← All Articles

We Replaced Our Team of 6 with AI Agents — Here’s What Actually Happened

February 17, 2026 · 8 min read

At 11 PM in October 2025, a spreadsheet showed the fully loaded annual cost of a six-person security team: €847,000. GRC analyst, policy manager, vendor risk assessor, compliance officer, IR coordinator, AppSec lead. Approximately 60% of this team’s work was mechanical.

The Six Agents Deployed

1. GRC Agent

Risk registers, control mapping, board reports

2. Policy Manager Agent

Policy lookups, gap analysis, document reviews

3. Vendor Risk Agent

Questionnaire processing, cross-referencing, risk scoring

4. Compliance Agent

Regulatory monitoring, control mapping, evidence collection

5. Incident Response Agent

Playbook maintenance, alert correlation, response coordination

6. AppSec Agent

Code review triage, vulnerability prioritisation, developer comms

What Worked: Performance Metrics

70%
audit prep reduction
90%
policy Q&A faster
80%
vendor assessment faster
85%
board reporting faster

Board Reports: 30 Seconds vs. 3 Days

Agent produces draft in ~30 seconds; human edits for tone and strategy in 30 minutes. Total time: under one hour with improved quality.

Vendor Assessments: 3 Hours vs. 3 Weeks

Agent pre-populates from public information, generates targeted questions, cross-references for consistency. Caught inconsistencies across 60-page questionnaires that human reviewers would miss.

Cross-Agent Intelligence

IR agent findings automatically feed to GRC for risk register updates. Compliance agent checks notification requirements. Policy agent flags required updates. A phishing exercise (40% click rate) triggered automated escalation across risk scoring, policy review, and audit compliance—completed in minutes versus a human-coordinated week.

What Didn’t Work

AI Hallucination on Control Numbers

Agent confidently cited non-existent "ISO 27001 Control A.12.4.3." Solution: Ground agents in verified data only. Reduced hallucination on factual claims to near zero.

Client Resistance

Initial discomfort with AI-delivered work. Resolved when side-by-side comparison showed agent caught three issues the human assessment missed.

AI agents without human oversight in security is malpractice. Full stop. Regulatory notifications, board communications, vendor risk acceptance, and political findings always require human judgement.

The New Model

Old: CISO → 6–15 people spending most time on structured, repeatable tasks.

New: CISO → 2–3 senior people for oversight and strategy + AI agents handling 24/7 execution with cross-domain intelligence sharing.

The agents handle the floor. The humans handle the ceiling.

Need help implementing this?

First strategy session is complimentary. We typically respond within 4 hours.