The S Curve
Thu, 24 SeptMelbourne · Singapore · New York
Book a call
News

AGL builds AI agent for security architecture reviews

Security architecture reviews have long occupied a peculiar position in enterprise technology: critical enough that no one questions their necessity, yet repetitive enough that

The S-Curve··4 min read
A sunburst mark with a shield over a security architecture grid

AGL builds AI agent for security architecture reviews

Security architecture reviews have long occupied a peculiar position in enterprise technology: critical enough that no one questions their necessity, yet repetitive enough that experienced practitioners can predict most findings before the first meeting ends. Australia's largest electricity generator and retailer has decided that this tension makes the work an ideal candidate for augmentation rather than elimination.

AGL has built an AI agent designed to conduct preliminary security architecture reviews, a move that reflects a broader shift in how large organisations are thinking about specialist knowledge work. Rather than deploying generative AI to answer customer queries or summarise emails, the company is aiming the technology at a task that requires deep domain expertise, pattern recognition across hundreds of prior assessments, and the ability to flag edge cases that junior reviewers might miss. The agent does not replace the security architecture team. It handles the first pass, surfacing the obvious gaps and known anti-patterns so that human reviewers can spend their time on the judgement calls that actually require judgement.

This approach matters because it sidesteps the two failure modes that have defined most enterprise AI experiments over the past eighteen months. The first is over-ambition: asking a large language model to do work it cannot reliably do, then expressing surprise when it hallucinates a compliance standard or invents a vulnerability that does not exist. The second is under-ambition: limiting AI to tasks so trivial that any productivity gain is swamped by the overhead of managing the tool. AGL's agent sits in the middle. Security architecture reviews follow known frameworks, reference established standards and rely on a body of prior work that can be encoded, retrieved and applied. The task is structured enough that an AI can add real value, yet complex enough that full automation would be reckless.

What this means for capability building

The implications for learning and development teams are immediate. If AGL can build an agent that conducts security architecture reviews, then the skills required to perform those reviews are no longer static. Junior security professionals will still need to understand threat modelling, zero-trust principles and the OWASP Top Ten, but they will also need to know how to interrogate an AI's recommendations, spot the cases where pattern-matching fails and decide when to override the agent's conclusions. That is a different skill set, and most enterprise training programmes are not yet teaching it.

The same logic applies across other domains where AI is being aimed at specialist work. Legal teams using contract review agents need to know when a clause is genuinely novel versus when it simply lacks precedent in the training data. Finance teams using anomaly detection tools need to distinguish between a legitimate outlier and a model artefact. In each case, the work is not disappearing. It is shifting from execution to evaluation, and evaluation requires a different kind of expertise: one that combines domain knowledge with a working understanding of how these systems succeed and how they fail.

L&D leaders who treat this as a purely technical problem will miss the point. Teaching people to prompt an AI or interpret its output is necessary but not sufficient. The harder task is helping them rebuild their mental models of what their role entails. A security architect who has spent a decade learning to spot misconfigurations will need to recalibrate their sense of where they add value once an agent can flag most of those misconfigurations faster than they can. That recalibration is not a training module. It is a sustained conversation about expertise, delegation and the boundaries of machine competence.

AGL's agent also raises a question that most organisations have not yet answered: who decides when an AI's output is good enough to act on? In a preliminary security review, the stakes are lower because a human will check the work before anything reaches production. But as these agents move closer to decision-making, the governance model becomes critical. If the AI flags a risk and the human reviewer disagrees, who owns the outcome? If the AI misses a risk that a human would have caught, is that a training failure, a model failure or a process failure? These are not hypothetical concerns. They are the questions that will determine whether AI agents become a genuine capability multiplier or another layer of technical debt.

The path forward is not to resist these tools or to adopt them uncritically. It is to treat them as a forcing function for clarity about what human expertise actually consists of. AGL's security architecture agent works because the company understands what a good security review looks like, what can be automated and what cannot. Organisations that lack that clarity will struggle, not because the technology is inadequate, but because they have not done the foundational work of defining what quality means in their context. That work has always been the job of learning and development. It just became more urgent.

Sources:

From The S Curve

News and insights for innovation, digital transformation, future of work and L&D leaders.

Stay ahead of learning and development, corporate innovation and digital transformation news. Plus the future of work. For leaders in AU, NZ, HK, SG, the US, the UK and Canada.