted, when it was granted, and whether the reason still applies.

Audit Evidence Preparation

Assemble the configuration evidence for each control ahead of an external assessment.

Comparison

AI Security Analyst vs chatbots and SaaS copilots

Control assessment has an unusual property: the organisations most confident in their answers are frequently the ones assessing design rather than deployment, because a well-written policy produces a well-answered questionnaire.

  Generic chatbot SaaS copilot VDF AI
Assessment basis Framework text Questionnaire Configuration and telemetry
Coverage reporting Not applicable A percentage The uncovered set by name
Exemptions Unknown Separate register Collected and reviewed
Gap ranking Generic severity Vendor score What it reaches in your estate
Evidence None Attestation Cited configuration
Changes configuration No Sometimes Never — owners remediate
Where the gap list lives Vendor service Vendor cloud Inside your own network
Controls

Governance and controls

A posture report is a ranked list of the ways into your organisation, so it needs the same handling as the estate it describes and the same restraint about acting on what it finds.

NIST CSFISO 27001 Annex ACIS ControlsNIS2 measures

Read-only assessment

No configuration is modified

No exploitation attempted

Findings are observed, not tested live

Findings carry evidence

Each determination cites its source

Risk acceptance stays human

Only owners may accept a gap

Report access restricted

Distribution limited to named roles

Exemptions surfaced

Granted exceptions reported, not hidden

Evidence it leaves behind

Configuration evidence record Coverage enumeration output Framework mapping trail Exemption review log
ROI snapshot

What changes after rollout

Verified Controls tested rather than attested
Named Uncovered assets listed individually
Prioritised Gaps ranked by estate-specific exposure
Evidenced Framework answers backed by configuration
Audience

Who runs the AI Security Analyst

Chief information security officer

Can distinguish between controls that are designed and controls that are deployed, and report posture to a board using enumerated exceptions rather than coverage percentages that conceal the interesting part.

Security architect

Sees which segments and account classes consistently fall outside the baseline, which usually points at a structural reason — an acquisition, a legacy platform — rather than at individual oversights.

Compliance and audit lead

Answers framework questions with configuration evidence attached rather than with policy references, which changes the character of an external assessment from discussion to verification.

FAQ

Questions about the AI Security Analyst

What is an AI security analyst?

It is an agent that assesses security posture from evidence: testing whether each control is actually operating using configuration and telemetry, enumerating the assets it does not cover, mapping coverage to framework requirements, and ranking gaps by exploitable exposure.

How is an AI security analyst different from a generic chatbot?

A chatbot can describe what a control framework requires. This agent reads your configuration and telemetry to establish whether the control is deployed, and names the assets where it is not.

Can an AI security analyst run on-premise on security configuration data?

Yes. A posture assessment is a complete description of where your defences are weakest, which is the single document you would least want to exist outside your own environment.

What does an AI security analyst produce, and in what format?

A control-by-control determination with evidence cited, the enumerated uncovered set for each control, a framework coverage map, and gaps ranked by what they would allow in your estate.

Where does an AI security analyst fit in a governed AI programme?

It assesses; it does not remediate. Changing a configuration, granting an exemption and accepting a risk are decisions owned by the accountable people, with the agent supplying the evidence.

Is this a penetration test?

No. It observes configuration and telemetry to determine whether controls are deployed and operating, and it does not attempt exploitation of anything. Those are complementary activities: a posture assessment tells you which controls are missing across the whole estate, while a penetration test demonstrates what a specific chain of weaknesses allows. Neither substitutes for the other.

How is this different from the SOC analyst agent?

Time horizon and subject. The SOC analyst works on events happening now, deciding whether a signal warrants attention. This agent works on standing state: whether the controls that should prevent those events are in place across the estate. One reduces the time to assess an alert; the other reduces how many alerts there are to assess, by finding the coverage gaps that generate them.

Can it accept a risk or grant an exemption?

No. It collects the exemptions that exist, reports when the stated reason no longer appears to apply, and routes the question to the accountable owner. Risk acceptance is an act with organisational consequences and a named owner, and an agent that could grant one would create exemptions nobody decided to take.

What if our asset inventory is incomplete?

That becomes the first finding, and usually the most consequential one. Coverage cannot be assessed against an unknown denominator, so where configuration sources disagree about what exists — endpoints in the identity platform that are absent from the asset register, segments with log traffic and no owner — those discrepancies are reported before any control determination that depends on them.

How does it rank gaps without knowing our business context?

It uses the context available in the estate: what the uncovered asset can reach across the network, what data classification is attached to it, whether other controls constrain the consequence. Where business criticality is recorded in your inventory it is used; where it is not, the agent says the ranking is based on technical reachability alone rather than presenting it as a business risk assessment.

Find the controls that exist only on paper

See the AI Security Analyst test your control baseline against actual configuration.