We Didn’t Close the Skills Gap. We Financed It.

From the Chief Identity Officer title card on a black background. Eyebrow: "Identity & the Workforce". Headline: "We Didn't Close the Skills Gap. We Financed It." with "Financed" set in oxblood. Dek: "AI agents masked the talent shortage. A masked gap compounds and comes back stronger." Byline: Nicholas Hunt, Chief Identity Officer, fromthecido.com.

A masked gap doesn’t disappear. It compounds. And the interest is coming due in the one currency we’ve stopped minting: senior identity expertise.

For four years the industry told itself a story about a shortage. From 2021 to 2024 the headline was the cybersecurity skills gap: millions of unfilled roles, a number quoted in every board deck. Then, sometime in 2025, the story went quiet. Not because we solved it. Because we changed the subject to AI.

Here’s the part no one is putting on the board slide. The gap didn’t close. We financed it. AI and agents let us defer the hiring, defer the training, and defer the succession planning, and deferral is not payment. It’s a loan against a future that arrives on schedule.

Watch how quietly the subject changed. ISC2, the organization whose annual study was the “we need four million more people” headline, stopped publishing a global workforce-gap number in its 2025 study and reframed the whole conversation around skills, with AI now the single most-needed one at 41%. The shortage didn’t get counted as solved. It stopped getting counted. Meanwhile demand for security people never actually fell. US job openings rose 12% to roughly 514,000. What fell was our willingness to staff it: in 2024, 38% of organizations froze hiring, 25% ran layoffs, and 31% had no entry-level security staff at all. We didn’t fill the roles. We put an agent in the chair and moved on.

The collateral on the loan is bad

Every loan has collateral, and ours is the quality of the agents we’re borrowing against. That collateral is not what the marketing implies.

When skilled people don’t build and supervise the automation, the automation doesn’t quietly know security. It produces confident, plausible, insecure work. Veracode tested more than a hundred models and found that 45% of AI-generated code failed security tests, introducing a known vulnerability class. Crucially, bigger and newer models were not safer, so you cannot wait this one out with a model upgrade. The human failure mode is worse than the machine one: in a controlled Stanford study, developers with an AI assistant wrote less secure code while being more confident it was secure. And the volume outruns whoever is left to check it, because AI-assisted teams ship three to four times more code and ten times more security findings.

That is the shape of the debt. We masked a shortage of expertise with a tool that requires expertise to be safe, then thinned the ranks of the experts who make it safe. The gap didn’t leave. It moved downstream and started compounding.

Identity is where the balloon payment lands

Now make it concrete, because this is where a CIdO has to look. The control plane every one of these agents runs on is identity. In 2025, 82% of CrowdStrike’s detections were malware-free: attackers logged in with valid credentials rather than breaking in. Credential abuse is now the single most common way breaches start. The workload underneath has exploded. Machine and agent identities now outnumber humans by roughly 82 to 1, and when organizations were asked who owns the identity and access of their AI agents, only 9% said their IAM team does.

Here is the reframe no workforce study will hand you, because none of them even measures it. The discipline the entire AI-security problem now depends on is the one nobody is counting. The published skills-gap lists name “AI security” and “cloud security,” never identity as its own line. So the identity-specific shortage doesn’t show up as a statistic. It shows up as an unowned agent with more access than it needs, standing on the exact control plane attackers already prefer. That’s not a hiring metric. That’s the balloon payment.

We know how this movie ends, because we’ve watched it

If the compounding sounds abstract, we have a fully depreciated example sitting in production. Decades ago the industry decided mainframe skills were legacy, stopped training successors, and kept depending on the systems anyway. The result, audited and on the record: federal systems up to sixty years old still running COBOL, with “a dwindling number of people available with the skills needed to support them.” We didn’t retire the systems. We retired the people who understood them, and now we pay a premium to a shrinking pool to keep critical infrastructure alive.

We are running that exact experiment again, only faster. AI is already absorbing the entry-level rung where the next generation was always trained. Workers aged 22 to 25 in the most AI-exposed jobs have seen roughly a 16% relative decline in employment, and Gartner projects AI will handle more than half of Tier-1 security-operations work by 2028. Cut the bottom rung, and you don’t just lose juniors. You stop manufacturing the seniors who supervise the agents. Identity is on track to become the new COBOL: critical, invisible, and one automation cycle away from being under-staffed. The difference is that the systems it guards are under active attack today.

Two-lane timeline diagram titled "Identity Is the New COBOL." Top lane, mainframe/COBOL precedent: declared "legacy," stopped training successors, specialist workforce ages out, 60-year-old systems with a dwindling support pool. Bottom lane, cybersecurity/identity repeat: automate the entry-level rung, juniors thin with no successors trained, identity becomes the control plane with unowned agents. Sources: GAO-25-107795 (2025), Stanford Digital Economy Lab "Canaries in the Coal Mine" (2025).

Pay the principal now, on purpose

The answer is not to slow down on AI. It’s to stop pretending automation is payment and start treating it as the loan it is, then pay down the principal deliberately, while it’s still cheap.

That means three moves, and they are leadership moves, not tooling ones. First, keep humans in the loop by design. Gartner’s own position is that there will never be an autonomous SOC, because automation bias is a documented, measured failure mode that trained verifiers, not more automation, are what contain. Second, rebuild the training ground you just automated away. Do it deliberately, through apprenticeship and rotation, because the World Economic Forum estimates that of every hundred workers, 59 need reskilling by 2030 and 11 won’t get it. The new junior competency is supervising agents, and it has to be taught. Third, put your senior identity expertise where the risk actually concentrated. That means specifying, governing, and checking the agents now standing on the control plane, rather than treating identity as the box the automation happens to run in.

Pull-quote card on a black background with an oxblood left rule. Serif italic text reads: "A skills gap you mask with agents doesn't go away. It goes quiet, compounds in the dark, and comes back, this time wearing your own credentials." Byline: Nicholas Hunt · From the CIdO.

The organizations that will look smart in 2028 are not the ones that automated fastest. They’re the ones that automated and kept minting the expertise the automation runs on. A skills gap you mask with agents doesn’t go away. It goes quiet, compounds in the dark, and comes back bigger, this time wearing your own credentials.


References

LinkedIn

Leave a Reply

Your email address will not be published. Required fields are marked *