Machine Speed?  At What Cost?

Ira Levy
Chief Technology Officer   TachTech

“Machine Speed” is a term increasingly heard in industry discussions, and it is becoming a red flag.

Do you want a catastrophe at machine speed?  Who cares how fast something gets done if sound judgement and business context are absent.

The CEO described a vulnerability that an AI assessment tool had rated as critical.  It was not associated with any critical asset.  But the tool still called it critical.  The score was right.  The risk was wrong.

Only about 6% of published Common Vulnerabilities and Exposures (CVEs) are ever exploited in the wild.  CISA’s SSVC guidance recommends prioritizing vulnerabilities based on factors such as active exploitation and mission prevalence—not severity scores alone.  A person with knowledge of context knows this.  This model did not.

This is reflective of today’s critical workforce story.  The cybersecurity workforce is not being replaced by AI.  It is being redefined by it.

For years, the message from security leaders was straightforward: I need more people.  In 2026, the question has changed. The question is not simply which positions require a person, but what the consequences will be if the eliminated roles are entry-level positions.  

Stanford’s Digital Economy Lab found employment of workers aged 22 to 25 in AI-exposed occupations now sits 19% below where it would have been had they kept pace with less-exposed peers. The gap comes from reduced hiring, not layoffs. In cybersecurity, 56% of practitioners say AI has reduced the need for entry-level roles.   Yet 63% spend more time validating AI outputs and 89% have seen an AI recommendation led to a wrong outcome.  A Harvard Business School and Boston Consulting Group study with 758 professionals found AI users finished tasks 25% faster but were 19% less likely to get the answer right when working outside the model’s area of competence.  Speed and error moved together.  How badly do you want to run that experiment at machine speed at your company?

Entry-level roles are where professional judgment is developed.  Eliminating them does more than save a salary; it weakens the pipeline that produces the experienced professionals capable of catching critical errors. It also removes the individuals who stand between the organization and that 19% risk.

Three questions organizations should ask their teams and clients:

  1. Where does a human decision sit in this workflow, and can that person override the tool? The EU AI Act requires this for high-risk systems.  NIST’s AI Risk Management Framework asks the same.
  2. What should the people I already have really be doing? And how does that impact my relationship with my partners and customers?
  3. If we stop hiring juniors, who will be the senior in five years? Will someone else train them for me? How do I mitigate the risk of training staff just to have them stolen after my investment?

AI has knowledge.   Our people need understanding.  You simply cannot buy understanding with tokens.

The most valuable hires of the next few years will not out-triage a model.  I am certainly not suggesting that, but they will know when the model is wrong, and why it matters to the business.

So, are you implementing machine speed or building a better business? Which one does your board care most about?