A masked gap doesn’t disappear. It compounds. And the interest is coming due in the one currency we’ve stopped minting: senior identity expertise.
For four years the industry told itself a story about a shortage. From 2021 to 2024 the headline was the cybersecurity skills gap: millions of unfilled roles, a number quoted in every board deck. Then, sometime in 2025, the story went quiet. Not because we solved it. Because we changed the subject to AI.
Here’s the part no one is putting on the board slide. The gap didn’t close. We financed it. AI and agents let us defer the hiring, defer the training, and defer the succession planning, and deferral is not payment. It’s a loan against a future that arrives on schedule.
Watch how quietly the subject changed. ISC2, the organization whose annual study was the “we need four million more people” headline, stopped publishing a global workforce-gap number in its 2025 study and reframed the whole conversation around skills, with AI now the single most-needed one at 41%. The shortage didn’t get counted as solved. It stopped getting counted. Meanwhile demand for security people never actually fell. US job openings rose 12% to roughly 514,000. What fell was our willingness to staff it: in 2024, 38% of organizations froze hiring, 25% ran layoffs, and 31% had no entry-level security staff at all. We didn’t fill the roles. We put an agent in the chair and moved on.
The collateral on the loan is bad
Every loan has collateral, and ours is the quality of the agents we’re borrowing against. That collateral is not what the marketing implies.
When skilled people don’t build and supervise the automation, the automation doesn’t quietly know security. It produces confident, plausible, insecure work. Veracode tested more than a hundred models and found that 45% of AI-generated code failed security tests, introducing a known vulnerability class. Crucially, bigger and newer models were not safer, so you cannot wait this one out with a model upgrade. The human failure mode is worse than the machine one: in a controlled Stanford study, developers with an AI assistant wrote less secure code while being more confident it was secure. And the volume outruns whoever is left to check it, because AI-assisted teams ship three to four times more code and ten times more security findings.
That is the shape of the debt. We masked a shortage of expertise with a tool that requires expertise to be safe, then thinned the ranks of the experts who make it safe. The gap didn’t leave. It moved downstream and started compounding.
Identity is where the balloon payment lands
Now make it concrete, because this is where a CIdO has to look. The control plane every one of these agents runs on is identity. In 2025, 82% of CrowdStrike’s detections were malware-free: attackers logged in with valid credentials rather than breaking in. Credential abuse is now the single most common way breaches start. The workload underneath has exploded. Machine and agent identities now outnumber humans by roughly 82 to 1, and when organizations were asked who owns the identity and access of their AI agents, only 9% said their IAM team does.
Here is the reframe no workforce study will hand you, because none of them even measures it. The discipline the entire AI-security problem now depends on is the one nobody is counting. The published skills-gap lists name “AI security” and “cloud security,” never identity as its own line. So the identity-specific shortage doesn’t show up as a statistic. It shows up as an unowned agent with more access than it needs, standing on the exact control plane attackers already prefer. That’s not a hiring metric. That’s the balloon payment.
We know how this movie ends, because we’ve watched it
If the compounding sounds abstract, we have a fully depreciated example sitting in production. Decades ago the industry decided mainframe skills were legacy, stopped training successors, and kept depending on the systems anyway. The result, audited and on the record: federal systems up to sixty years old still running COBOL, with “a dwindling number of people available with the skills needed to support them.” We didn’t retire the systems. We retired the people who understood them, and now we pay a premium to a shrinking pool to keep critical infrastructure alive.
We are running that exact experiment again, only faster. AI is already absorbing the entry-level rung where the next generation was always trained. Workers aged 22 to 25 in the most AI-exposed jobs have seen roughly a 16% relative decline in employment, and Gartner projects AI will handle more than half of Tier-1 security-operations work by 2028. Cut the bottom rung, and you don’t just lose juniors. You stop manufacturing the seniors who supervise the agents. Identity is on track to become the new COBOL: critical, invisible, and one automation cycle away from being under-staffed. The difference is that the systems it guards are under active attack today.

Pay the principal now, on purpose
The answer is not to slow down on AI. It’s to stop pretending automation is payment and start treating it as the loan it is, then pay down the principal deliberately, while it’s still cheap.
That means three moves, and they are leadership moves, not tooling ones. First, keep humans in the loop by design. Gartner’s own position is that there will never be an autonomous SOC, because automation bias is a documented, measured failure mode that trained verifiers, not more automation, are what contain. Second, rebuild the training ground you just automated away. Do it deliberately, through apprenticeship and rotation, because the World Economic Forum estimates that of every hundred workers, 59 need reskilling by 2030 and 11 won’t get it. The new junior competency is supervising agents, and it has to be taught. Third, put your senior identity expertise where the risk actually concentrated. That means specifying, governing, and checking the agents now standing on the control plane, rather than treating identity as the box the automation happens to run in.

The organizations that will look smart in 2028 are not the ones that automated fastest. They’re the ones that automated and kept minting the expertise the automation runs on. A skills gap you mask with agents doesn’t go away. It goes quiet, compounds in the dark, and comes back bigger, this time wearing your own credentials.
References
- 2025 Cybersecurity Workforce Study. ISC2, Dec 2025. https://www.isc2.org/Insights/2025/12/ISC2-Publishes-2025-Cybersecurity-Workforce-Study
- 2024 Cybersecurity Workforce Study. ISC2, Oct 2024. https://www.isc2.org/Insights/2024/10/ISC2-2024-Cybersecurity-Workforce-Study
- Cybersecurity job openings rise ~57,000 (514,359 total). CyberSeek / NIST NICE, Jun 2025. https://www.nist.gov/news-events/news/2025/06/new-cyberseek-updates-reveal-57000-increase-cybersecurity-job-openings
- 2025 GenAI Code Security Report. Veracode, Oct 2025. https://www.veracode.com/blog/genai-code-security-report/
- Perry, Srivastava, Kumar, Boneh. Do Users Write More Insecure Code with AI Assistants? Stanford / ACM CCS 2023. https://arxiv.org/abs/2211.03622
- 4x Velocity, 10x Vulnerabilities. Apiiro, Sep 2025. https://apiiro.com/blog/4x-velocity-10x-vulnerabilities-ai-coding-assistants-are-shipping-more-risks/
- 2026 Global Threat Report (findings). CrowdStrike, Feb 2026. https://www.crowdstrike.com/en-us/blog/crowdstrike-2026-global-threat-report-findings/
- 2025 Data Breach Investigations Report (Executive Summary). Verizon, Apr 2025. https://www.verizon.com/business/resources/reports/2025-dbir-executive-summary.pdf
- 2025 Identity Security Landscape (82 machine identities per human). CyberArk, Apr 2025. https://www.cyberark.com/press/machine-identities-outnumber-humans-by-more-than-80-to-1-new-report-exposes-the-exponential-threats-of-fragmented-identity-security/
- Identity and Access Gaps in the Age of Autonomous AI. Cloud Security Alliance (with Aembit), Mar 2026. https://cloudsecurityalliance.org/press-releases/2026/03/24/more-than-two-thirds-of-organizations-cannot-clearly-distinguish-ai-agent-from-human-actions
- IT: Agencies Need to Plan for Modernizing Critical Decades-Old Legacy Systems (GAO-25-107795). U.S. GAO, Jul 2025. https://www.gao.gov/products/gao-25-107795
- Brynjolfsson, Chandar, Chen. Canaries in the Coal Mine? Six Facts about the Recent Employment Effects of AI. Stanford Digital Economy Lab, Nov 2025. https://digitaleconomy.stanford.edu/publication/canaries-in-the-coal-mine-six-facts-about-the-recent-employment-effects-of-artificial-intelligence/
- >50% of SOC Tier-1 work AI-handled by 2028. Gartner, via SecureWorld, May 2025. https://www.secureworld.io/industry-news/ai-future-of-work-cybersecurity-beyond
- Predict 2025: There Will Never Be an Autonomous SOC. Gartner, 2025. https://www.gartner.com/en/documents/6027635
- Kahn, Probasco, Kinoshita. AI Safety and Automation Bias. CSET, Georgetown, Nov 2024. https://cset.georgetown.edu/wp-content/uploads/CSET-AI-Safety-and-Automation-Bias.pdf
- Future of Jobs Report 2025. World Economic Forum, Jan 2025. https://www.weforum.org/press/2025/01/future-of-jobs-report-2025-78-million-new-job-opportunities-by-2030-but-urgent-upskilling-needed-to-prepare-workforces/



