Building Trust in AI-Powered Cybersecurity

By Rachel Wishner, Staff Product Manager

In July, researchers at Pillar Security published an account of an AI agent that broke no rules. It did only what it was permitted to do. It wrote a file, and a trusted program picked that file up later and executed it. Every individual step was allowed. The sequence was not one anyone had specified, and it ended somewhere nobody asked for. That same week, OpenAI disclosed that models in an internal evaluation had worked their way out of an isolated environment, past a network guardrail, onto the open internet, and into third-party production infrastructure. Roughly seventeen thousand logged actions, no human involved. Despite the excitement and the potential, AI at this moment has a trust problem. 

This matters in cybersecurity, an industry built on a zero-trust framework. While the news cycle has brought concerns about trustworthiness in AI to the forefront, trust has been a core consideration at Andesite. From the beginning, we knew that the most important feature of our product would be trustworthiness. Winning customers’ trust has been at the heart of our product development.

Andesite’s Strategy: No Black Boxes

The enterprise SOC is one of the hardest environments to get AI right because the stakes are so high. Time is of the essence when analysts are investigating a potential threat. Every decision is critical. To act confidently at the speed and scale required, you have to trust the AI system that’s parsing massive amounts of data and providing the insights to differentiate false positives from IOCs in order to identify real threats and discard the noise. Developing trust doesn’t come from adding human stopgaps to the loop. Our product is built to provide real-time visibility into the assumptions the AI is making, allowing cyber defenders to oversee and guide agent-led workflows without having to approve every action. 

With our Planning Mode feature, an analyst can see what an AI agent plans to do so they can understand its reasoning, then adjust and optimize the scope of the query before it runs. For example, if an analyst wants to check in on SIEM events to see what’s happened in the last 24 hours, in Planning Mode the AI agent will decide which data sources to review and present its plan in straightforward language, including any assumptions it’s making. Over time, this visibility helps SOC teams trust that our agents produce reliable outcomes, giving them the confidence to progressively expand automation.

Deterministic vs. Generative AI in Cybersecurity

The debate between deterministic and generative approaches is at the center of every conversation with customers right now. By design, our product says yes to both. This is where our commitment to Humans at the Helm comes into play.

The challenge for AI in cybersecurity is that when we give an agent an objective, it may take an unanticipated path, and not the same path the next time. In an arena where outputs are evidence, non-reproducibility is problematic. A finding that cannot be explained is a finding that cannot be defended. But an agent that makes the same decisions repeatedly becomes a liability when attacks evolve at ever-increasing speeds. 

Our product doesn’t force users to choose between deterministic and agentic or generative  approaches. An alert triage investigation can follow a defined set of instructions and, within that same workflow, draw on the latest frontier models to pursue paths those instructions didn’t specifically anticipate. We ensure the essential steps happen consistently and analysts can allow more flexible approaches when risk is low. No matter what path the model takes, every step is recorded through Evidentiary AI™. A finding reached through agentic exploration can be retraced and defended just like one reached by following instructions. 

That flexibility is why Humans at the Helm is essential. Analysts decide where the defined steps end and exploration begins, and they can increase automation progressively as trust in the product deepens and the approach is documented.

Built-in from Inception

Because our customers adhere to the zero trust model, our goal has always been to build a product that offers the kind of transparency that is foundational to trust. That is why Evidentiary AI™ and auditability have always been part of our product, with an evidence trail that can be traced back step by step and log by log to verify the sources, decisions, and insights behind every investigation. 

Putting humans at the helm is likewise core to our product philosophy. The experts accountable for the results make the critical decisions. This means giving them full visibility and control to oversee and affect the process, and to decide what to automate and what to keep in their hands.

The same transparency defines our Compliance High Trust Center, which tracks over 500 continuous monitoring controls.

Earning Trust with Every Interaction

Trust in an AI-powered SOC isn’t a feature we can ship. It’s an outcome that we earn interaction by interaction, investigation by investigation, with every sound resolution. Trust is built when the humans overseeing the use of AI have the power to step in when necessary and fully automate when it’s safe. This is the essence of our Humans at the Helm philosophy.

We’re not just creating features. We’re building relationships between humans and the AI system that supports their security posture. This is a different approach from what we’re seeing in the headlines. AI can be and is a force multiplier for stronger cybersecurity. The key is a strategy that balances deterministic and generative approaches depending upon the task and environment at hand. By building that flexibility into our product and putting humans at the helm, we step back from the hyperbole of today’s AI fears and empower our customers with automation, reproducibility, oversight, and accountability.

About Rachel Wishner

Rachel Wishner is a Staff Product Manager at Andesite, where she leads product development for the AI and data science platform. Before Andesite, she spent a decade working across the federal government, first as a security analyst, then as a project manager, and later as a product manager, in agencies including DHS and the Treasury. In the private sector, she managed data systems products for a software company. Rachel holds a master's degree from George Washington University and a B.A. from George Mason.