βAI Normal Techβ vs βAGI by Tuesdayβ: Security Advice That Survives Either Future
If you look at social media debates about AI, two extreme patterns emerge. Studying extreme patterns is very useful because understanding boundary conditions helps you understand the whole phenomenonβββin this case of security in AI adoption (recent extreme example). You can also do all sorts of fun scenario planning withΒ this.
Predictably, security leaders have caught the same fever, and even some technologists did. Letβs catalog them likeΒ this:
- Camp 1 (The Meh Camp): This camp spans a spectrumβββfrom the hard cynics (βitβs autocomplete with a marketing budget,β LLMs are stochastic parrots, there is no βintelligenceβ anywhere in the building) to the more measured βAI as normal technologyβ crowd, who concede the tech is real, but expect it to diffuse slowly and messily over decades. What unites them: no discontinuous jump, no paradigm rupture, no exponents, no robot overlords. And yes, βthe parrot wingβ of this camp is alive and well in some very senior securityΒ circles.
- Camp 2 (The Deep Believers): AGI is coming by βnext Tuesdayββββor 2027 at the absolute latest. This camp also spans a spectrum, from the βdoomerβ accelerationists who foresee inevitable, systemic collapse to the optimistic futurists anticipating a complete, rapid upheaval of the global security landscape. Some hold this timeline with religious fervor while being unable to define βintelligenceβ if their bonus depended on it. What unites them is the conviction that we are facing an immediate, discontinuous, exponential leap in capability that will render all traditional defensive strategies obsolete overnight. And yes, there are influential security leaders who lean heavily into thisΒ camp.

Here is the fun part and the point of this blog: you donβt need to know whoβs right. In fact, betting your security program on either camp being right is the actual mistake I want to pointΒ out.
Maybe the Parrot camp is right. Maybe the AGI-doomers are spot on. Or maybe the truth is somewhere in the swampy middle. If you find yourself unable to justify a security investment without first winning a philosophy-of-mind debate, you are doing itΒ wrong.
But letβs instead ponder what works in βeither / neither / bothβΒ cases.
What security advice remains correct today and for the medium term without relying on either camp beingΒ right?
One structural note before we start: every section below runs the same play. What the βparrot futureβ does to you. What the βAGI Tuesdayβ future does to you. What you do about bothβββwith one control. Watch how many times the answer converges.
That convergence is my argument (with help from Gemini and ClaudeΒ Fable).
Universal Security Controls for BothΒ Futures
If youβre Camp 1βββwhether the parrot wing or the βnormal technologyβ wingβββyou believe AI is an incremental extension of βclassicβ ML: it accelerates existing security processes without any dramatic paradigm shift. But even then, you concede it speeds things upβββincluding for attackers, who now discover vulnerabilities and misconfigurations faster and phish with impeccable grammar (nobody, not even the βparrotiestβ parrot will argue with this one!). If youβre Camp 2, you may be surprised to see that these same controls apply, just with the volume knob turned to 11 atΒ times.
1. Configuration Hygiene
Boring? Yes. Optional? Definitely not. Cloud misconfigurations and weak baselines remain the #1 way attackers walk in through the front doorβββno AGI required, thank you veryΒ much.
- Parrot future: attackers use AI to find your misconfigurations faster. The parrot doesnβt need to be smart; your S3 bucket isΒ public.
- AGI future: the βsuperintelligentβ attacker also starts with your public S3 bucket, because why use an AI-crafted zero-day when the door isΒ open?
The universal control: treat configuration hygiene as tier-1 defense, with continuous (not quarterly!) posture validation. Hygiene is the rare control that is equally valuable whether AI is a mildly better βgrepβ or an existential threat (Claude came up with this metaphor, thanks buddy, it almost rhymes). If your AI security roadmap has βagentic red teamingβ on it but not βclose the open buckets,β you are accessorizing a house with no doors. See good argumentΒ here.
2. Threat Detection & Security Monitoring
You do recall I had a title βChief Logging Evangelistβ a few years back (βA few, Antonβ? Who are you kidding?βΒ β¦ Anyhowβ¦) Your SOC or D&R team or whatever you call it still needs to log, sense, detect, investigate, etc.
- Parrot future: your normal systems face automated, AI-accelerated attacksβββsame TTPs, faster tempo, and phishing that finally spells βinvoiceβ correctly. Your triage queue was built for human-speed adversaries; it is about to meet an assemblyΒ line.
- AGI future: the AI systems themselves become the thing to watchβββinputs, outputs, tool calls, and internal telemetryβββbecause prompt injection, abuse, and quiet exfiltration through an agent leave traces nowhere in your current detection content.
The universal control: log and detect. Your classic estate under machine-accelerated attack, and your AI stack as a first-class telemetry source with its own detections (devil here is in the details, as usual). I admit this smells like an βEasier Said Than Doneβ competition entry with some chance of getting a 3rd prize. But the fact remains: good logging helps you in eitherΒ case.
3. Accelerated Vulnerability Management
Vulnerability managementβββdealing with security-relevant flaws in vendor software and your own code and open source codeβββmust run on a faster clock in 2026. The clock disagreement between the camps is about how much faster, not whether. Think 30%+, 2x, 10x or βwe are all gonna dieβxΒ :-)
- Parrot future: AI compresses the exploit timeline the boring wayβββfaster recon, faster PoC-to-prod exploit code, βcommodityβ attackers punching above their weight class. Your 30-day patch SLA quietly became a 30-day βwe have a front door open, locks what locksβΒ period.
- AGI future: βPatching is dead! The machines will find zero-days continuously!β Fine. Even granting the premise, the conclusion isnβt βgive upββββitβs that mitigation and rewriting becomes the wholeΒ game.
The universal control: vulnerability management inclusive of mitigation planning (segmentation, βvirtualβ patching, compensating controls, config weakness scanning, etc) becomes more critical under both futures, not less. Most companies cannot break their βpatch sound barrierβ, AI or no AI. When you canβt fix the flaw, youβd better be able to contain the blast radius. Note the irony: the AGI campβs own argument makes the boring VM discipline more important. Funny how thatΒ works.
4. Data Security & Sensitive Data Discovery
Both camps should care deeply about knowing where their sensitive data lives, but they lose sleep over different nightmares:
- Parrot future: the risk is leakage and compliance. Employees will lovingly paste source code, PHI, and PII into consumer chatbots to βpolish an email.β Regulators do not accept βthe parrot ate my dataβ as a defense. Am I overdoing the βparrot thingβΒ here?
- AGI future: the risk shifts to poisoning and exploitation. An agentic system with access to poorly governed data repositories plus one well-crafted prompt injection equals an AI that cheerfully exfiltrates things it should never haveΒ touched.
The universal control: build a real-time, accurate inventory of your sensitive dataβββand yes, AI-automated sensitive data discovery and mapping is finally real (while in 2016, it largely was not, for most organizations). The uncomfortable truth: most organizations spent two decades not doing data security because it was hard and nobody made them. AI just made βwe donβt know where our data isβ much more painful, whether you are βcamp parrotβ or βcamp AGI.β Heard this advice before? Yes, you did. So? Did you actually try implementing it? Well, now you need to, parrots orΒ not.
5. Shadow AI Governance & Sanctioned Alternatives
Banning public AI tools is the ultimate security theaterβββright up there with confiscating USB sticks in 2009 or banning Internet connectivity in 1998 (βbut why would you need the internet for work?!β). It doesnβt stop usage; it just moves it to personal phones and personal accounts, where you canβt see it, log it, or ever get the dataΒ back.
- Parrot future: employees casually feed proprietary code and PII into consumer LLMs, generating incidents and triggering your lawyercats unnecessarily.
- AGI future: well-meaning developers hand API keys and internal data access to unmonitored shadow agents and creating a sprawling, autonomous attack surface that nobody owns. WhatΒ fun!
The universal control: stop playing firewall whack-a-mole. Get visibility (CASB and DLP are still a thing, yes, really!), then remove the excuse: offer a sanctioned enterprise AI tool with real contractual data protections. People take shortcuts when the official path is a dirt road. Pave it. And if your ban is still in place in 2026, understand that you donβt have a policyβββyou have a shadow inventory problem youβve chosen not toΒ measure.
6. Identity & Access forΒ Agents
Hereβs the control nobody had on their 2016 bingo card: least privilege for machines that ask nicely. We barely handled NHI (no, we never did, IRL) and now we have βagent identityβ with a pillow fight ongoing on βis agent more like an employee or more like a workloadββ¦
- Parrot future: AI tools and integrations quietly accumulate OAuth grants, service accounts, and long-lived API keysβββclassic non-human identity sprawl, now with extra steps. Regular NHI problem left unsolved would kill you slowly, the agentic one will workΒ faster.
- AGI future: autonomous agents holding broad credentials become the single most attractive target in your enterprise. Compromise the agent, inherit its permissionsβββand its work ethic. Tricking an agent to do βa rogue actionβ is becoming more popular everyΒ dayβ¦
The universal control: treat every agent, and integration as an identity with a lifecycle (!). Scope it, time-limit it, log it, and review it. Your agents currently have more access than your interns and sometimes less judgment. Fix at least one of thoseΒ ;-)
7. Environmental Reality Testing vs. Marketing Benchmarks
Model capability benchmarks are largely a mirage if they do not match your realities. A high score on a vendor slide means precisely nothing about your production environment, if you are notΒ them.
- Parrot future: blind trust in claimed accuracy yields silent failures, hallucinations in critical workflows, and surprise data leakageβββthe parrot passed the exam and still canβt do the job. I am not adding βit will peck you to deathβ, this is where I draw theΒ lineβ¦
- AGI future: deploying an agentic system for consequential autonomous tasks without validation invites systemic, unpredictable behaviorβββan advanced agent breaking things faster than you can file the postmortem.
The universal control: ignore the brochure. Run internal, multi-run reliability testing and AI red-teaming in your environment with your data before any AI system earns operational duties. Trust is earned in your environment, not on the vendorβs leaderboard. Hereβs the provocative version: if your AI procurement process accepts benchmark scores as evidence, your procurement process is part of your attackΒ surface.
Moving Beyond theΒ Debate
And, yes, we could keep adding entries (asset management, IR playbook updates for AI incidents; the list of unglamorous-but-necessary goes on). But youβve seen the pattern ten times now, so letβs nameΒ it.
The two camps diverge violently on timelines and on whether a discontinuous βAGI jumpβ is coming at allβββyet they converge on the near-term necessity of architectural control, every single time. Autonomous agents, supply-chain exposure, machine-speed offense: both worldviews agree these risks are real, present, and demand actionΒ today.
When two groups who agree on nothing agree on your homework, the homework is probably real. If I hear one more CISO tell me they are βwaiting for the dust to settle on AIβ before building a security strategy, Iβm going to start charging for therapy. The dust isnβt settling. Itβs just turning into more data you arenβtΒ logging.
So the next time someone tells you they canβt build an AI security strategy until the AGI debate settlesβββsmile, nod, and go patch something. The philosophers will still be arguing next Tuesday. Your attackers wonβt wait thatΒ long.
Summary
- The dichotomy: security leaders split into the βnormal technologyβ camp (from stochastic-parrot cynics to slow-diffusion βpragmatistsβ) and the βAGI by next Tuesdayβ believers (and of course less extreme middleΒ too)
- The core thesis: we do not need to settle the philosophical debate. Many of the same fundamental, no-regret controls apply regardless of which future arrives, and the campsβ convergence on near-term controls is itself the strongest evidence those controlsΒ matter.
- The no-regret controls:
- Treat configuration hygiene as tier-1 defenseβββboth futures start at your public S3Β bucket.
- Monitor both your normal systems under AI attack and the telemetry of your AI systems themselves.
- Accelerate vulnerability management loops, with mitigation planning for the flaws you canβtΒ patch
- Prioritize sensitive data discoveryβββagainst leakage (low end) and poisoning/exploitation (highΒ end).
- Replace blanket bans with sanctioned enterprise AI plus visibility.
- Govern non-human identities: least privilege, lifecycle, and logging for every agent and integration.
- Re-engineer threat models and containment for machine-speed intrusions.
- Ignore synthetic vendor benchmarks; mandate local adversarial red-teaming before operational trust.
βAI Normal Techβ vs βAGI by Tuesdayβ: Security Advice That Survives Either Future was originally published in Anton on Security on Medium, where people are continuing the conversation by highlighting and responding to this story.



