Why the first cyber function AI automates is the one that gets more important as it shrinks.
There is a consensus forming that AI will hollow out cyber governance, risk and compliance. The consensus is right about the hollowing and wrong about almost everything that follows from it: what gets removed, what survives, and whether the people still standing are doing more important work or less.
GRC is the first function in a security organisation that AI will substantially automate. This is usually delivered as a warning. It is better understood as a diagnosis, because the part of GRC that automates was never the job.
Look at where the hours go. Collecting evidence. Mapping one framework onto another. Reconciling crosswalks. Synthesising gaps. Re-keying registers. Assembling the first draft of a report nobody enjoys reading. These are the largest line items on any GRC timesheet, and they share one property: none of them is judgement. They are production, the manufacturing floor of an assurance function. Necessary, voluminous, and almost entirely mechanical.
The actual job of GRC is something else. It is independent judgement and challenge over whether the organisation’s risk position is acceptable, and a clear answer to who is accountable when it is not. That is the function. Everything else is the cost of producing the inputs to that judgement. And that part does not automate. It arguably becomes more important as the production layer collapses, because there is suddenly far less busywork standing between the practitioner and the only question that ever mattered.
The job was never the hours
This is the inversion the headcount panic misses. When AI removes the production work, it is not removing humans. It is removing the wrong kind of human work, the kind that was never judgement in the first place. A senior practitioner who spent most of the week chasing evidence and reconciling registers does not become most-of-the-week redundant. They become that much more available for the part of the job they were hired to do and rarely had room for.
There is an old confusion buried in most automation arguments, which is the assumption that a function equals the sum of its hours. It does not. A function equals its purpose, and the hours are just the current, contingent way that purpose gets met. GRC’s purpose is challenge. The hours happen to be evidence-chasing because, until now, challenge required a mountain of manual production to stand on. Remove the requirement to build the mountain by hand and the purpose does not shrink. It is simply freed from the labour that obscured it.
So the honest framing of what is happening is not “AI replaces GRC analysts.” It is “AI removes the part of GRC that was never the analyst’s value.” Those are different claims, and only the second one is true.
Thinner at the bottom, heavier at the top
Here is where it gets less comfortable for everyone, automation optimists included.
The work that survives is not evenly distributed across the function. It concentrates at the top. The judgement that does not automate: risk appetite for autonomous systems, decisions about what authority a tool may hold, the materiality of an incident, what to attest to and what to escalate, is senior judgement. Much of it is net new: questions that did not exist with this weight a few years ago and now land squarely, and only, on humans.
So the function does not get smaller in a tidy, proportional way. It changes shape. It gets thinner at the bottom, where the production work used to sit, and heavier at the top, where the judgement now concentrates. The team that emerges has fewer people doing evidence collection and more people, or the same people, differently deployed, making consequential calls that carry their name.
This is not the story a tooling vendor tells, because it is harder to sell. The vendor wants to sell hours removed. The reality is hours reshaped, and the reshaping demands more capability at the senior end, not less.
The claim, stated honestly
If you strip the optimism and the panic out, the honest version of the claim is narrow and defensible: agentic GRC does not chiefly cut the number of people. It changes their shape. Where it does reduce hours, it reduces the hours that were never judgement. That is the whole of it. Anyone promising more than that (headcount halved, the second line as a dashboard, assurance as a subscription) is selling you the removal of the very thing the function exists to provide.
And none of it works as a tooling change alone. This is the part the regulators have already seen coming. APRA’s 30 April 2026 letter to industry, its first AI-specific set of expectations, landed on a governance problem, not a technology one: boards pursuing the benefits of AI while accepting vendor briefings at face value rather than asking the hard questions. ASIC’s 8 May letter reinforced the same line, expecting genuine human involvement for high-risk decisions and clear accountability for them. Neither regulator is worried that firms lack tools. They are worried that firms lack the literacy to challenge the tools. A green dashboard accepted without examination is consensus bias with better production values, and it now sits, in so many words, in a regulator’s letter.
You cannot buy your way past that. Removing the production floor only pays off if the people who remain are equipped to do the judgement the floor was hiding. A second line that automates its evidence collection but still cannot interrogate a probabilistic system has not modernised. It has just made its inability to challenge faster and cheaper to reach.
Where the hours actually go
So where does the freed capacity go, if not out the door? In practice, three directions.
The first is the proactive, threat-led risk work the team never had time for, the analysis that was always the point and was always the thing crowded out by collection and synthesis. The second is redeployment toward the engineering edge: the people who understand the control set move toward designing control requirements with architecture, and toward detection and purple-team work with security operations. That is real reassignment of judgement to where it compounds.
The third direction is the interesting one, and it is the reason this series exists. Automating the function creates net-new work that did not exist before: curating what the machine is allowed to learn from, challenging what it produces, and governing the platform itself as a regulated asset. This is not overhead to apologise for. It is precisely the second line and assurance labour the regulators are now explicitly asking for. Call it governing the machine.
And that third direction is where the comfortable story quietly ends.
The trap nobody is pricing in
When the thing that provides assurance and the thing being assured share a brain, what exactly is the assurance worth?
Notice what has happened. To absorb its own production burden, GRC has become an agentic system. The function whose entire purpose is independent challenge over the organisation’s AI is now, itself, AI.
Which means the assurer has just become part of the estate it is meant to assure. It is subject to the same drift, the same opacity, the same failure modes as everything else it governs. The independent reference frame over the organisation’s machine intelligence is now running on machine intelligence, and quite possibly the same machine intelligence, from the same vendor, trained on the same corpus, as the systems it is supposed to hold to account.
That is not a footnote to the automation story. It is the next problem in full, and it is the one the regulators are circling without yet naming: when the thing that provides assurance and the thing being assured share a brain, what exactly is the assurance worth?
That question is where this goes next.
Key Takeaway
AI removes the part of GRC that was never the analyst’s value. The function does not shrink, it changes shape: thinner at the bottom, heavier at the top.
This is the first of three pieces on governing the judgement layer. Part two takes up the trap directly: what happens to assurance when the assurer becomes part of the correlated surface it exists to catch.