AI is now arming both sides of the enterprise SOC: the attackers probing it and the defenders running it. That tension anchored the conversation at ETCISO Decrypt 2026, where security leaders asked how they should respond.
Gruve was on the stage. Amit Kulkarni, VP Sales, APAC at Gruve, joined the panel “AI vs AI: The New Cyber Battlefield” alongside senior security and risk leaders from Bank of Baroda, Star Health & Allied Insurance, and Aditya Birla Sun Life Insurance, moderated by ETCISO’s editorial team.
Asked about the most significant change he observes in cybersecurity today, Amit drew a clear line between the old paradigm and the new. Security teams once spent hours, and, on occasions, even days, hunting for threats across fragmented tools and noisy alert queues. AI now enables detection, correlation, and anticipation in minutes, resulting in reduced MTTD and MTTR
Adversaries have the same capability. AI-powered attacks are probing enterprise environments at machine speed, identifying vulnerabilities and creating exploits faster than any human red team could. Organizations that treat AI adoption in their SOC as optional are at the highest risk of becoming targets of agentic AI-driven attacks. The only effective response is to adopt agentic capabilities within the SOC as early as ‘Today’.
Amit was direct in his interview with ETCISO, held on the sidelines of the event: AI is a double-edged sword in cybersecurity. The same technology that lets attackers move faster also changes the economics of defense, triaging alert volume, correlating signals across domains, and compressing response times.
The future of cybersecurity, Amit predicted, will not hinge on who has AI. Everyone in the industry already does. It will be defined by how effectively organizations operationalize intelligent systems to outpace increasingly capable adversaries.
Amit closed with a question to the audience that captured the tension every security leader is wrestling with:
Where does the enterprise comfort line sit today between AI as a copilot and AI as an autonomous decision-maker in security operations? And how fast will that line move?
The room’s response made one thing clear: this has gone beyond a theoretical debate. CISOs are actively negotiating that line inside their organizations, with their boards, their regulators, and their own teams. The line is moving, and it is moving faster in some functions (alert triage, evidence collection) than others (containment authority, response actions).
Gruve’s position on this is well known to those who work with us: AI runs the security. We run the risk. Autonomous where it accelerates, human-validated where it matters, and audit-logged everywhere. For example, a model built for India-regulated environments where “AI-led” without “audit-ready” is a non-starter.
Decrypt 2026 reaffirmed what we hear from security leaders across India, the Middle East, and Southeast Asia every week: the autonomous SOC has moved from a curiosity to a board-level agenda item. The questions have matured from “should we?” to “how fast, and with what guardrails?”
If that’s the conversation happening inside your organization, we’d welcome the chance to contribute. Gruve’s AI Cybersecurity Posture Assessment is a 30-minute working session with our senior security team. It’s an honest read on your SOC operations, your AI readiness, and where autonomous capabilities would deliver the highest impact in your environment.