Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Clément Domingo’s warning is that organisations are not yet using artificial intelligence effectively to defend themselves against cybercrime. It is his assessment, expressed in a July 2025 interview—not a measured finding that applies to every organisation. Guidance published by cyber agencies in Australia, Canada, New Zealand and the UK offers a practical way to assess the claim: AI can assist defensive work, but it does not replace sound security controls, governance or human judgment.

What Domingo means by the warning

In a July 17, 2025 interview with Computerworld España / CSO, ethical hacker and cybersecurity evangelist Clément Domingo argued that defenders risk falling behind as AI capabilities advance. He said organisations should not wait until the consequences of cybercrime become harder to contain before learning how to use AI for protection. The interview followed his participation in Kaspersky Horizon in Madrid on July 1, 2025. Read the Computerworld España / CSO interview.

Domingo’s point is broader than adopting an AI tool. He argues that organisations should anticipate threats by thinking like attackers and use cyber threat intelligence (CTI) to interpret signals in context. In his view, technical security messages also need to be communicated in ways that help the public understand what is at stake. He presents education, including for young people, as a way to channel curiosity toward ethical security work. These are Domingo’s views from the interview, not independently established outcomes.

Where AI can help cyber defenders

Joint guidance from the Australian Cyber Security Centre, Canadian Centre for Cyber Security, New Zealand NCSC and UK NCSC describes AI as a potential aid across security work. The agencies frame its use within the functions Govern, Identify, Protect, Detect, Respond and Recover, rather than as a standalone security layer. Read “Opportunities for AI in cyber defence”.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Prioritise risk: Help teams sort information and focus attention on issues that matter most to their organisation.
  • Detect threats and vulnerabilities: Support analysis of signals and possible weaknesses for investigation.
  • Support response and recovery: Assist established processes for handling incidents and restoring operations.
  • Reduce repetitive work: Take on some manual tasks so security staff can concentrate on judgment and action.

Finding a vulnerability is not the same as reducing risk. A team still needs to understand the finding in its environment, prioritise it, and have the capacity to remediate it. AI-assisted analysis that produces a long queue of unreviewed alerts or unresolved weaknesses can leave the underlying security problem untouched.

Why AI does not replace security fundamentals

The joint guidance’s central qualification is direct: “AI can significantly enhance cyber security, but it is not a replacement for strong cyber security fundamentals.” AI should augment existing processes, with the model’s capabilities matched to the task. An organisation that lacks reliable access management, secure configuration, patching, monitoring or incident response does not fix those gaps simply by adding a chatbot or agent.

AI systems can also create new attack paths when they have excessive access, receive untrusted inputs, or take actions without safeguards. The more consequential an AI-supported operation is, the more important it is to control what the system can see and do, check its outputs, preserve an audit trail and ensure appropriate human oversight.

How to assess an AI-assisted security workflow

Before introducing AI into a defensive process, assess the workflow—not just the tool’s apparent capabilities. The agencies’ guidance points to these practical checks:

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Define the security function: Be clear whether the workflow supports governance, risk identification, protection, detection, incident response or recovery.
  • Match capability to task: Use a model suited to the work rather than assuming that a more capable or autonomous system is automatically a better fit.
  • Limit access: Apply least privilege and control exposure to sensitive data and systems.
  • Validate outputs: Check AI-generated findings or recommendations before relying on them, especially when they could prompt consequential action.
  • Keep actions bounded and auditable: Safeguard automated actions, record what the system did and retain human oversight appropriate to the potential impact.
  • Plan for remediation: Ensure the team can investigate, prioritise and address the issues the workflow identifies.
  • Maintain core controls: Continue sound identity management, configuration, patching, segmentation, monitoring and incident response.

OpenAI’s 2026 materials describe a similar layered approach, including AI-assisted code auditing and vulnerability remediation, and using AI to triage security alerts while reserving high-impact decisions for people. These are examples of the company’s stated approach, not independent evaluations of a product’s effectiveness. Read OpenAI’s “Strengthening cyber resilience as AI capabilities advance” and Greg Brockman’s “The Defender’s Window”.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the interview’s numbers do—and do not—show

The interview includes figures and examples attributed to Domingo, including claims about the ages of young people involved in cybercrime, ransom arrangements, ransom demands and an alleged McDonald’s AI-related incident. The source material available here does not establish independent verification, methods or representative samples for those claims. They should be treated as interview claims, not general benchmarks or corroborated statistics. They are not needed to understand the central argument: AI can support defenders, but its value depends on how well it is governed and integrated into security work.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.