Robot Performance Management Risks = f(Cybersecurity AI Agents, Human Risks)
You have a performance review cycle for your SOC analysts. Goals, check-ins, regular conversations about what's working and what isn't. When someone stops performing, you notice, you document it, and eventually you do something about it.
When did you last have that conversation about your AI agents?
You're not alone if your honest answer is "never." If performance conversations with your human cyber-defenders already make you feel like it's time for a major medical procedure without enough anesthesia, adding one more with an agent sounds like the last thing you need.
In a recent McKinsey Talks Talent episode, Kate Smaje put it plainly: most organizations can't recall the last time they prioritized a conversation about the performance of their nonhuman labor. We've built decades of infrastructure for managing human performance. For agents, most companies have nothing.
That gap should worry a CISO more than almost anyone else in the building.
Smaje makes a point that should sound familiar if you've been reading our posts: standing up an agent doesn't mean you get to hand off the judgment that used to sit with a person. As she puts it, the rise of AI doesn't mean we all get to delegate our responsibilities for quality control and critical thinking. The tool changed. The obligation didn't.
Which raises a question we've asked about the CFO and cybersecurity risk management: who actually owns that? Smaje's answer is that the business-domain owner using the agent should own its performance, the same way they'd own a human cyber-defender's performance. Not the CTO, not IT by default. Whoever's accountable for the outcome the agent produces owns its performance management.
Now for the part that should really get your attention as a CISO: agents decay. Smaje's term for it is "abandonware," a perfectly fit-for-purpose agent from six months ago that's quietly become a liability nobody's watching. Think about what that is: an unmonitored actor with standing access to your systems, doing something, indefinitely, until someone happens to remember it exists.
We've talked in this series about insider threats arising from unintentional damage, negligence, and malice. Abandonware doesn't fit neatly into any of those buckets. It's a piece of infrastructure that was never negligent in the human sense. It's just still running, with nobody assigned to notice when its behavior drifts, its scope creeps, or its access becomes a liability. That's what happens by default when performance management for agents doesn't exist.
Cybersecurity performance is not exempt from this. If your organization runs AI-based threat detection, automated triage, or agentic response tooling, ask the same three questions Smaje poses for any agent: How many do you actually have? Who's accountable for how well they're performing? What value are they still creating?
A security agent nobody's evaluating isn't a security asset, it's an assumption you're making about a system you stopped watching. You know what we say when you ASSUME things.
Talent management and cybersecurity risk management have always been the same discipline wearing different clothes. Now that discipline has to cover agents with the same rigor you'd apply to a human hire: defined scope, an owner, a review cycle, and a plan for what happens when performance drifts or the role no longer exists.
We at Pythia Cyber build that rigor for the human side of your organization. The same questions apply to the digital half of your workforce. Are you asking them yet?
Ask us how to build performance management for the workforce you can see, and the one you can't.

Comments
Post a Comment