GoFirm
Back to Blog
GoFirm·3 min read

Four questions that predict which security categories survive AI. One category the framework missed.

By GoFirm Team

Ross Haleliuk published a piece this week asking which security products will survive in the AI-first world. His framework is four questions. Products that answer yes to the first three and no to the fourth are durable. The rest are vulnerable.

The questions are: does the product do in-line enforcement; does solving the problem require runtime data; does it require a model of a complex system; and can the problem be fixed with a single pull request?¹

It is a good framework. It also has a blind spot: authority confirmation at the execution boundary doesn’t appear anywhere in it. But when you run GoFirm through the four questions, the result is unambiguous.

Does it do in-line enforcement?

Yes. GoFirm sits at the execution boundary of consequential actions - financial transactions, sensitive system access, agentic AI decisions, privileged operations - and enforces a hard halt until a named human authority confirms on a registered device through a separate channel. It does not analyse, recommend, or report. It enforces. The action proceeds or it does not.

Does it require runtime data?

Yes. The confirmation event - the biometric, the named authority, the exact action parameters, the timestamp - exists only at the moment of execution. It cannot be generated from static analysis, threat intelligence, or documentation. The audit trail GoFirm produces is runtime data that cannot be replicated any other way.

Does it require a model of a complex system?

Yes. Who is the named authority for this action type in this organisation? What constitutes a consequential action here? Which workflows require single authority and which require multiple? Those answers are organisation-specific, must be configured, and must be maintained as the organisation changes. No AI can produce them from a screenshot or a paragraph of text.

Can the problem be fixed with a pull request?

No. Unverified authority at the execution boundary is not a code problem. It is an architectural and governance problem that spans multiple teams, workflows, systems, and organisations. The $46.7 million stolen from Ubiquiti Networks in 2015 was not a software bug. The US Treasury breach via a compromised vendor API key in 2024 was not a software bug. The Stryker attack in 2026 was not a software bug. These were authority failures. A pull request does not fix them.

Haleliuk’s conclusion is that the products most likely to benefit from the AI transition are those built around enforcement, runtime data, and complex system models - categories where AI increases demand rather than replacing the product. GoFirm sits squarely in that territory, and the demand signal is accelerating: agentic AI systems executing at machine speed without a confirmed human authority requirement is precisely the governance gap that enterprises, regulators, and boards are now being forced to address.

The framework didn’t include authority confirmation as a category. It should have.

GoFirm is The Authority Platform. Stop unauthorised action. Every time.

In association with Osinto.ai, the collective intelligence platform for Security, Resilience & Defence. Osinto’s AI-enabled open-source network and governed collaborative operational environment helps synthesise data across conflict zones to cyberspace to achieve defensible decision advantage, and provide the evidentiary proof required to reduce liability exposure.

References

1. Ross Haleliuk, Four questions to answer if a security product will survive in the AI-first world, Venture in Security, June 2026

Share this article