Autonomous remediation is 90% here. The last 10% is trust.
Every vendor claims "autonomous," but most have just wrapped an agent around the same old ticket-by-ticket workflow. The capability to automate roughly 90% of the resolution lifecycle already exists. The last 10% isn't a technical limit, it's a trust problem.
TL:DR
- Autonomous remediation is 90% automation today. Agents can already handle finding validation, ownership resolution, prioritization, fix or mitigation planning, ticketing, and follow-through, without a person doing it by hand.
- The last 10% is a trust problem, not a technical one. High-impact actions, like production patches or firewall changes, still need a human authorization checkpoint because a bad outcome there can hurt the business as much as the vulnerability itself.
- Attackers already move at machine speed. Vulnerability exploitation is the top breach vector, 31% of cases in the 2026 Verizon DBIR, and disclosure-to-mass-exploitation windows have shrunk to days or even zero for internet-facing edge systems. Defense stuck at human speed cannot keep up.
- Decision-Based Exposure Management puts the human judgment in one place: the decision. A person approves a decision once for an entire class of exposures, and agents execute it across every matching asset from then on, without a new ticket each time.
- Trust expands one action class at a time, and only with evidence. Cross-validated exploitability, dependency checks before approval, full audit trails, and one-step rollback earn the right to widen autonomy. No vendor gets to just declare the agents ready.
So it is worth being precise about what autonomous remediation actually is, what it can genuinely do today, and where a careful security team should still keep a human hand on the switch. The honest answer is more useful than the marketing one. Roughly 90% of the work can be automated now. The last 10% is not a technical limit. It is a trust problem, and trust is earned, not announced.
The word “autonomous” is doing too much work
Start with the hype, because it is doing real damage. A wave of tools now describes itself as agentic or autonomous, and most of them have taken the old task-based model and wrapped an agent around it. The agent routes the ticket faster. It drafts the remediation text. It nudges the owner. Useful, but the shape of the work has not changed: one finding, one ticket, one human still chasing it to closure. Calling that autonomous sets an expectation the product cannot meet, and when it underdelivers, the whole idea of agentic security takes the blame.
The ambition is not wrong. The marketing is just ahead of the mechanism. Autonomy worth the name does not mean doing the same manual steps faster. It means removing the need for a human to touch most of them at all, safely, with the human present exactly where judgment is required.
Why autonomy is suddenly worth wanting
The reason to want this is not novelty. It is that the other side is already automated.
Vulnerability exploitation is now the single most common way enterprises are breached, 31% of cases in the 2026 Verizon DBIR. For internet-facing edge systems, the median time from disclosure to mass exploitation is zero days, and five days for all vulnerabilities on the Known Exploited Vulnerabilities list. And the tooling behind that speed is increasingly AI. In a 2024 University of Illinois study, GPT-4 agents successfully exploited 87% of one-day vulnerabilities when handed the CVE description. Without the advisory the same agents managed only a fraction, which is precisely the point: attackers always have the advisory, and they can now turn it into a working exploit almost as fast as it publishes.
A defense that runs at human speed, one ticket at a time, cannot meet an offense that runs at machine speed across every exposed asset at once. Autonomy on the defensive side is not a luxury feature. It is the only way the math balances.
What autonomous remediation can actually do today
Here is the part the hype gets directionally right. Most of the remediation lifecycle can be handled by software now, and by our assessment that is roughly 90% of it.
Onit’s agent, for example, can pull findings from every scanner and cloud source, normalize them, remove the duplicates that show up across overlapping tools, and filter out what is not real risk. They can test whether an exposure is genuinely reachable and exploitable before it ever reaches a queue. They can resolve ownership by reading live signals across ticketing, code history, and communications. They can group exposures that resolve together, propose the fix or a compensating control, open the right tickets with the right context attached, send reminders, escalate when work stalls, and enforce SLAs to closure. Onit runs these as specialized agents working in parallel, each reasoning over the same organizational knowledge graph, so their actions stay consistent with one another.
That is real, and it is most of the job. The research, the ownership hunt, the planning, the follow-through: all of it can happen without a person doing it by hand.
The 10% that stays human
What is left is small and it is the part that matters most. Some actions carry a failure mode as bad as the risk they address. A firewall rule that blocks legitimate traffic can take down a business. A patch pushed to a fragile production system can break a revenue application. In those moments the right move is not maximum autonomy. It is a human authorization checkpoint. This is where human-in-the-loop remediation earns its place, and it is not a weakness in the model but a deliberate part of it.
That boundary is not a technical shortcoming. It is sound risk management. The useful analogy is what happened to software engineering: engineers increasingly govern agents that write the code, stepping in for the architectural calls and the judgment. Security is on the same path. Humans define judgment. Agents execute. The skill is knowing which decisions belong on which side of that line, and moving the line only as fast as trust allows.
Trust is earned, not assumed
This is where most "autonomous" claims go quiet, because trust is harder than capability. An agent that is usually right is not good enough to act unsupervised on a production estate. So the question is not whether the agent is smart. It is whether its actions are verifiable.
Onit's approach is to check agent work against evidence, not against the agent's own confidence. Exploitability is cross-validated against authoritative sources rather than asserted. Remediation proposals are checked for dependency conflicts before they reach a human for approval. Every action an agent takes is written to a full audit trail, and every action can be undone with one-step rollback, so a mistake is recoverable rather than permanent. Onit also operates under SOC 2 Type II, ISO 27001, and ISO 42001, the management-system standard built specifically for AI. The point of all of it is to earn the right to expand autonomy one action class at a time, as accuracy in that class is demonstrated, not assumed.
That is how the human authorization zone narrows responsibly. Not by a vendor deciding the agents are ready, but by the evidence showing a given class of action is safe to hand over.
Decision-Based Exposure Management: where the autonomy actually lives
The practical form autonomy takes today has a name: Decision-Based Exposure Management, the category Onit built. It resolves the tension between "let the agents run" and "keep humans in control" by putting the human judgment in exactly one place, the decision.
A decision is a human's call about an entire class of exposures that share a root cause, a fix, or an owner: this exposure, these assets, this owner, this resolution. A person approves it once. Agents then execute it across every matching asset at the same time, and the decision persists as an operating rule, so the next exposure that fits the pattern is handled automatically, without a new ticket or a new approval. That is genuine autonomy, and it is safe, because the scope of what the agents may do was set by a human judgment and every action remains reversible. Decide once. Resolve forever.
The teams that build trust now will own the autonomy later
Autonomous remediation is not a switch you flip. It is a boundary that moves, and it moves at the speed of demonstrated trust. Anyone promising full autonomy today is selling the 90% as if it were the 100%, and skipping the part that actually protects you.
The honest version is better anyway. Automate the 90% that can be automated now. Keep a human on the 10% that could hurt you. Earn the right to move the line with evidence, one action class at a time. The teams that build that agentic foundation now, with the validation and the guardrails in place, will be the ones ready to capture fuller autonomy the moment it is proven safe.
See what autonomous remediation looks like when a human still owns the judgment. Get a demo.
Frequently asked questions
Autonomous remediation is the resolution of security exposures by software agents rather than by manual, ticket-by-ticket human effort. In practice today it means agents handle the bulk of the lifecycle, context gathering, ownership resolution, prioritization, fix or mitigation planning, execution, and follow-through, while humans approve the high-impact actions. It is different from tools that simply auto-open a ticket, which automate a step without changing who does the work.
Not for every action. By our assessment about 90% of the resolution lifecycle can be automated now. The remaining 10% involves actions whose failure could damage the business as much as the vulnerability would, such as production patches or firewall changes. Those should stay behind a human authorization checkpoint until trust in that specific action class is earned through demonstrated accuracy.
The consequential judgment calls. Humans approve actions that could cause an outage, validate ownership, calibrate how agents behave, and can override any recommendation. Agents handle everything upstream and execute approved decisions. The principle is simple: humans define judgment, agents execute.
Onit checks agent work against evidence rather than the agent's own reasoning. Exploitability is cross-validated against authoritative sources, remediation proposals are checked for dependency conflicts before approval, every action is logged to a full audit trail, and every action can be undone with one-step rollback. Onit also operates under SOC 2 Type II, ISO 27001, and ISO 42001, the AI management-system standard. Autonomy expands one action class at a time, as accuracy is proven.