โAI Normal Techโ vs โAGI by Tuesdayโ: Security Advice That Survives Either Future
If you look at social media debates about AI, two extreme patterns emerge. Studying extreme patterns is very useful because understanding boundary conditions helps you understand the whole phenomenonโโโin this case of security in AI adoption (recent extreme example). You can also do all sorts of fun scenario planning withย this.
Predictably, security leaders have caught the same fever, and even some technologists did. Letโs catalog them likeย this:
- Camp 1 (The Meh Camp): This camp spans a spectrumโโโfrom the hard cynics (โitโs autocomplete with a marketing budget,โ LLMs are stochastic parrots, there is no โintelligenceโ anywhere in the building) to the more measured โAI as normal technologyโ crowd, who concede the tech is real, but expect it to diffuse slowly and messily over decades. What unites them: no discontinuous jump, no paradigm rupture, no exponents, no robot overlords. And yes, โthe parrot wingโ of this camp is alive and well in some very senior securityย circles.
- Camp 2 (The Deep Believers): AGI is coming by โnext Tuesdayโโโโor 2027 at the absolute latest. This camp also spans a spectrum, from the โdoomerโ accelerationists who foresee inevitable, systemic collapse to the optimistic futurists anticipating a complete, rapid upheaval of the global security landscape. Some hold this timeline with religious fervor while being unable to define โintelligenceโ if their bonus depended on it. What unites them is the conviction that we are facing an immediate, discontinuous, exponential leap in capability that will render all traditional defensive strategies obsolete overnight. And yes, there are influential security leaders who lean heavily into thisย camp.

Here is the fun part and the point of this blog: you donโt need to know whoโs right. In fact, betting your security program on either camp being right is the actual mistake I want to pointย out.
Maybe the Parrot camp is right. Maybe the AGI-doomers are spot on. Or maybe the truth is somewhere in the swampy middle. If you find yourself unable to justify a security investment without first winning a philosophy-of-mind debate, you are doing itย wrong.
But letโs instead ponder what works in โeither / neither / bothโย cases.
What security advice remains correct today and for the medium term without relying on either camp beingย right?
One structural note before we start: every section below runs the same play. What the โparrot futureโ does to you. What the โAGI Tuesdayโ future does to you. What you do about bothโโโwith one control. Watch how many times the answer converges.
That convergence is my argument (with help from Gemini and Claudeย Fable).
Universal Security Controls for Bothย Futures
If youโre Camp 1โโโwhether the parrot wing or the โnormal technologyโ wingโโโyou believe AI is an incremental extension of โclassicโ ML: it accelerates existing security processes without any dramatic paradigm shift. But even then, you concede it speeds things upโโโincluding for attackers, who now discover vulnerabilities and misconfigurations faster and phish with impeccable grammar (nobody, not even the โparrotiestโ parrot will argue with this one!). If youโre Camp 2, you may be surprised to see that these same controls apply, just with the volume knob turned to 11 atย times.
1. Configuration Hygiene
Boring? Yes. Optional? Definitely not. Cloud misconfigurations and weak baselines remain the #1 way attackers walk in through the front doorโโโno AGI required, thank you veryย much.
- Parrot future: attackers use AI to find your misconfigurations faster. The parrot doesnโt need to be smart; your S3 bucket isย public.
- AGI future: the โsuperintelligentโ attacker also starts with your public S3 bucket, because why use an AI-crafted zero-day when the door isย open?
The universal control: treat configuration hygiene as tier-1 defense, with continuous (not quarterly!) posture validation. Hygiene is the rare control that is equally valuable whether AI is a mildly better โgrepโ or an existential threat (Claude came up with this metaphor, thanks buddy, it almost rhymes). If your AI security roadmap has โagentic red teamingโ on it but not โclose the open buckets,โ you are accessorizing a house with no doors. See good argumentย here.
2. Threat Detection & Security Monitoring
You do recall I had a title โChief Logging Evangelistโ a few years back (โA few, Antonโ? Who are you kidding?โย โฆ Anyhowโฆ) Your SOC or D&R team or whatever you call it still needs to log, sense, detect, investigate, etc.
- Parrot future: your normal systems face automated, AI-accelerated attacksโโโsame TTPs, faster tempo, and phishing that finally spells โinvoiceโ correctly. Your triage queue was built for human-speed adversaries; it is about to meet an assemblyย line.
- AGI future: the AI systems themselves become the thing to watchโโโinputs, outputs, tool calls, and internal telemetryโโโbecause prompt injection, abuse, and quiet exfiltration through an agent leave traces nowhere in your current detection content.
The universal control: log and detect. Your classic estate under machine-accelerated attack, and your AI stack as a first-class telemetry source with its own detections (devil here is in the details, as usual). I admit this smells like an โEasier Said Than Doneโ competition entry with some chance of getting a 3rd prize. But the fact remains: good logging helps you in eitherย case.
3. Accelerated Vulnerability Management
Vulnerability managementโโโdealing with security-relevant flaws in vendor software and your own code and open source codeโโโmust run on a faster clock in 2026. The clock disagreement between the camps is about how much faster, not whether. Think 30%+, 2x, 10x or โwe are all gonna dieโxย :-)
- Parrot future: AI compresses the exploit timeline the boring wayโโโfaster recon, faster PoC-to-prod exploit code, โcommodityโ attackers punching above their weight class. Your 30-day patch SLA quietly became a 30-day โwe have a front door open, locks what locksโย period.
- AGI future: โPatching is dead! The machines will find zero-days continuously!โ Fine. Even granting the premise, the conclusion isnโt โgive upโโโโitโs that mitigation and rewriting becomes the wholeย game.
The universal control: vulnerability management inclusive of mitigation planning (segmentation, โvirtualโ patching, compensating controls, config weakness scanning, etc) becomes more critical under both futures, not less. Most companies cannot break their โpatch sound barrierโ, AI or no AI. When you canโt fix the flaw, youโd better be able to contain the blast radius. Note the irony: the AGI campโs own argument makes the boring VM discipline more important. Funny how thatย works.
4. Data Security & Sensitive Data Discovery
Both camps should care deeply about knowing where their sensitive data lives, but they lose sleep over different nightmares:
- Parrot future: the risk is leakage and compliance. Employees will lovingly paste source code, PHI, and PII into consumer chatbots to โpolish an email.โ Regulators do not accept โthe parrot ate my dataโ as a defense. Am I overdoing the โparrot thingโย here?
- AGI future: the risk shifts to poisoning and exploitation. An agentic system with access to poorly governed data repositories plus one well-crafted prompt injection equals an AI that cheerfully exfiltrates things it should never haveย touched.
The universal control: build a real-time, accurate inventory of your sensitive dataโโโand yes, AI-automated sensitive data discovery and mapping is finally real (while in 2016, it largely was not, for most organizations). The uncomfortable truth: most organizations spent two decades not doing data security because it was hard and nobody made them. AI just made โwe donโt know where our data isโ much more painful, whether you are โcamp parrotโ or โcamp AGI.โ Heard this advice before? Yes, you did. So? Did you actually try implementing it? Well, now you need to, parrots orย not.
5. Shadow AI Governance & Sanctioned Alternatives
Banning public AI tools is the ultimate security theaterโโโright up there with confiscating USB sticks in 2009 or banning Internet connectivity in 1998 (โbut why would you need the internet for work?!โ). It doesnโt stop usage; it just moves it to personal phones and personal accounts, where you canโt see it, log it, or ever get the dataย back.
- Parrot future: employees casually feed proprietary code and PII into consumer LLMs, generating incidents and triggering your lawyercats unnecessarily.
- AGI future: well-meaning developers hand API keys and internal data access to unmonitored shadow agents and creating a sprawling, autonomous attack surface that nobody owns. Whatย fun!
The universal control: stop playing firewall whack-a-mole. Get visibility (CASB and DLP are still a thing, yes, really!), then remove the excuse: offer a sanctioned enterprise AI tool with real contractual data protections. People take shortcuts when the official path is a dirt road. Pave it. And if your ban is still in place in 2026, understand that you donโt have a policyโโโyou have a shadow inventory problem youโve chosen not toย measure.
6. Identity & Access forย Agents
Hereโs the control nobody had on their 2016 bingo card: least privilege for machines that ask nicely. We barely handled NHI (no, we never did, IRL) and now we have โagent identityโ with a pillow fight ongoing on โis agent more like an employee or more like a workloadโโฆ
- Parrot future: AI tools and integrations quietly accumulate OAuth grants, service accounts, and long-lived API keysโโโclassic non-human identity sprawl, now with extra steps. Regular NHI problem left unsolved would kill you slowly, the agentic one will workย faster.
- AGI future: autonomous agents holding broad credentials become the single most attractive target in your enterprise. Compromise the agent, inherit its permissionsโโโand its work ethic. Tricking an agent to do โa rogue actionโ is becoming more popular everyย dayโฆ
The universal control: treat every agent, and integration as an identity with a lifecycle (!). Scope it, time-limit it, log it, and review it. Your agents currently have more access than your interns and sometimes less judgment. Fix at least one of thoseย ;-)
7. Environmental Reality Testing vs. Marketing Benchmarks
Model capability benchmarks are largely a mirage if they do not match your realities. A high score on a vendor slide means precisely nothing about your production environment, if you are notย them.
- Parrot future: blind trust in claimed accuracy yields silent failures, hallucinations in critical workflows, and surprise data leakageโโโthe parrot passed the exam and still canโt do the job. I am not adding โit will peck you to deathโ, this is where I draw theย lineโฆ
- AGI future: deploying an agentic system for consequential autonomous tasks without validation invites systemic, unpredictable behaviorโโโan advanced agent breaking things faster than you can file the postmortem.
The universal control: ignore the brochure. Run internal, multi-run reliability testing and AI red-teaming in your environment with your data before any AI system earns operational duties. Trust is earned in your environment, not on the vendorโs leaderboard. Hereโs the provocative version: if your AI procurement process accepts benchmark scores as evidence, your procurement process is part of your attackย surface.
Moving Beyond theย Debate
And, yes, we could keep adding entries (asset management, IR playbook updates for AI incidents; the list of unglamorous-but-necessary goes on). But youโve seen the pattern ten times now, so letโs nameย it.
The two camps diverge violently on timelines and on whether a discontinuous โAGI jumpโ is coming at allโโโyet they converge on the near-term necessity of architectural control, every single time. Autonomous agents, supply-chain exposure, machine-speed offense: both worldviews agree these risks are real, present, and demand actionย today.
When two groups who agree on nothing agree on your homework, the homework is probably real. If I hear one more CISO tell me they are โwaiting for the dust to settle on AIโ before building a security strategy, Iโm going to start charging for therapy. The dust isnโt settling. Itโs just turning into more data you arenโtย logging.
So the next time someone tells you they canโt build an AI security strategy until the AGI debate settlesโโโsmile, nod, and go patch something. The philosophers will still be arguing next Tuesday. Your attackers wonโt wait thatย long.
Summary
- The dichotomy: security leaders split into the โnormal technologyโ camp (from stochastic-parrot cynics to slow-diffusion โpragmatistsโ) and the โAGI by next Tuesdayโ believers (and of course less extreme middleย too)
- The core thesis: we do not need to settle the philosophical debate. Many of the same fundamental, no-regret controls apply regardless of which future arrives, and the campsโ convergence on near-term controls is itself the strongest evidence those controlsย matter.
- The no-regret controls:
- Treat configuration hygiene as tier-1 defenseโโโboth futures start at your public S3ย bucket.
- Monitor both your normal systems under AI attack and the telemetry of your AI systems themselves.
- Accelerate vulnerability management loops, with mitigation planning for the flaws you canโtย patch
- Prioritize sensitive data discoveryโโโagainst leakage (low end) and poisoning/exploitation (highย end).
- Replace blanket bans with sanctioned enterprise AI plus visibility.
- Govern non-human identities: least privilege, lifecycle, and logging for every agent and integration.
- Re-engineer threat models and containment for machine-speed intrusions.
- Ignore synthetic vendor benchmarks; mandate local adversarial red-teaming before operational trust.
โAI Normal Techโ vs โAGI by Tuesdayโ: Security Advice That Survives Either Future was originally published in Anton on Security on Medium, where people are continuing the conversation by highlighting and responding to this story.












