Logo
FrontierNews.ai

Why AI Agents Are Failing at Cybersecurity: The Data Foundation Problem

Most organizations are deploying AI agents for cybersecurity without the foundational data infrastructure these systems need to work effectively. A survey of over 850 IT and cybersecurity professionals across Australia and New Zealand found that while 52% to 62% of organizations are already using AI for cybersecurity, only about 20% say their security data is actually ready for an AI agent to use reliably.

What's the Real Problem with AI Agents in Security?

The issue isn't that AI agents are inherently flawed. It's that they're being deployed on fragmented, incomplete data foundations. An AI agent, like any intelligent system, can only act on the context it can reach. If that context is scattered across disconnected systems, incomplete, or inaccessible in real time, the agent becomes blind in exactly the places attackers are trained to exploit.

The timing makes this problem acute. Frontier AI has handed attackers something unprecedented: the ability to move at machine speed. Attacks that once took days to craft now take minutes. Yet most organizations are still relying on mixed or manual processes to respond to threats. Only 14% of organizations in both countries say they could respond to an AI-automated attack at machine speed.

Where Are Organizations Losing Visibility?

Monitoring blind spots are widespread and acknowledged. In Australia, 60% of organizations have knowingly identified at least one unmonitored area in their environment, with 33% reporting multiple gaps. In New Zealand, the problem is even more pronounced: 67% have identified at least one blind spot, and 26% report several gaps.

The causes are consistent across both countries:

  • Legacy Systems: Older infrastructure that is difficult to monitor with modern tools and lacks integration capabilities.
  • Skills Shortages: Security teams lack the expertise to consolidate and manage data across multiple platforms.
  • Fragmented Data: Security information is scattered across cloud, on-premises, and SaaS environments with no unified view.

Detection speed outside business hours reveals another critical vulnerability. Only 9% of Australian organizations would detect a compromise within five minutes after hours. More than a third in each country expect detection to take at least an hour. These are the windows attackers are built to exploit.

How to Build AI-Ready Security Infrastructure

  • Consolidate Data Sources: Pull security data from on-premises, cloud, third-party, IoT, and operational technology systems into a single, unified platform rather than layering point solutions on disconnected environments.
  • Prioritize Data Architecture Before AI Deployment: Ensure your security data is complete, searchable, and available in real time before deploying any AI agent. Deploying AI on a fragmented foundation hides readiness gaps rather than closing them.
  • Choose Open and Model-Agnostic Foundations: Avoid locking your critical security operations to a single AI provider. As frontier AI continues to evolve, organizations need flexibility to adopt new models and tools without rebuilding their entire data infrastructure.

Why Awareness Isn't Translating to Action

The disconnect between understanding the threat and responding to it is stark. Ninety percent of Australian respondents and 87% in New Zealand say their organization understands how frontier AI could be weaponized against them. Yet this awareness isn't driving operational change at the pace the threat demands.

In Australia, 28% of organizations say their response to AI-enabled threats has been mostly paperwork. In New Zealand, 52% say stronger enforcement has not meaningfully changed their leadership team's behavior. The pressure on leaders is mounting: under Australian law, directors can face personal fines and removal following a breach. Yet accountability has not yet translated into the infrastructure investments required.

Even organizations that have updated their incident response playbooks remain unconfident in their defenses. In Australia, 54% of respondents with updated playbooks from the past 12 months still say they remain unconfident in their defenses. In New Zealand, that figure is 49%.

What Does Machine-Speed Defense Actually Look Like?

When the data foundation is in place, genuine agentic security becomes possible. AI agents handle automated threat workflows at machine speed. Security teams gain unified visibility with no blind spots. Humans move to the top of the loop, making decisions rather than manually reconstructing context across disconnected systems.

The challenge is architectural. Fragmented tools produce fragmented visibility. Fragmented visibility produces a lack of machine-speed readiness. The path to machine-speed defense runs through the data foundation first, and that foundation should be open and model-agnostic so organizations are not locked to a single AI provider for critical security operations as frontier AI continues to evolve.

For both Australia and New Zealand, the next step for frameworks and organizations is the same: guidance needs to drive tool consolidation, not tool sprawl. The question now is whether the architecture choices being made today will get organizations to genuine agentic security before the threat widens the gap further.