Top AI Cybersecurity Companies 2026: 8 Leaders Compared
The Brief
The Pulse Top AI cybersecurity companies in 2026 are no longer competing only on who has the smartest security copilot. The market is moving toward AI systems that can investigate alerts, hunt threats, prioritize vulnerabilities, generate detections, secure AI agents and increasingly take bounded defensive actions across enterprise environments. The leading platforms are taking different […]
Why It Matters
The story matters because it changes how buyers, builders, or policymakers should read the Enterprise AI market.
Watch Next
Watch whether the signal becomes a budget, procurement, or platform decision in the next cycle.
The Pulse
Top AI cybersecurity companies in 2026 are no longer competing only on who has the smartest security copilot. The market is moving toward AI systems that can investigate alerts, hunt threats, prioritize vulnerabilities, generate detections, secure AI agents and increasingly take bounded defensive actions across enterprise environments.
The leading platforms are taking different routes. CrowdStrike is turning Charlotte AI into an extensible agentic security workforce. Palo Alto Networks is combining Cortex XSIAM and AgentiX for autonomous security operations while Prisma AIRS secures AI systems themselves. Microsoft is embedding Security Copilot agents across Defender, Entra, Intune and Purview. SentinelOne’s Purple AI can autonomously initiate investigations, while Google Security Operations combines Gemini agents with Mandiant and VirusTotal intelligence. [CrowdStrike Charlotte AI AgentWorks] [Palo Alto Networks Cortex AgentiX] [Microsoft Security Copilot] [SentinelOne Purple AI]
There is therefore no single best AI cybersecurity company for every organization. CrowdStrike is particularly strong around endpoint-driven security operations, Palo Alto Networks around broad SOC transformation and AI security, Microsoft inside Microsoft-heavy environments, SentinelOne around autonomous investigation, Google around threat intelligence and agentic SecOps, Darktrace around behavioral AI, Check Point around prevention and AI protection, and Checkmarx around application security.
Core Significance
Why it matters:
- “AI cybersecurity” now describes several different markets: A conversational assistant, an autonomous SOC agent, a behavioral detection engine and a platform that secures AI models are all called AI security products, even though they solve very different problems.
- The competitive frontier has moved from answering to acting: The important 2026 distinction is whether AI merely summarizes information or can independently investigate, reason across telemetry and execute actions within governed boundaries.
- Security for AI is becoming as important as AI for security: Enterprises now need protection for AI agents, models, prompts, MCP connections, AI supply chains and autonomous actions in addition to using AI to defend conventional infrastructure.
How we evaluated the top AI cybersecurity companies
This list is not based on which company uses the word AI most often. TBS evaluated the companies across five practical dimensions using publicly documented product capabilities available in 2026.
1. AI depth
Does AI primarily answer analyst questions, or can it investigate, build hypotheses, generate detections, coordinate workflows and take actions? Platforms moving toward agentic security score higher on this dimension than simple conversational assistants.
2. Security data advantage
AI security quality depends on what the model can see. Endpoint telemetry, identity activity, cloud data, threat intelligence, malware analysis and historical incidents provide the context needed for useful security reasoning.
3. Autonomy and guardrails
The ability to act is valuable only when enterprises can control identity, permissions, triggers, approvals and audit trails. A highly autonomous security agent without governance can create as much operational risk as it removes.
4. Platform breadth
We considered how broadly each company’s AI reaches across endpoint, identity, network, cloud, security operations, vulnerability management, data and application security.
5. Security for AI
We also considered whether the vendor can protect AI systems themselves through model scanning, prompt-injection controls, AI asset discovery, agent identity, runtime protection, AI supply-chain security or related capabilities.
1. CrowdStrike: Best for agentic endpoint and XDR security
CrowdStrike has turned Charlotte AI from a conversational security assistant into a broader agentic platform built around the Falcon security ecosystem.
At RSA Conference 2026, CrowdStrike launched the Charlotte AI AgentWorks Ecosystem, allowing organizations and partners to build and orchestrate custom security agents using a no-code development platform and frontier AI models. Launch collaborators included AWS, Anthropic, NVIDIA, OpenAI, Salesforce, Accenture, Deloitte and others. [CrowdStrike Charlotte AI AgentWorks]
CrowdStrike’s 2026 agentic SOC strategy positions AI agents as operating units that can reason across security data and automate tasks such as triage, malware analysis, threat hunting and exposure prioritization while analysts retain control over consequential decisions. [CrowdStrike agentic SOC]
The company’s biggest advantage is context. Falcon already sits close to endpoint, identity, cloud and threat-intelligence data, which gives Charlotte AI a large security dataset to reason over without requiring customers to build a separate AI layer from scratch.
Best for: Large enterprises that want AI embedded deeply into endpoint/XDR-driven security operations and want to build custom security agents around an existing Falcon deployment.
Watch: How quickly customers move from vendor-provided agents to custom AgentWorks deployments, and how much autonomy organizations are willing to give those agents.
2. Palo Alto Networks: Best for autonomous SOC transformation
Palo Alto Networks has one of the broadest AI-security strategies in the market because it attacks the problem from both directions: using AI to run security operations and securing the AI systems enterprises are deploying.
Cortex XSIAM combines SIEM, XDR, SOAR, security analytics and automation around a unified data layer. Cortex AgentiX extends that architecture with agents designed to plan, reason and act within enterprise-defined guardrails. Palo Alto Networks says more than 200 XSIAM customers have enabled AgentiX. [Palo Alto Networks Cortex AgentiX]
The underlying data scale is also notable. Palo Alto Networks says its Cortex Extended Data Lake ingests more than 15 petabytes of telemetry per day across more than 1,100 integrations, giving its agents a broad information layer for investigations and response. [Palo Alto Networks agentic SOC architecture]
Palo Alto Networks also has a stronger AI-for-AI story than many traditional SOC vendors. Prisma AIRS now covers AI model security, AI red teaming, runtime protection, AI posture management and agent security, including controls around agent identities, MCP connections, tool calls and autonomous behavior. [Prisma AIRS Agent Security]
Best for: Enterprises trying to consolidate security operations while also building a dedicated security layer around models and autonomous agents.
Watch: Whether Cortex AgentiX becomes the main orchestration layer for SOC automation and whether Prisma AIRS becomes a standard control plane for the agentic enterprise.
3. Microsoft Security: Best for Microsoft-heavy enterprises
Microsoft’s biggest advantage is distribution. Security Copilot agents are not confined to a separate AI product; they are being embedded across Microsoft Defender, Entra, Intune and Purview, allowing AI to operate across endpoint, identity, device management, data security and security operations.
Microsoft describes Security Copilot agents as systems that can observe, reason and act with administrator oversight. In Intune, specialized agents include vulnerability remediation, policy configuration, change review and device offboarding. Similar agents operate across Defender, Entra and Purview. [Microsoft Security Copilot agents in Intune]
The governance model is particularly important. Security Copilot agents can have their own identities, role-based permissions, triggers and connected plugins, while administrators control which agents can operate and what systems they can access. [Microsoft Security Copilot agent architecture]
Microsoft is also extending Defender toward security for AI agents themselves. Its 2026 Defender capabilities can discover AI agents, inventory their tools and identities, evaluate posture risks and identify conditions such as privileged access or the ability to operate without human approval. [Microsoft Defender AI agent risk]
Best for: Organizations already centered on Microsoft 365, Defender, Entra, Intune, Sentinel and Purview that want agentic security without introducing a completely separate operational ecosystem.
Watch: Whether the scale of Microsoft’s installed base makes Security Copilot agents the default AI-security layer for Microsoft-centric enterprises.
4. SentinelOne: Best for autonomous investigation
SentinelOne is one of the clearest examples of the move from security copilot to autonomous investigator.
In June 2026, SentinelOne opened Purple AI Agentic Investigation broadly to customers. The system can initiate investigations without waiting for an analyst prompt, detect and investigate threats, verify evidence and provide a full evidence chain behind its verdict. [SentinelOne Purple AI Agentic Investigation]
This “zero-click” model is important because it changes when AI enters the security workflow. A copilot waits for an analyst to ask a question. Purple AI can begin investigating the alert independently, which means human time is concentrated later in the process when evidence needs review or a consequential response decision is required.
SentinelOne has also moved into protecting autonomous AI systems. In June 2026, it announced security integration with Amazon Bedrock AgentCore for runtime guardrails around AI agents, extending the Singularity platform beyond conventional endpoint security. [SentinelOne 2026 product releases]
Best for: Security teams that want AI to take on more of the investigation workload without replacing the existing Singularity operational model.
Watch: How much investigation and response can become genuinely zero-click while still producing evidence analysts trust.
5. Google Cloud Security: Best for threat intelligence and agentic SecOps
Google is one of the more interesting companies in this list because its current cybersecurity position is stronger than many generic vendor rankings suggest.
Google Security Operations combines Gemini models with Mandiant frontline intelligence, VirusTotal data and Google’s broader threat visibility. Its agentic SOC includes dedicated agents for triage and investigation, threat hunting and detection engineering. [Google Cloud Agentic SOC]
Google says its Triage and Investigation agent has processed more than 5 million alerts and can reduce a typical 30-minute manual investigation to around 60 seconds. The agent autonomously gathers evidence, enriches alerts with threat intelligence and returns an explained verdict. [Google Cloud Next 2026 security updates]
The acquisition of Wiz, completed in 2026, expands Google’s cloud-security position and strengthens its ability to connect agentic SecOps with cloud and AI application protection. Google is also building protections for agents through Model Armor, agent identities and AI Threat Defense. [Google Security and Wiz at RSA 2026]
Best for: Data-heavy SOCs that value frontline threat intelligence, natural-language investigation and agentic detection engineering, especially in Google Cloud or multicloud environments.
Watch: How quickly Google combines Wiz, Gemini, Mandiant and Google Security Operations into one coherent enterprise security platform.
6. Darktrace: Best for behavioral AI and anomaly detection
Darktrace is different from most companies on this list because machine learning was central to its security architecture long before generative AI became the industry’s dominant narrative.
The Darktrace ActiveAI Security Platform uses Self-Learning AI to establish an understanding of normal behavior inside an organization and detect anomalies across network, email, identity, cloud, endpoint and other environments. The platform combines real-time detection with automated investigation and targeted autonomous response. [Darktrace ActiveAI Security Platform]
This behavioral approach is valuable for detecting unusual activity that does not match an existing signature or known malware family. Instead of asking only whether an event looks like a known attack, Darktrace attempts to identify when behavior deviates meaningfully from the organization’s normal operating baseline.
Darktrace also expanded into security for AI in 2026 with SECURE AI, designed to provide visibility and behavioral control over enterprise AI usage, data access and AI activity. [Darktrace SECURE AI]
Best for: Organizations prioritizing behavioral anomaly detection, novel-threat discovery and autonomous response across complex environments.
Watch: How successfully Darktrace combines its long-standing self-learning architecture with newer generative and agentic security capabilities.
7. Check Point: Best for prevention and securing AI adoption
Check Point’s AI strategy has become broader in 2026. The company is combining AI-powered threat prevention with a dedicated security architecture for the AI systems enterprises themselves are deploying.
Check Point launched its AI Defense Plane in March 2026 as a unified control layer for employee AI use, AI applications and agentic systems. The architecture is designed to govern how AI connects to enterprise data and tools while applying security controls around autonomous activity. [Check Point AI Defense Plane]
Its security stack includes ThreatCloud AI for threat prevention, GenAI protections for workforce use, AI red teaming, AI infrastructure security and controls around prompts, applications and agents. Check Point also announced in June that it was integrating OpenAI frontier cyber models into defensive workflows and product capabilities. [Check Point and OpenAI cyber models]
Check Point’s 2026 AI Security architecture is particularly relevant for organizations worried about AI data leakage, prompt injection, Shadow AI and agent-tool access rather than only SOC automation. [Check Point AI Security]
Best for: Enterprises that favor a prevention-first security model and want controls around employee AI, AI applications and autonomous agents alongside conventional network and workspace security.
Watch: Whether Check Point’s AI Defense Plane becomes a widely adopted governance layer for enterprise AI traffic and autonomous agents.
8. Checkmarx: Best for AI-era application security
Checkmarx is the specialist on this list. It does not compete with CrowdStrike or Palo Alto Networks as a complete enterprise SOC platform. Its strength is securing software development as AI generates more code and development itself becomes increasingly agentic.
Checkmarx One now combines deterministic application-security testing with AI reasoning, automated vulnerability prioritization and AI-assisted remediation. Its agentic architecture covers code, open-source dependencies, infrastructure-as-code, secrets, AI assets and software supply-chain risk. [Checkmarx One]
In 2026, Checkmarx introduced autonomous Triage and Remediation agents, AI Inventory for discovering models, agents and MCP servers, an AI bill of materials, and an MCP server that allows security workflows to run through AI assistants and developer environments. [Checkmarx AI Inventory] [Checkmarx MCP Server]
The company then expanded its Assist agent family with autonomous find-and-fix workflows designed to identify, remediate and verify vulnerabilities as developers write code. [Checkmarx self-healing application security]
Best for: Software-heavy organizations that need AI-driven AppSec, AI code-security controls and visibility into the growing AI software supply chain.
Watch: Whether agentic AppSec becomes a distinct enterprise security category as AI coding agents generate more production software with less direct human review.
Data Insights
By the numbers:
Vendor-reported figures below describe individual platforms and should not be treated as directly comparable benchmarks. Deployment environments, telemetry, workflows and definitions differ substantially.
- More than 200 XSIAM customers have enabled Cortex AgentiX: Palo Alto Networks reports growing customer adoption of its agentic layer as it moves XSIAM toward autonomous security operations. [Palo Alto Networks AgentiX]
- Palo Alto Networks says its Cortex data layer ingests more than 15 PB of telemetry daily: The company reports more than 1,100 integrations feeding the AI-ready Cortex Extended Data Lake. [Cortex agentic SOC]
- Google says its Triage and Investigation agent processed more than 5 million alerts: The company reports that Gemini reduced a representative 30-minute manual analysis to around 60 seconds in its SecOps workflow. [Google Cloud Next 2026]
- CrowdStrike opened AgentWorks to an ecosystem that includes major frontier-model and enterprise partners: Its 2026 launch included OpenAI, Anthropic, AWS, NVIDIA, Salesforce and consulting partners, showing that custom security agents are becoming a platform category rather than one closed product feature.
- SentinelOne moved agentic investigation from analyst-triggered to autonomously initiated: Purple AI Agentic Investigation can begin without a human prompt and produce an evidence chain behind its verdict, making it one of the clearest examples of zero-click investigation in a mainstream security platform.
Table 1: Top AI cybersecurity companies in 2026
| Company | Main AI platform | AI model | Strongest area | Best for |
| CrowdStrike | Charlotte AI + AgentWorks | Agentic | Endpoint/XDR-driven SecOps | Large Falcon customers and custom security agents |
| Palo Alto Networks | Cortex XSIAM + AgentiX + Prisma AIRS | Agentic / autonomous | Broad SOC transformation and AI security | Platform consolidation and autonomous operations |
| Microsoft Security | Security Copilot | Agentic | Identity, endpoint, data and Microsoft security workflows | Microsoft-heavy enterprises |
| SentinelOne | Purple AI | Agentic / autonomous investigation | Threat investigation | Teams wanting machine-led investigations |
| Google Cloud Security | Gemini + Google Security Operations | Agentic | Threat intelligence and SecOps | Data-heavy and intelligence-driven SOCs |
| Darktrace | ActiveAI Security Platform | Behavioral / autonomous | Anomaly detection and response | Novel-threat and behavior-based defense |
| Check Point | ThreatCloud AI + AI Defense Plane | AI-assisted / preventive | Threat prevention and AI security | Prevention-focused enterprises |
| Checkmarx | Checkmarx One | Specialized agentic AppSec | Application and AI supply-chain security | Software development organizations |
Table 2: Best AI cybersecurity company by use case
| Use case | TBS pick | Why | Alternative |
| Endpoint and XDR | CrowdStrike | Charlotte AI operates directly across Falcon security context and now supports custom agent creation | SentinelOne |
| Autonomous SOC transformation | Palo Alto Networks | XSIAM combines unified security data, automation and AgentiX agents in one SOC architecture | Google Cloud Security |
| Microsoft environment | Microsoft Security | Security Copilot agents operate across Defender, Entra, Intune and Purview | CrowdStrike |
| Autonomous threat investigation | SentinelOne | Purple AI can initiate zero-click investigations and produce an evidence chain | Google Cloud Security |
| Threat intelligence | Google Cloud Security | Combines Gemini with Mandiant, VirusTotal and Google-scale threat intelligence | CrowdStrike |
| Behavioral anomaly detection | Darktrace | Self-Learning AI builds organization-specific behavioral baselines instead of relying only on known threat signatures | SentinelOne |
| Securing AI agents and models | Palo Alto Networks | Prisma AIRS covers agent identity, runtime protection, AI model security, red teaming and AI gateway controls | Check Point |
| AI-use governance and prevention | Check Point | AI Defense Plane covers workforce AI, applications, agents and AI-specific prevention controls | Darktrace |
| Application security | Checkmarx | Specialized agents cover AI-generated code, vulnerability triage, remediation and AI software supply-chain visibility | Palo Alto Networks |
The Business Case: How to choose an AI cybersecurity company
The wrong starting point is asking which vendor has the most advanced AI model. Security teams should start with the workflow they need to improve.
If alert investigation is the bottleneck, look at how the platform correlates evidence, explains verdicts and hands uncertain cases back to analysts. If vulnerability backlogs are the problem, examine prioritization and remediation rather than conversational search. If autonomous agents are entering the enterprise, prioritize identity, permissions, runtime enforcement and AI asset visibility.
The second question is where the security data already lives. AI is only as useful as the context available to it. Organizations heavily invested in Falcon, Microsoft Defender, Cortex, Google SecOps or Singularity may gain more from AI embedded into that existing data layer than from introducing another independent assistant.
The third question is how much autonomy the organization actually wants. A system that summarizes an incident creates relatively little operational risk. A system that can disable accounts, isolate hosts, modify policies or trigger remediation requires far more careful identity, approval and rollback design.
The fourth question is whether the company needs AI for cybersecurity, cybersecurity for AI, or both. A SOC platform may be excellent at investigating attacks but weak at protecting models and agents. Conversely, a specialist AI-security product may secure prompt flows and agent permissions without replacing an XDR or SIEM.
As covered in our AI applications in cybersecurity 2026 analysis, the value of AI increasingly comes from shortening the complete defensive loop—from detection through investigation to remediation—rather than generating another layer of alerts.
Do not compare AI security pricing by license alone
Enterprise AI-security pricing is increasingly tied to data ingestion, platform modules, endpoint counts, AI credits, model usage or security compute rather than one simple seat price.
A cheaper AI assistant can become expensive if it requires duplicating telemetry or moving security data into another platform. An apparently expensive integrated platform can become economically attractive if it replaces multiple SIEM, SOAR, investigation or point-security tools.
Buyers should therefore compare total security workflow cost: data ingestion, analyst hours, investigation time, infrastructure, AI usage, existing platform commitments and the number of tools the deployment can realistically consolidate.
Expert Nuance: The best AI model may not create the best security platform
AI cybersecurity is becoming a data-and-control problem as much as a model problem.
A frontier model may be excellent at reasoning, but a security agent cannot investigate an incident well if it lacks endpoint telemetry, identity context, cloud events, threat intelligence or historical data. The value therefore comes from the combination of model intelligence and security context.
This explains why established cybersecurity companies have an advantage even when they do not build their own frontier models. CrowdStrike can connect AI to Falcon data. Google can combine Gemini with Mandiant and VirusTotal. Microsoft connects models to Defender and Entra. Palo Alto Networks feeds AgentiX through the Cortex data layer.
The second advantage is control. Once AI is allowed to act, identity and authorization matter more than conversational quality. The enterprise needs to know which agent acted, what permissions it had, which evidence justified the action and how the decision can be reversed.
That is why the market is moving from generic security copilots toward agentic security platforms with identities, policies and audit trails.
As covered in our analysis of whether AI will replace cybersecurity jobs, more automation does not remove the need for human security judgment. It moves analyst value toward validating AI conclusions, supervising autonomous workflows and remaining accountable for high-impact decisions.
Strategic Outlook
- Watch copilots disappear into the platform: Conversational AI will become a standard interface rather than a standalone differentiator. The competitive edge will move toward what the AI can investigate and execute behind the interface.
- Watch autonomous investigation become standard: SentinelOne, Google, CrowdStrike and Palo Alto Networks are already moving toward machine-initiated or machine-led investigations. Basic alert summarization will increasingly become table stakes.
- Watch custom security agents become a platform battle: CrowdStrike AgentWorks, Microsoft custom agents, Google MCP-based security agents and other ecosystems are turning security automation into a programmable agent layer.
- Watch security for AI become a buying requirement: Prisma AIRS, Check Point AI Defense Plane, Darktrace SECURE AI, Microsoft Defender agent posture and Checkmarx AI Inventory show established vendors racing to secure the new AI attack surface.
- Watch threat intelligence become the grounding layer: The more autonomous agents become, the more important high-quality security context becomes. CrowdStrike intelligence, Mandiant, Unit 42, Microsoft threat data and other proprietary security datasets become part of the AI moat.
- Watch consolidation pressure increase: Enterprises are unlikely to want separate copilots for every security product. Vendors that can connect AI across endpoint, identity, cloud, SOC and AI security will have an advantage over isolated assistants.
Key Question Answered
What are the top AI cybersecurity companies in 2026?
The top AI cybersecurity companies in 2026 include CrowdStrike, Palo Alto Networks, Microsoft Security, SentinelOne, Google Cloud Security, Darktrace, Check Point and Checkmarx. They lead different parts of the market rather than competing as identical products.
CrowdStrike is particularly strong in endpoint/XDR-driven agentic security. Palo Alto Networks has one of the broadest autonomous SOC and AI-security strategies. Microsoft is strongest inside Microsoft-heavy enterprises. SentinelOne stands out for autonomous investigation, Google for threat intelligence and agentic SecOps, Darktrace for behavioral AI, Check Point for prevention and enterprise AI protection, and Checkmarx for AI-era application security.
The best choice therefore depends on where the organization’s telemetry already lives, which security workflow needs automation, how much autonomy the company is prepared to allow and whether the requirement is AI-powered defense, securing AI systems, or both.
FAQ
1. Which company is best for AI cybersecurity?
There is no universal best AI cybersecurity company. CrowdStrike is a strong choice for endpoint and XDR environments, Palo Alto Networks for broad autonomous SOC transformation, Microsoft for Microsoft-centric enterprises, SentinelOne for autonomous investigations, Google for threat-intelligence-driven SecOps, and Darktrace for behavioral anomaly detection.
2. Is CrowdStrike or Palo Alto Networks better for AI security?
CrowdStrike is particularly strong when Falcon endpoint, identity and threat context form the center of security operations. Palo Alto Networks is stronger when the goal is broader SOC consolidation through XSIAM and AgentiX or when the organization also needs dedicated AI model and agent security through Prisma AIRS.
3. Which AI cybersecurity company is best for Microsoft environments?
Microsoft Security is the most natural fit for organizations already using Defender, Entra, Intune, Sentinel and Purview because Security Copilot agents are embedded directly into those workflows and can use Microsoft security context without requiring a separate operational layer.
4. Which company is best for securing AI agents?
Palo Alto Networks has one of the broadest dedicated agent-security offerings through Prisma AIRS, covering agent identity, runtime activity, tool calls, MCP connections and AI red teaming. Check Point, Microsoft, Darktrace and Checkmarx also introduced important AI-agent security capabilities in 2026.
5. Which AI cybersecurity company is best for application security?
Checkmarx is the specialist choice in this comparison for application security. Checkmarx One combines deterministic scanning, AI reasoning, autonomous vulnerability triage and remediation with visibility into AI models, agents, MCP servers and software supply-chain components.
6. Are AI cybersecurity companies replacing human analysts?
AI security platforms are automating more alert triage, investigation, threat hunting and remediation work, but human analysts remain important for validating evidence, supervising autonomous actions, understanding business context and accepting responsibility for consequential decisions.
The Takeaway
The AI cybersecurity market in 2026 has moved beyond the copilot era.
CrowdStrike, Palo Alto Networks, Microsoft, SentinelOne and Google are competing to define the agentic SOC, where AI performs more of the investigation and orchestration work that analysts once handled manually.
Darktrace remains differentiated by behavioral AI and autonomous anomaly response. Check Point is building a broader prevention and AI-protection architecture. Checkmarx is applying agentic AI directly to the software-development security problem.
The most important buying distinction is therefore not which vendor claims to have the smartest AI. It is what security context that AI can access, which workflows it can actually improve, which actions it is allowed to take and whether the platform can prove why those actions were justified.
The strongest AI cybersecurity platforms will increasingly look less like chatbots and more like governed digital security teams: systems that investigate continuously, act inside defined boundaries, secure other AI agents and escalate the decisions where human judgment still matters most.