AI will automate more security work, but that doesn’t mean partners should lose out.
As tech becomes easier to consume, trusted expertise becomes more valuable, according to Alex Glass, VP of global channel sales and alliances at managed detection and response provider Expel. However, partners should resist the temptation to put AI at the forefront of customer conversations.
“One of the biggest mistakes I’m seeing is partners leading with AI because it’s the hot technology rather than starting with the business outcome the customer is trying to achieve,” Glass told Channel Dive. “In the rush to live up to AI hype, many in the channel are pushing fully autonomous concepts without realizing that these AI tools inadvertently widen a client’s attack surface. The goal shouldn’t be autonomy for autonomy’s sake.”
Securing AI means looking beyond the model to gaps in the identity, SaaS and cloud infrastructure that powers AI. The three threat vectors partners should address are unvetted shadow AI tools, data pipeline exposures, and automated attacks on credentials and system weaknesses.
“AI can make detection and response dramatically faster, but it still needs context,” said Glass. “Understanding how a customer’s users, identities, cloud infrastructure and business systems operate is what allows you to separate something unusual from something truly dangerous.”
There are limits to what customers should automate. Glass said AI is well suited to detection, correlating signals across different attack surfaces and accelerating threat hunting. But humans must remain in the loop for critical decisions.
“AI can’t own the outcome or assess local business impact, and ultimately, can’t guide a client through that crisis,” Glass said. “Critical incident remediation, strategic risk management and the human conversations required during an attack simply can’t be handed over to an algorithm.”
The margin opportunity
A key commercial opportunity for partners rests in securing the infrastructure behind customer AI deployments. Channel firms can address underlying security issues while translating threat intelligence into something customers can act on.
“Partners evolve into trusted translators, giving valuable intelligence and making sure clients have the security basics for rapid tech adoption covered,” Glass said. “This lets them focus on giving the human touch that self-managed software lacks.”
As self-service security technologies become available, Glass believes that expertise becomes more important.
Partners must bring more than technology to the table. They should engage with CISOs proactively about vulnerabilities and business risk before an incident forces the conversation.
“A good conversation cuts through vendor hype to focus on practical resilience and business risk,” Glass said. “Partners need to be translators, offering clear, jargon-free threat intelligence that highlights platform gaps and architectural vulnerabilities before an incident occurs.”
Those conversations can’t be limited to renewal cycles, he added.
“The strongest partners are constantly bringing customers new intelligence and helping them understand what has changed in their environment and in the threat landscape,” Glass said. “That’s how you move from being a supplier to being someone the CISO genuinely relies on.”
Client relationships become a differentiator when AI takes over routine work. “Technology drives efficiency, but trust is built on how human teams navigate that pressure,” Glass said.
Personal contact is paramount when a customer is under attack, according to Glass.
“When a security event happens, a customer probably won’t remember which algorithm first identified the activity,” he said. “They’ll remember who answered the phone, who gave them good advice and who helped them get through the crisis.”