Multiple reputable security solutions in the market that calls itself AI, including some I have personally used, is not even close to what I would consider an AI system. So I started asking a simple question: is there anyone actually checking these claims? The answer is not very encouraging.
The term AI has become another marketing word. Put it on a product page and suddenly the product sounds smarter. But where is the evidence? Where is the machine learning? Where is the learning, the adaptation, or any real intelligent methodology behind the product?
I have tested at least five very reputable security solutions, from email security and network detection to endpoint protection and asset management. The interesting part is that the tests were not complicated. In fact, they were surprisingly simple. And some of these products failed very quickly.
Don’t buy the label
This is not about being skeptical of AI. It is about understanding what you are buying. If a vendor tells you that its product is intelligent, ask what actually makes it intelligent. Don’t accept a few impressive diagrams and a page full of terminology as an answer.
“A shiny car is still not a Ferrari just because somebody puts a Ferrari badge on it.“
The same applies to AI.
What concerns me more in information security is the expectation this creates. You may believe your security solution is smart enough to detect something because the vendor told you it uses AI. Then you discover that behind the scenes there is nothing particularly intelligent happening. That can become a security problem, not just a marketing problem.
Test it yourself
The good news is that you don’t need a PhD in artificial intelligence to challenge many of these claims. Simply use the trial period.
Create situations where the product should demonstrate the capability it claims to have. Change the conditions. Try something unexpected. See whether the product actually adapts or whether it simply follows the same predefined logic.
If a vendor refuses to give you a meaningful trial, I would move on. A vendor should be confident enough in its own product to let you test it. Don’t buy the terminology. Buy the capability.
And if the capability cannot survive a simple test, I don’t really care what they decided to call it.