← Latest reporting

Cyber-agent autonomy should be set by consequence and approval latency

PwC found 22% of surveyed leaders would authorise fully autonomous cyber defence. The right operating model is a tiered action matrix, not a single human-in-the-loop switch.

Skills Demand and Labour MarketAI Capability Frontier
A full-scale cable lattice meets an amber gate before three folded fabric response paths.
Conceptual illustration generated with AI under editorial direction; it does not depict a real event.

What happened

PwC’s survey of 3,934 leaders in 71 countries found 22% would authorise fully autonomous defensive actions, 38% partial autonomy and 36% human-led execution with AI support.

Why it matters

A preference survey does not prove which model is safer or faster. It exposes the need to match each action’s reversibility and blast radius to a tested approval time and rollback path.

PwC’s 2027 Global Digital Trust Insights surveyed 3,934 business and technology leaders in 71 countries from May through July 2026. It reports that 22% would authorise fully autonomous cyber-defence actions, 38% partial autonomy and 36% human-led execution with AI support. The Wall Street Journal independently discussed the result with security leaders on 9 October.

Replace one switch with an action matrix

Classify defensive actions by consequence. Threat-intelligence enrichment can be autonomous when it cannot block users or alter evidence. Quarantine can be conditional when scope is small and rollback is immediate. Identity revocation, destructive remediation and production isolation need explicit approval unless a documented emergency rule applies.

For every tier, record maximum approval latency, required evidence, authority, rollback and post-action review. Then rehearse an attack moving faster than the human deadline. If approval cannot arrive in time, redesign the action to reduce blast radius rather than silently granting full autonomy.

The survey is large and geographically broad, but it measures stated willingness, not observed incident outcomes. Respondents are executives, 36% from companies above $5 billion revenue, so the distribution may not represent smaller organisations or frontline operators. The percentages should frame a control-design question, not benchmark maturity.

Pilot one bounded action from each tier. Measure detection delay, approval time, false containment, recovery and analyst correction burden. Include degraded communications and an unavailable approver, because a nominal human gate is not a control if it disappears during the incident. The decision is ready only when the team can explain why the same agent may enrich automatically, quarantine conditionally and revoke credentials only through a separate authority.