4 min read

The ATM or the iPhone - Which Is the AI Story?

The ATM or the iPhone - Which Is the AI Story?

There are two stories about what technology does to the people who do a job. Both are true. They just have different endings. 

Story One: The ATM Impact

When the ATM arrived in the late 1960s, the consensus was clear: a machine that dispenses cash and accepts deposits would eliminate the people who did that manually.

As Boston University economist James Bessen documented, bank teller employment in the United States grew from roughly 500,000 to nearly 600,000 between the 1980s and 2010 - even as 400,000 ATMs were deployed across the country. The mechanism was counterintuitive: ATMs made branches cheaper to operate, so banks opened more of them. And with routine cash-handling offloaded to machines, instead of replacing tellers, tellers evolved; they became relationship bankers - building customer trust, identifying financial needs, and doing work that no ATM could replicate. Their wages went up.

The machine didn't replace the human. It changed what the human was for - and made them more valuable in the process.

Story Two: The iPhone

Then came the iPhone.

The iPhone didn't try to do what tellers did. It didn't automate a transaction or speed up a deposit. It made the place where tellers worked - the branch - structurally unnecessary for most people most of the time. Bank of America went from 288,000 employees in 2010 to 204,000 in 2018. The teller jobs that had survived and grown through 40 years of ATM deployment were gone within a decade.

The ATM automated tasks within an existing paradigm. The iPhone made the paradigm obsolete.

Same profession. Two technologies. Two completely different outcomes.

The Question No One Can Assertively Answer: Which Is the AI story?

From my perspective - the one I came back with after a week at RSAC 2026, meeting with over a dozen security vendors across AI SOC platforms, SOAR tools, workflow automation, and Microsoft's own security teams - is that we don't know yet.

What we do know is this: right now, in 2026, AI in the SOC looks a lot more like the ATM than the iPhone. It's automating tasks within an existing paradigm - triaging alerts, correlating telemetry, summarizing incidents, drafting reports. The human analyst is still the one who investigates, contextualizes, and decides. The paradigm hasn't shifted. The branch is still open.

What We Know for Certain Right Now – AI Defenses get Tricked

While the bigger question remains open, there is one thing the evidence makes unambiguous: AI defenses get tricked.

  • Check Point Research (2025) found that embedding prompt injection instructions into malicious code could manipulate AI analysis tools into classifying threats as benign - the AI compromised by the very content it was analyzing.

  • Palo Alto Unit 42 (2024) used large language models to generate over 10,000 malware variants engineered to evade AI detection systems. The evasion rate was 88%.

  • Google's Threat Intelligence Group (2025) documented PROMPTFLUX - malware that uses LLM inference at runtime to continuously rewrite its own code, producing samples that shift away from AI detection signatures in real time.

  • Zombie ZIP (March 2026) - a technique exploiting malformed ZIP archive headers - was tested against 51 antivirus engines, including AI-enhanced solutions. It evaded 50 of them.

  • The CrowdStrike 2026 Global Threat Report adds further context: 82% of observed intrusions are now malware-free, relying on legitimate tools that automated systems struggle to distinguish from normal activity. Average adversary breakout time has dropped to 29 minutes.

While human analysts don't catch everything AI misses either, the real argument isn't "humans are the fallback that catches what AI drops." It's that a SOC with deep analyst capability operates on multiple overlapping layers - and when AI fails at one layer, there are other detection surfaces still active. A SOC that has over-delegated investigation to AI and invested less in their analysts’ technical skills has fewer of those layers.

How We're Playing It at Bulletproof SOC

At Bulletproof SOC, one of the mental models we've adopted is the Crawl, Walk, Run: A Practitioner's Guide to AI Maturity in the SOC. We don't grant AI autonomy before we've built the governance, measurement, and trust required to know whether it's helping or generating noise. Prove value first in bounded use cases then expand deliberately.

We've already deployed AI-driven tools for reporting and QA. The quality assurance tooling for example, independently audits analyst triage decisions, investigation quality, and escalation logic - a layer of consistency that scales with our team and catches categories of error before they reach the customer.

At the same time, what has always differentiated Bulletproof is the skills depth of our analysts. They don't catch and dispatch - they investigate. They are required to understand the incident: the kill chain, the lateral movement, the intent. They already operate at a level most organizations would call Tier 2. That depth is not a legacy artifact we're looking to automate away. It's the edge we're protecting.

Our Posture

We are not frozen by uncertainty. We are building in a way that wins under both outcomes. Investing in our analysts as we believe that they will evolve our SOC in both cases and that AI will evolve them to do other valuable work.

We're adopting AI where it demonstrably strengthens our analysts and our quality. We're maintaining the human capability that makes us still resilient when AI fails - and that makes us excellent when it doesn't. And we're watching the paradigm closely, ready to move faster if the picture changes.

The ATM and the iPhone are both real. We just don't know yet which one we're living through. What we do know is that the worst possible response to that uncertainty is to pick the optimistic story and bet everything on it.

Final Thoughts

The real risk with AI isn’t that it will replace people, it’s that organizations will over‑automate before they understand where human judgment still matters.

AI may ultimately reshape the paradigm. Or it may continue to act as an accelerator within it. Right now, the evidence suggests we’re still in the ATM phase, automation that amplifies skilled analysts rather than replaces them.
The safest posture in an uncertain transition is not blind optimism or blanket resistance. It’s deliberate adoption: proving value, preserving human depth, and building systems that remain resilient when automation fails and exceptional when it works.


The ATM and the iPhone were both transformative. The mistake is assuming you know which story you’re in before the ending is written.

Want to Learn More About Bulletproof SOC Services?

If you’re evaluating how to strengthen detection, response, and resilience, without over‑delegating critical judgment to automation here are a few next steps:

  • Explore how our SOC operates: Built around deep analyst expertise, layered defenses, and deliberate AI adoption

  • Understand where AI fits (and where it doesn’t): See how we use AI to improve quality and scale without sacrificing human judgment

  • Talk through your current posture: Whether you’re reviewing an existing SOC, MDR provider, or internal model

Start the conversation when it makes sense for you.  We’re happy to walk through our approach and how it applies to your environment.

Bulletproof Credentials

With 25+ years of IT, cybersecurity, and compliance experience, Bulletproof is a trusted Microsoft and Fortinet partner supporting organizations across North America. Our credentials include recognition on CRN’s 2026 Solution Provider 500, Fast Growth 150, and MSP 500 lists; Microsoft Security Trailblazer Award winner; 2021 Microsoft Global Security Partner of the Year; and 5× Microsoft Canada Security IMPACT Award winner. Bulletproof is also SOC 2 Type 2 compliant, a member of the Microsoft Intelligent Security Association, and a Fortinet Advanced Expert Partner, backed by 24/7 SOC, NOC, Service Desk, and Technology Operations capabilities.

Is Your Microsoft Environment Ready for Copilot and AI?

Is Your Microsoft Environment Ready for Copilot and AI?

Your employees already have new AI coworkers.

Read More
Securing Canada's Digital Communities: A Cybersecurity Roadmap for Municipalities

Securing Canada's Digital Communities: A Cybersecurity Roadmap for Municipalities

Security is no longer just about systems - it's about behavior

Read More
The Next Insider Threat Will Not Be Human

The Next Insider Threat Will Not Be Human

Author: Christopher Simm, CTO, Bulletproof

Read More