2023: The Generative AI Revolution and the Beginning of a New Cybersecurity Era
The story of modern AI security did not begin with autonomous agents. It began when generative AI became accessible to almost everyone.
This article is Part 1 of From Generative AI to AI Agents: Why the Next Five Years Will Change Cybersecurity.
In 2023, artificial intelligence changed from something many people primarily associated with research laboratories, specialized software, and machine-learning teams into something ordinary employees could use directly.
People could suddenly ask AI to write, explain, summarize, translate, analyze, code, brainstorm, and create.
The interface was simple.
Open a browser.
Write a prompt.
Receive an answer.
But behind that simple interaction was a much larger technological shift.
AI was becoming part of everyday digital work.
And that created a new cybersecurity question:
What happens when employees begin using powerful AI systems with access to business information?
That question was only the beginning.
Over the following years, AI would move from generating information toward using tools, interacting with applications, and performing increasingly complex tasks.
Understanding 2023 therefore helps explain why cybersecurity becomes increasingly important in the age of AI agents.
2023 Was the Beginning of a New AI Era
Artificial intelligence had existed for decades before 2023.
Machine learning, natural-language processing, computer vision, recommendation systems, speech recognition, and other AI technologies were already being used commercially.
What changed was accessibility.
Generative AI made sophisticated AI capabilities available through natural-language interfaces.
Instead of requiring a specialized technical workflow, a user could simply describe what they wanted.
For example:
"Summarize this document."
Or:
"Write a Python function that does this."
Or:
"Explain this technical concept."
Or:
"Create a marketing campaign for this product."
The technology was no longer hidden behind specialized interfaces.
It was becoming a general-purpose computing interface.
From Search to Generation
For many years, the web had trained people to think in terms of search.
The process was approximately:
Question → Search → Results → Human interpretation
Generative AI introduced another model:
Question → AI → Generated response
This difference was significant.
Search primarily returned information that already existed somewhere.
Generative AI could synthesize information into a new response.
That meant users began interacting with computers differently.
Instead of searching for a document, they could ask AI to summarize it.
Instead of searching for programming examples, they could ask AI to generate code.
Instead of searching for marketing ideas, they could ask AI to create them.
The computer was becoming an active participant in knowledge work.
The New Interface Was Language
One of the most important changes was the interface itself.
Historically, computers generally required users to understand the application's interface.
Menus.
Forms.
Commands.
Search boxes.
Programming languages.
APIs.
Generative AI made natural language a powerful interface to computing capabilities.
The user could describe an objective rather than necessarily knowing the exact sequence of operations required to achieve it.
That idea would become extremely important later.
Because once natural language becomes an interface for computing, the next question is:
What happens when the system can do more than generate an answer?
The 2023 AI Workflow
The typical generative AI workflow looked something like this:
Human → Prompt → AI Model → Generated Response → Human Reviews → Human Takes Action
The human remained the primary operator.
The AI generated information.
The person decided what to do with it.
This distinction is important because it limited the AI system's direct authority.
The AI could produce a recommendation.
The human could accept or reject it.
The AI could generate code.
The developer could review it.
The AI could summarize a document.
The employee could decide what to do with the summary.
This was still largely an assistant model.
Then Businesses Started Giving AI Real Information
The next major shift was inevitable.
If AI could help people work, employees wanted to give it real work.
That meant providing real information.
Documents.
Customer conversations.
Source code.
Business plans.
Contracts.
Product specifications.
Internal processes.
Financial information.
Support tickets.
Research.
The usefulness of AI increased when it had more context.
But the security implications increased at the same time.
A simple question emerged:
What information should an employee be allowed to provide to an external AI system?
This was one of the earliest major enterprise AI security questions.
The First AI Security Problem: Data
Traditional cybersecurity already focused heavily on protecting business information.
AI introduced another path through which information could move.
Consider a simple scenario.
An employee receives a customer document.
They want AI to summarize it.
They copy the document into an external AI service.
The employee's intention may be completely legitimate.
But from a security perspective, several questions appear.
What information was included?
Was the information confidential?
Was the employee authorized to share it?
Which AI service received it?
How is the information handled?
What organizational policy applies?
What controls exist around AI usage?
The technology itself does not determine the answer.
Organizations need policies, access controls, data governance, and security processes appropriate to their environment.
Shadow AI
Another important concept emerged as employees began adopting AI tools independently.
An organization might officially approve one AI platform.
Employees might nevertheless use several others.
They could use AI for:
Writing
Coding
Research
Translation
Design
Analysis
Customer communication
Productivity
Some of these tools might never pass through the organization's formal IT procurement process.
This creates a familiar cybersecurity problem:
The organization may not know everything being used inside its environment.
That is not unique to AI.
The same problem exists with applications, cloud services, browser extensions, and unmanaged devices.
But AI added another rapidly changing category of services.
Why Visibility Became Important
This is where a fundamental cybersecurity principle becomes relevant:
You cannot effectively manage what you cannot see.
If an organization does not know:
which devices exist
which users have access
which applications are being used
which systems contain sensitive information
where security weaknesses exist
then its security picture is incomplete.
AI increased the importance of that visibility because employees could rapidly adopt new services.
This is one reason endpoint inventory and endpoint visibility remain important even as technology changes.
The AI application may exist in the cloud.
But the employee still needs a device to access it.
The Endpoint Did Not Disappear
The arrival of generative AI did not eliminate traditional computing.
Employees still used:
laptops
desktops
browsers
operating systems
development environments
business applications
networks
AI simply became another layer in the environment.
This is important because cybersecurity did not suddenly become an "AI-only" problem.
Traditional risks remained.
Operating systems still had vulnerabilities.
Applications still required security controls.
Credentials still needed protection.
Endpoints still needed monitoring.
Users still needed appropriate access.
Security events still needed investigation.
AI added another dimension to an already complex environment.
AI Also Changed Software Development
One of the most significant uses of generative AI was software development.
Developers could ask AI to:
generate code
explain code
refactor code
write tests
identify potential issues
document software
troubleshoot problems
This created major productivity opportunities.
But it also created new questions.
Where did generated code come from?
Was it correct?
Did it contain vulnerabilities?
Did it introduce insecure dependencies?
Did developers understand the code being incorporated into production systems?
Again, AI did not eliminate existing software security problems.
It changed the speed and scale at which software could be produced.
That distinction would become even more important later as AI moved toward autonomous software development and agentic workflows.
AI Made the Human Review Step More Important
In 2023, a useful mental model was:
AI generates. Human verifies.
The human was still responsible for evaluating the output.
That was important because generative AI systems could produce incorrect or misleading results.
An answer could sound confident without necessarily being correct.
Generated code could appear plausible while containing defects.
Generated summaries could omit important context.
Therefore organizations needed to develop an understanding of where AI could be used safely and where human review remained necessary.
This principle would later become more complicated.
Because if AI eventually performs actions directly, the question changes from:
"Did a human review the answer?"
to:
"What controls exist before the AI takes the action?"
The Difference Between Information and Action
This is the central idea connecting 2023 to the later agentic era.
In the early generative AI model:
AI → Information
The system generates something.
A human decides what happens next.
In a more autonomous model:
AI → Action
The system may perform something in another system.
That transition changes the security requirements.
Consider two examples.
Example 1: Generative AI
An AI writes an email.
The employee reviews it.
The employee sends it.
Example 2: Agentic AI
An AI determines that an email should be sent.
It accesses the appropriate system.
It creates the message.
It sends the message.
The second workflow requires considerably more authority.
The AI needs access.
It may need credentials.
It may need an identity.
It may need permission to perform an action.
The organization may need to record what happened.
This is the road from generative AI to agentic AI.
2023 Introduced the First Layer of the AI Security Stack
The first major layer was data awareness.
Organizations needed to understand:
What information can AI access?
What information can employees provide?
Which AI services are approved?
Where can sensitive information go?
What policies apply?
How should employees use AI?
These questions remain relevant today.
But they are no longer enough.
As AI becomes more capable, the security model has to expand.
The Security Model Starts Expanding
A simplified 2023 AI environment could be represented as:
Employee → Endpoint → AI Service → Business Data
The security questions were primarily:
Is the endpoint secure?
Is the user authorized?
Is the data appropriate to share?
Is the AI service approved?
Is sensitive information protected?
The future architecture becomes more complicated.
Employee → Endpoint → AI Agent → Tools → Applications → APIs → Business Data
And potentially:
Agent → Agent → Agent → Business Systems → Business Data
That is a fundamentally different security environment.
Why 2023 Still Matters in 2026
It may be tempting to look back at 2023 as the early stage of AI and consider it obsolete.
It is not.
Many of the security questions introduced during the generative AI wave remain foundational.
Organizations still need to understand:
AI usage
data exposure
access
identity
endpoints
applications
vulnerabilities
security monitoring
user behavior
third-party services
The difference is that the scope is expanding.
What began with:
"What information are we giving AI?"
is evolving toward:
"What authority are we giving AI?"
That is a much bigger cybersecurity question.
From Shadow AI to Agentic AI
There is an important progression here.
Stage 1: Shadow AI
Employees independently use AI services.
The organization may have limited visibility.
Stage 2: Managed AI
Organizations approve specific AI tools and establish policies.
Stage 3: Integrated AI
AI becomes part of business applications and workflows.
Stage 4: Agentic AI
AI systems can potentially use tools and perform multi-step tasks.
Stage 5: Multi-Agent Systems
Multiple AI agents may coordinate across systems.
Each stage introduces additional security considerations.
The challenge is not that one stage suddenly replaces the previous one.
Organizations may operate all of these models simultaneously.
What Cybersecurity Teams Need to Learn
The emergence of AI does not mean cybersecurity teams need to abandon everything they already know.
Many traditional security principles remain fundamental.
Visibility
Know what exists.
Identity
Know who or what is accessing systems.
Access control
Limit what each identity can access.
Monitoring
Understand what is happening.
Vulnerability management
Identify and manage weaknesses.
Threat detection
Identify potential malicious or suspicious activity.
Alerting
Surface information that may require attention.
Investigation
Understand what happened.
Response
Take appropriate action.
AI adds new entities and workflows to these existing principles.
Endpoint Security Becomes Part of the AI Story
This is an important point for businesses.
The AI model may run in a cloud environment.
The application may be hosted remotely.
The agent may use APIs.
But employees still access these systems through endpoints.
Those endpoints remain part of the organization's security environment.
An employee might use:
a laptop
a browser
an IDE
a terminal
a collaboration application
a cloud console
AI may interact with many of the same environments.
Therefore endpoint security remains an important layer of the overall architecture.
Why Endpoint Visibility Matters
Imagine a business where employees use AI heavily.
One employee uses AI for coding.
Another uses it for customer support.
Another uses it for research.
Another uses it for marketing.
Another uses AI-assisted development tools.
If the organization has no visibility into its endpoint environment, it becomes harder to understand where those activities are occurring.
Endpoint visibility provides a foundation for understanding the device environment.
Endpoint monitoring adds the ability to observe activity and status over time.
Security monitoring provides broader security context.
Threat detection focuses on potential threats.
Vulnerability management focuses on weaknesses.
These are different capabilities, but together they contribute to a stronger security foundation.
2023 Taught Businesses an Important Lesson
The most important lesson from the first year of mainstream generative AI was not simply:
"AI is powerful."
Businesses already understood that quickly.
The deeper lesson was:
Technology adoption can move faster than security processes.
Employees can adopt new tools in days.
Organizations may take considerably longer to create:
policies
approval processes
access controls
monitoring
training
governance
security workflows
This gap can create risk.
The same pattern can happen again with AI agents.
The Next Question Was Inevitable
Once AI could generate useful information, businesses wanted more.
They wanted AI to:
access information
understand context
interact with applications
perform repetitive tasks
coordinate workflows
make recommendations
execute actions
This is where the story moves beyond generative AI.
The next stage is not simply better content generation.
It is AI that participates in work.
And eventually:
AI that can act.
From 2023 to 2024
The transition can be summarized simply.
2023
AI generates.
The primary interaction is:
Human → Prompt → AI → Response
The emerging next stage
AI participates.
The interaction becomes:
Human → AI → Workflow → Business System
That shift creates new questions around access, permissions, applications, identity, monitoring, and security.
The following article in this series examines that transition.
What Comes Next
Part 2: 2024 — When AI Entered the Business Workflow
The next stage explores how AI moved beyond standalone conversations and became increasingly integrated into:
productivity software
software development
customer support
business applications
search
research
data analysis
enterprise workflows
The central question changes from:
What information are we giving AI?
to:
What systems are we allowing AI to interact with?
That question takes us one step closer to today's agentic AI environment.
Conclusion
2023 was not the year AI was invented.
It was the year AI became dramatically more accessible to ordinary users and businesses.
Generative AI changed the interface between humans and computers.
Natural language became a powerful way to interact with computing systems.
Employees began using AI for real work.
Businesses began connecting AI with real information.
And cybersecurity teams began confronting a new reality:
AI had become part of the organization's digital environment.
At first, the primary concern was information.
What data goes into AI?
Where does it go?
Who can access it?
What should employees be allowed to share?
But that was only the first chapter.
As AI became more capable, the next question emerged:
What if AI does not just generate information, but actually performs the work?
That is where the story moves from generative AI to agentic AI.
And that is where cybersecurity becomes even more important.
2023 taught us to secure AI usage. The following years would force us to think about securing AI actions.
Return to the series introduction: From Generative AI to AI Agents.
Secure the Foundation Before AI Acts
Visibility, monitoring, and endpoint security remain essential as AI usage expands from information to action.
No credit card required.
Related DotlyGuard topics
Series Introduction
From generative AI to AI agents — why the next five years change cybersecurity.
Endpoint Security
Protect business devices where AI-enabled work still happens.
Endpoint Visibility
Understand devices and security-relevant context across the environment.
Endpoint Monitoring
Observe endpoint conditions as AI tools proliferate.
Security Monitoring
Maintain broader awareness of security-related information.
Threat Detection
Identify potential threats and suspicious activity.
Vulnerability Management
Identify and manage weaknesses that remain relevant in an AI era.
Endpoint Security Alerts
Surface information that may require investigation.
What Is Endpoint Security?
Foundational guide to protecting business endpoints.
Series
From Generative AI to the Agentic Enterprise
2023: The Generative AI Revolution and the Beginning of a New Cybersecurity Era (this article)
**2027: The Multi-Agent Organization** (forward-looking scenario)
**2028: The AI-Native Business** (forward-looking scenario)