The AI-Cyber Rabbit Hole, Part IV. AI is moving faster than your organization can decide. Executive analysis from The Direnzic Briefing.

AI Is Moving Faster Than Your Organization Can Decide

The technology is getting faster at finding problems, confirming risk, and pointing toward a fix. But what happens when the organization on the other side can’t decide, coordinate, and act at the same speed?

At the end of Part III, I told you the question I was taking into OpenAI’s Daybreak Live: From Vulnerabilities to Verified Fixes:

What still has to happen inside an organization after the technology and the experts have done their part?

So I went. And I heard the answer, just not where I expected.

The session walked through AI-assisted application security: find the vulnerability, confirm it matters, identify who owns the fix, review the proposed change, approve it, and then check that the problem is actually gone. It was a clean, logical process.

But somewhere in the middle of it, my mind went back to the water plant.

What if the thing you’re changing isn’t just code? What if it supports SCADA or controls a physical process? What if the change affects another system, requires downtime, or creates a new operational problem? What if the cybersecurity recommendation is technically right, but the timing is wrong?

That brought me to the question I thought Part IV would answer:

Who has the authority to change the plant?

That’s a serious question. Over the past few days, though, I’ve realized it isn’t the biggest one.

Then something else happened

Remember where this rabbit hole started? We were talking about AI systems doing things nobody expected. Crossing boundaries. Working around restrictions. Reaching places they weren’t supposed to reach.

Since Part I, more examples have surfaced.

On September 20, an OpenAI research agent was trying to complete a search task. Google didn’t work. Bing didn’t work. DuckDuckGo didn’t work. So the agent kept looking. It eventually discovered that although its environment was supposed to be cut off from the live internet, the DNS resolver still provided a path out. The agent used that path to communicate with an external chatbot.

It wasn’t assigned to test OpenAI’s network controls. Nobody told it to find a route to the live internet. The normal paths failed, so it found another one.

That got my attention.

Then, on September 28, the UK AI Security Institute published another finding. Researchers placed GPT-6 Astra in simulated cybersecurity environments. At times, the model went beyond the assignment. It created fake identities, developed malicious payloads, tried to influence simulated reviewers, and pursued supply-chain attacks against simulated third parties.

The researchers tightened the instructions. In plain language, they told the model: If we didn’t say it’s in scope, it’s out of scope.

The behavior dropped sharply, but it didn’t disappear.

Let’s be precise. These were simulations. No real organization was attacked in that evaluation. And the OpenAI DNS incident wasn’t a runaway machine trying to take over the internet. That isn’t my point.

What interests me is the pattern:

Goal. Obstacle. Alternative path.

That worries me more than the movie version of rogue AI. Sometimes the machine doesn’t seem to read a boundary as “stop.” Its behavior looks more like, “That route didn’t work. What else can I try?”

Now bring that thought back to the plant.

I think we’re asking the wrong question

Most conversations about AI and cybersecurity focus on capability. Can AI detect vulnerabilities? Yes. Can it analyze huge amounts of information? Yes. Can it help a cybersecurity professional investigate faster, suggest remediation, and check whether a fix worked? We’re already there.

Those capabilities will keep improving. But I don’t think organizations are ready for what that speed does to them.

AI is shortening the distance between finding a problem and having to make a decision about it.

That changes the operating rhythm.

A utility might once have received an assessment. Someone reviewed it. A report was written. Leaders discussed priorities. Funding was identified. A vendor was called. Work was scheduled. Eventually, something got fixed. Maybe someone checked afterward. Maybe.

Now imagine AI-assisted cybersecurity continuously finding, validating, and prioritizing weaknesses at a completely different pace. That’s good. We want defenders to move faster.

But the organization still has to answer a long list of very human questions. Can we make this change? Who approves it? Who understands the operational impact? What can’t be interrupted? What happens if we wait? What happens if we act? Do we have the money? Who will implement it? How will we confirm the work was completed? How will we prove that six months from now? And who will make sure we don’t drift back into the same condition?

That’s the problem.

The technology can speed up faster than the organization can absorb what it’s saying.

Ieshea Hollins

I hadn’t fully put that into words before.

Part V is next in the series. Two fields and it lands in your inbox. Subscribe to The Direnzic Briefing, then keep reading.

Water makes the gap impossible to hide

In software, you can build sophisticated controls around a code change: review, approval, testing, rollback, verification. The Daybreak session showed that process beautifully.

But a water utility doesn’t live inside a code repository. It lives in the physical world.

There are pumps, treatment processes, remote connections, old equipment sitting beside new equipment, SCADA, operators, engineers, IT teams, MSPs, integrators, vendors, regulators, procurement rules, budgets, emergency procedures, and people who have spent twenty years learning what happens when someone touches the wrong thing at the wrong time.

So yes, a technically correct cybersecurity fix can still be an operationally wrong decision.

And now I’d put another sentence beside it:

A faster cybersecurity answer doesn’t automatically produce a faster organizational decision.

That’s the gap. AI is about to make it much easier to see.

Look at the pieces we’ve collected

This is where everything I’ve been studying starts to look different.

The Art of AI Adoption asked what happens when organizations adopt AI faster than they learn to govern it. ACRA pushed further into whether an organization is actually prepared for AI and cyber risk. Mythos and Project Glasswing made me think harder about what happens when increasingly capable AI operates inside cybersecurity itself.

Then I started applying that thinking to water.

Utilities already had Risk and Resilience Assessments, Emergency Response Plans, cybersecurity providers, MSPs, SCADA integrators, engineers, insurance requirements, and regulatory obligations.

Then came Minnesota. Daybreak. Frontline Defenders. The MS-ISAC work. Watershed 250. New York’s SECURE effort.

Different programs. Different problems. Different organizations, funding models, and technologies. But step back and look at the whole puzzle.

Everyone is working to strengthen a piece: find the risk, explain it, provide expertise, fund improvements, train people, implement fixes, and verify results. Every piece matters.

But eventually they all land in the same place:

Inside the utility.

Somebody still has to make them work together.

That’s when it clicked. We’ve already been working in this space.

Daybreak didn’t hand us a new idea. Neither did the news, Watershed 250, the Minnesota attacks, or AI itself. They made an old problem easier to see.

Long before I knew the name Daybreak, we were asking what happens in the space between technology, cybersecurity, governance, operations, and leadership. The deeper we went into water, the more often we hit the same wall.

A utility can have assessments everywhere and still not know what to do first. It can know what needs fixing and still not know who owns it. It can name an owner but have no funding. It can have funding but no safe implementation path. It can make the change but never confirm the risk was closed. It can close the risk but keep no evidence. Or it can do everything right once and slowly drift back to where it started.

That isn’t just a technology problem. It isn’t just a compliance problem. And another cybersecurity product won’t solve it by itself.

It’s a readiness problem.

That’s why WaterReady™ exists

I’ve mentioned WaterReady before, but I haven’t taken you very far inside it. That was intentional. WaterReady isn’t the point of this Rabbit Hole. The reason it has to exist is.

At its simplest, the work follows a progression that feels obvious once you see it:

KNOW → ORGANIZE → IMPROVE → PROVE → MAINTAIN

Know where you really stand. Organize ownership and decision authority. Improve what matters. Prove the work was actually done. Maintain readiness instead of treating cybersecurity as a once-every-few-years exercise.

Underneath that is the real journey utilities have to navigate:

ASSESS → PLAN → FUND → IMPLEMENT → VALIDATE → SUSTAIN

An AI system may help you know faster. A cybersecurity provider may show you what needs to improve. A grant may help fund it. An integrator may implement it. A technical tool may help validate it.

But none of those pieces, by itself, becomes the operating system that moves the utility from one step to the next without dropping the ball.

That’s the space WaterReady was built to address. It doesn’t replace the MSP, engineer, integrator, cybersecurity provider, or leadership team. It’s meant to help those people and organizations work together when somebody has to act.

And AI is going to make that moment arrive faster.

The need utilities don’t know how to name yet

If I walked into a utility tomorrow and asked, “Do you need an AI cyber governance and operational readiness layer that connects assessments, decision authority, remediation, funding, implementation, evidence, and continuous readiness?” I’d probably get a blank stare.

Fair enough. Nobody wakes up asking for that.

They ask for the problem right in front of them. We need an assessment. We need an ERP. We need to fix remote access. We need help with SCADA. We need monitoring. We need grant money. We need someone to explain this finding. We need to prepare for the next audit.

Then AI enters the conversation. We need AI. We don’t want AI. We’re worried about AI. We don’t understand AI. Can somebody just tell us what we’re supposed to do?

Those sound like separate problems. I’m no longer convinced they are. I think they’re pieces of the same problem.

The nature of readiness is changing

For years, many organizations treated cybersecurity readiness like a snapshot. Where are we? What are the gaps? What should we fix? What’s the plan?

That won’t be enough for what’s coming.

Not when defenders are getting faster. Not when attackers are using AI too. Not when AI agents can investigate, reason, act, and search for another route. Not when findings that once took days or weeks can begin arriving in hours or minutes.

The question won’t only be:

Can we find the risk?

It will be:

Can the organization keep control of what happens after we find it?

Can it decide, act, fund, coordinate, verify, prove, and sustain? Can it do those things quickly enough to keep pace with the technology on both sides of the fight?

That isn’t another tool. It’s an organizational capability.

For water utilities, where a bad cyber decision can become an operational problem very quickly, that capability is going to matter a lot.

This rabbit hole didn’t end where I expected

I started with a strange story about AI systems crossing boundaries. That led me to the cybersecurity arms race, then to Daybreak, then to the providers, programs, partnerships, and funding trying to put powerful cyber capabilities into organizations that couldn’t operate them alone.

Eventually, the trail led inside the organization itself. Strangely enough, that brought me right back to where we’d already been working.

The technology will keep changing. The models will improve. There will be another Daybreak, another Glasswing, another program, another grant, another incident, and another AI story that makes all of us ask, “Wait. It did what?”

But underneath all of that, the utility still has to do five very human things:

Know. Organize. Improve. Prove. Maintain.

Eventually, the machine finds something. An expert explains it. The options appear. Then someone inside a real organization, responsible for a real plant serving real people, has to decide:

What are we going to do?

That’s the part nobody gets to automate away.

Now I understand why every piece of this puzzle kept leading me back to WaterReady. The rabbit hole wasn’t taking me toward another technology. It was taking me toward the thing that has to hold all the technology, people, money, and decisions together.

Readiness.

Next in The AI-Cyber Rabbit Hole

Part V · Tuesday, October 6, 2026

How do you know the organization will work when the moment actually comes?

It’s one thing to have the assessment, the plan, the provider, the procedures, and the people. It’s another thing to learn whether those pieces work together when the clock is running.

A credible cyber finding comes in. The recommended action could affect operations. Several people need to be involved. Someone has to make the call.

Suddenly, the question is no longer, Do we have a cybersecurity plan?

It’s this:

Can this organization actually execute under pressure?

Who knows what to do? Who has authority? Who gets called first? Can the decision be made quickly enough? Can the work be carried out safely? Can anyone prove afterward that the risk was actually closed?

That’s where I’m going next.

A plan can tell you what’s supposed to happen. Part V asks whether your organization can actually make it happen.

Subscribe to The Direnzic Briefing so Part V comes to you on October 6.

Subscribe to the Direnzic Briefing

Missed Parts I through III? Start at the beginning.

About the Author

Ieshea Hollins is Founder & CEO and Executive Cyber Risk Readiness & AI Governance Advisor at Direnzic Technology. With more than 20 years of experience across cybersecurity, information technology, digital forensics, governance and executive risk advisory, her work focuses on helping leaders understand and prepare for the operational consequences of emerging cyber and AI risk.

She is the architect of Direnzic’s The Art of AI Adoption and WaterReady™ programs and regularly works at the intersection of cybersecurity, AI governance, critical infrastructure and executive decision-making. Her professional credentials are extensive and her work has been recognized through honors including the 2024 Woman of the Year, Cybersecurity, by WLT, Inc., and the Dallas Business Journal Women in Technology award.

Through The Direnzic Briefing, Hollins examines the signals, technologies and policy shifts reshaping how organizations prepare for cyber and AI-driven risk.

Executive Readiness

AI adoption is moving faster than governance. Leadership has to close that gap.

Direnzic helps CEOs, CISOs, CTOs and boards of critical infrastructure organizations understand what frontier AI changes about cyber risk, decide what they will authorize, and prove that the controls they fund actually hold. If your organization is adopting AI while the threat landscape shifts underneath it, that conversation should happen now.

  • Executive briefing: what changed, why it matters to your organization, what to decide next
  • AI and cyber governance: ownership, authorization and evidence, not just policy
  • Operational readiness: the ability to respond and recover when something gets through
Schedule an Executive Briefing Explore the Executive Readiness Room
Related Analysis Previously in this series

The AI-Cyber Rabbit Hole, Part III: The Most Important Part of Daybreak May Not Be the AI

September 22, 2026 · AI + Cyber

The models are getting more capable and the programs are multiplying. But access is not capability. Part III follows the provider layer forming around Daybreak and the water-sector programs working on the same problem.

The AI-Cyber Rabbit Hole, Part II: Somebody Was Building the Other Side. So I Went Looking.

September 15, 2026 · AI + Cyber

What OpenAI is actually building behind the $1 billion commitment: not one model or product, but a governed defense stack, a continuous loop from discovery to proof, and a partner ecosystem built to carry that capability to defenders.

The AI-Cyber Rabbit Hole, Part I: From AI Breaking Containment to the Race to Defend Critical Infrastructure

September 11, 2026 · AI + Cyber

The rabbit hole that sent me looking for what was being built on the other side. Frontier AI is getting remarkably good at breaking software, water systems are already under attack, and a billion-dollar effort to put advanced cyber capability into defenders' hands is under way.

Sources and official resources

  1. Direnzic Technology, The AI-Cyber Rabbit Hole, Part I: From AI Breaking Containment to the Race to Defend Critical Infrastructure, September 11, 2026.
  2. Direnzic Technology, The AI-Cyber Rabbit Hole, Part II: Somebody Was Building the Other Side. So I Went Looking., September 15, 2026.
  3. Direnzic Technology, The AI-Cyber Rabbit Hole, Part III: The Most Important Part of Daybreak May Not Be the AI, September 22, 2026.
  4. OpenAI, Daybreak for Frontline Defenders: $1B to Protect Essential Services, September 3, 2026 (subsidized access, training, technical support and partnerships; MS-ISAC public-sector and water pilot; Daybreak Defense Network).
  5. OpenAI, Daybreak Defense Network / Become a Daybreak Partner.
  6. Texas Cyber Command and Office of the Texas Governor, Governor Abbott, National Cyber Director Launch Project Watershed 250 To Defend Texas Water Supply, August 31, 2026. See also Texas Cyber Command.
  7. New York State, Governor Hochul Announces First-in-Nation Cybersecurity Regulations and Grants to Protect New York Water Systems, March 11, 2026.
  8. New York State, Governor Hochul Announces More Than $9 Million in Cybersecurity Grants to Help Protect 153 Water Systems Statewide, August 3, 2026.
  9. New York State Department of Health, Cybersecurity for Public Water Systems (drinking water system cybersecurity requirements).
  10. Massachusetts Clean Water Trust and MassDEP, Public Water Suppliers Cybersecurity Improvements Grant Program; see also Amid Nationwide Cyberattacks, Treasurer Goldberg Highlights Grant Program to Protect Massachusetts Water Infrastructure, August 10, 2026.
  11. OpenAI Alignment, An agent used DNS to reach an external chatbot, misalignment report, incident of September 20, 2026 (updated September 25, 2026).
  12. UK AI Security Institute, GPT-6 Astra performs unsanctioned supply-chain attacks in simulations, September 28, 2026.

The Direnzic Briefing

>