I have commented before on the AI discussions that appear periodically on social media and do so with some trepidation because there are so many opinions.  And I must put my hands up and say I am not an expert although I do use AI in my everyday work.  I’m not against it but it must be used intelligently and seen for what it is, not what the hype says it is.  This is particularly true of generative AI, which is the type of AI that is most known about and discussed.  Generative AI is a branch of AI that focuses on creating new content, such as text, images, audio etc, by learning patterns from vast datasets and generating output that resembles human-created work.  Of course, to generate this content, you must define clearly what outcome you are looking for.

Over the years, I’ve seen change happening because of innovation within IT, much of which has forecast the end of the workforce.  It has streamlined many processes and taken a lot of drudgery away.  I’ve been involved in mapping out working practices and designing/implementing management processes using IT.  I’ve seen the development of relational databases and search engines, both of which have done much to increase the speed and access to information that is required.  Is AI doing anything different in the workplace?  Or is it just the next somewhat inevitable step up?

I have to say though, that during the years when I was working with management information systems, whilst they did improve speed and efficiency, they never really achieved the manpower savings they were advertised to do.  One claim about AI, that it will achieve those manpower reductions seem a little excessive, in fact one forecast I read by a CEO was that it would have a devastating effect.  It makes me wonder who is going to buy these wonderful goods that are being so efficiently produced if the unemployment rate is through the roof and no one can afford to buy them?  Just a thought.

But getting back to AI itself, is it truly intelligent?  This is where a lot of misunderstanding and indeed, misinformation, can be found.  What forms of AI are there?  And what forms of AI are available now to business and the public.  There are about 7 categories of AI, not types i.e. marketed under a trade name, but categories.

TypeExists today?Purpose
Narrow AI✅ YesPerforms specific tasks
General AI (AGI)❌ NoHuman-level intelligence across many tasks
Superintelligent AI (ASI)❌ NoExceeds human intelligence
Reactive AI✅ YesNo memory, responds to inputs
Limited Memory AI✅ YesUses past information
Theory of Mind AI❌ NoUnderstands emotions and intentions
Self-Aware AI❌ NoConscious, self-aware intelligence

Categories of AI

As we sit here today, virtually all AI systems, including the most well-known such as ChatGPT, are forms of Narrow AI. They can be highly capable within their domains, but they do not possess human-like general intelligence or consciousness.  Narrow AI (and yes, I did use it to create the graphic above), is characterised by:

  • Designed for specific tasks.
  • Cannot think generally outside its training or purpose.
  • Examples:
    • ChatGPT
    • Siri and Alexa
    • Google Translate
    • Image generators
    • Recommendation systems (Netflix, Spotify)
    • Etc

I have said that I use AI, but I struggle to think of it as intelligent, but I do recognise that it is all about how you define that intelligence.  I use it mostly in my managed service, to monitor clients’ systems and keep them as safe as is possible.  Prior to moving into the SME space, I worked for some major clients, both public and private sectors and built several security operations centres.  Back then most of these were centred on SIEM systems, which used correlation engines to correlate the results gathered from several other systems, such as anti-malware, firewalls, intrusion detection systems etc.  The system would then produce results, and those results would be viewed by an analyst before pronouncing them real or a false positive, or whatever.  That was always way too expensive for an SME.  Using AI systems, that cost has now been reduced to a price point that can be attractive to an SME.  So, this is one feature where AI can be of great benefit and is proving itself way more efficient than the correlation engines of old.  Of course, this isn’t the only difference, but it is the one we’re talking about today.

One type of AI that we didn’t qualify above was what is known as Agentic AI.  This is not a separate category but rather a description of how an AI behaves, rather than how capable it is.  For example, whereas many systems that fit within Narrow AI, do so because they are designed for specific tasks.  Agentic AI can plan and achieve a goal, providing it has the right information and instructions to act upon.  This enables it to undertake research for example, so when it finds what it thinks is an issue, it can research that to produce a more definitive answer to an analyst to review.  It might learn enough so that you will trust it with low level alerts and decisions, on its own.  Whether you think that that is intelligence or not, I will leave to you.

Agentic AI allows us to use a layered model embedded in an application which we can use to support SMEs at a reasonable price point.  That layered model includes:

  • Behavioural AI/ML → detects attacks.
  • Correlation engine → connects events across identities, endpoints, email, and cloud.
  • LLMs → explain incidents and assist administrators.
  • Human MDR analysts → validate and respond to serious threats.

Briefly:

Identity-based threat detection

Rather than looking at devices in isolation, we use a system which correlates activity around people (identities).

It continuously analyses signals from:

  • Microsoft 365 or Google Workspace accounts
  • Endpoints (Windows/macOS)
  • Email
  • Cloud storage
  • Dark web monitoring
  • External attack surface

The AI combines these signals to identify suspicious patterns, such as:

  • Impossible travel logins
  • Unusual login times
  • MFA changes
  • Credential leaks
  • Suspicious file access

Instead of generating dozens of alerts, it attempts to determine whether these events are part of the same attack.

Machine learning for detection

Machine learning is used to:

  • Learn normal user behaviour
  • Detect anomalies
  • Reduce false positives
  • Prioritise high-risk incidents

Generative AI (LLMs)

The system also uses large language models for tasks such as:

  • Summarising complex security incidents
  • Explaining alerts in plain English
  • Helping administrators understand why something was flagged
  • Generating phishing simulation emails for employee training

This is different from the AI used to detect threats, it’s focused on making security information easier to understand and act on.

Automated response

When the AI determines an attack is likely, it can recommend or automate actions such as:

  • Disabling compromised accounts
  • Isolating infected endpoints
  • Blocking phishing emails
  • Forcing password resets
  • Escalating incidents to a human analyst

The platform combines AI-driven automation with human security analysts for higher-confidence incidents.

So back to where I started before I got carried away.  Is AI truly intelligent?  I have my opinion which I hope came through here, but I leave you to make up your own mind.  One thing though is for sure, AI is here to stay, and it will continue to get developed and will get better, or worse, depending upon your point of view.

Leave a Reply

Your email address will not be published. Required fields are marked *

Scroll to top