Learn Mode and Enforce Mode Are Sold in the Same Breath. They Are Not the Same Thing.
AWS is now promising you security at machine speed. The agent will find the vulnerability by itself, write the exploit by itself, and fix it by itself.
I call that a hallucination. For now.
Twenty years I have been doing pentests, and I will tell you something no vendor slide will tell you. There is an enormous difference between two things that are sold to you in the same breath.
Learn mode and enforce mode
Learn mode: the agent scans, finds, proposes – and a real human looks and decides. Honestly, excellent. That is exactly where the field needs to go. Less grunt work, more thinking.
Enforce mode: automatic. On production. With no human in the middle.
That is no longer security. That is how you break a company at the push of a button.
What an exploit actually does
An exploit is not a theoretical check. It is code that runs on a live system and changes its state.
And when the agent decides by itself that it has “fixed” something, and in the process takes down your customer-facing service at peak hour – who takes responsibility?
The machine. Really. Send it to the inquiry board.
That is exactly the part nobody likes talking about. Responsibility does not automate. Responsibility always stays with a person. And when full automation is sold to you, what is really being sold is the illusion that you can get rid of that person. You cannot.
I am not against these tools
Quite the opposite. Our own platform does a great deal of automated work, and that frees the researchers to think instead of dig.
But the decision about what to do with a finding stays with a human. Always. Because security is not only finding the hole. It is understanding the context, the business risk, what happens if you touch it. And that is precisely the part a machine still does not understand.
The summary for your business is simple: let the machine find and propose. Do not let it decide and act alone on production. The distance between those two is the distance between being a security company and being an article about a security incident.
I first shared a version of this as a LinkedIn post on 2026-07-06. It is republished here, lightly edited, so it is easier to find and reference. — Erez Metula
