The Adoption of Autonomous AI Agents in Cybersecurity: A Qualitative Case Study of Early-Stage Adoption in a Security Organisation
Information
Författare: Elias BergmanBeräknat färdigt: 2026-06
Handledare: Elin Carlsson
Handledares företag/institution: Atea
Ämnesgranskare: Göran Lindström
Övrigt: -
Presentation
Presentatör: Elias BergmanPresentationstid: 2026-06-10 16:15
Opponent: Nils Blomberg
Abstract
The growing use of artificial intelligence in cybersecurity represents a significant shift in how
security work can be organised and performed. As cyber threats become faster, more complex and increasingly difficult to manage manually, autonomous AI agents are emerging as a possible way to support detection, analysis and response. However, adopting such systems raises more than technical questions, because cybersecurity work also considers questions such as reliability, traceability, accountability and control.
This thesis investigates the early-stage adoption of autonomous AI agents within cybersecurity organisations. It aims to understand the most important factors influencing adoption across technological characteristics, organisational conditions and the external environment. Drawing on a combined Diffusion of Innovations and Technology-Organisation-Environment framework, the study takes a socio-technical perspective. A qualitative single case study was conducted at Atea Sweden, based on semi-structured interviews with respondents from the strategic, tactical and operational levels of the security organisation.
The findings show that adoption is shaped by a tension between acceleration and restraint, in
which the qualities that make autonomous agents attractive are also those that raise the most caution. The agents are valued for handling growing data volumes, faster threats and complex technical work, especially in operational tasks. The adoption however, is limited by concerns regarding complexity, transparency, data quality, reliability and accountability. The study concludes that the main question is not whether AI should be used, but how much autonomy can be trusted. In particular, data control, transparency and accountability emerge as central conditions across all three contexts.