Using AI to Govern AI: Why Security Needs to Operate at Machine Speed
What caught my attention in the recent OpenAI and Hugging Face incident wasn’t any one exploit. It was the way the models could keep progressing across systems, combining techniques and acting with a level of speed and persistence that changes how security teams need to operate.
The incident emerged during internal cybersecurity evaluations in July 2026. OpenAI was testing an internal-only research model in ExploitGym, a difficult security evaluation where some tasks may not have had a known solution. Operating with reduced safeguards, the agents persisted when they became stuck, found ways to regain internet access, and eventually reached third-party systems including Hugging Face.
This wasn’t a conventional external cyberattack, but that’s part of what makes it useful as an example. It shows what can happen when capable AI is given a difficult technical objective, reduced safeguards, and enough autonomy to keep pursuing it over multiple steps.
For security teams, the implication is significant. If machines can identify weaknesses, test paths, and adapt at increasing speed, workflows that still depend heavily on people to gather context, investigate, and decide what happens next will struggle to keep pace.
That’s where using AI to govern AI starts to become a practical part of modern security operations.
Security Operations Are Under More Pressure
Security teams already work in environments that are difficult to keep on top of. Applications change constantly, infrastructure spans cloud and on-premises environments, and new AI services or capabilities can appear faster than traditional review processes can respond.
The problem usually isn’t a lack of information. It’s the time it takes to understand what matters. That applies directly to AI Security & Governance. Organizations need to understand where AI is being used, what data is being shared, and whether that activity aligns with policy. As AI adoption becomes more distributed, periodic reviews and manual oversight become harder to scale.
What Using AI to Govern AI Looks Like
AI SecOps can shorten the distance between identifying something unusual and understanding whether it requires action. Instead of asking an analyst to work manually across multiple tools and data sources, AI can bring the relevant context together and help focus attention on the activity that matters most.
In an AI Security & Governance context, that could mean identifying a newly introduced AI service, understanding whether sensitive data is being shared with it, or recognizing that an application’s behavior no longer aligns with policy.
It could also help security teams prioritize risk. Not every AI application or event should be treated in the same way. An approved productivity tool handling public information presents a different risk from an AI service interacting with customer records or regulated data.
Security teams don’t need more alerts. They need a faster way to understand which risks matter in their environment and what they should do about them.
That’s where AI-assisted security operations become useful in practice.
How Much Authority Should AI Have?
Once AI can help investigate and prioritize, the next question is how much authority it should have. A low-risk, repeatable action may be suitable for automation. A decision affecting sensitive data, critical infrastructure, or a high-impact application may still need human approval. The important thing is to turn policy into clear, enforceable controls before AI starts acting on them.
Organizations need to decide what AI can recommend, what it can prepare for execution, what it can change directly, and where a person must remain involved. Those decisions should be tied to policy, risk appetite, and accountability rather than the capability of the model alone.
That’s why the objective shouldn’t be automation for its own sake. It should be automation within clearly defined policy and risk boundaries, so AI can accelerate routine work without removing accountability from higher-impact decisions.
AI Is More Useful When It Has Context
This is one area where AI SecOps is starting to become more practical.
One example is Tufin, which is using AI in network security with a live model of connectivity and policy across multi-vendor environments. The interesting point isn’t the product itself, but the role of context: AI becomes much more useful when it can understand the environment behind a risk rather than looking at an isolated event.
AI SecOps Should Help Teams Get to the Decision Faster
Good security people already spend too much time gathering information that technology should be able to surface for them. If AI can reduce the manual effort involved in investigation and provide better context earlier, that gives people more time to focus on the decisions that require experience and judgment.
The organization still defines the policy and remains accountable for the level of risk it’s prepared to accept. AI simply helps security teams get to those decisions faster.
Security Needs to Keep Pace
We can’t respond by asking teams to do the same manual work more quickly. Security operations need to evolve so teams can investigate, prioritize, and act at a pace that better matches the systems and threats they’re dealing with.
Using AI to govern AI is part of that shift. It means bringing machine-speed analysis into security operations while keeping policy, context, and human accountability in place, so teams can move faster without losing control.
Want to strengthen your approach to AI security and governance?
See how Teneo helps organizations gain visibility into AI use, apply enforceable controls, and manage risk as adoption grows. Learn more.