Four years in the AI trenches: a practitioner's honest field notes from 2022 to 2026
Martin Leung traces AI in his security work from early hallucinated CVEs to agentic tools, ending with five questions senior leaders should ask their teams.
Session Details
Four years ago, ChatGPT changed how many of us thought about our jobs.
Four years in, the dust has settled enough to tell an honest story.
This session is a personal field-notes walkthrough of one security practitioner's AI adoption journey from late 2022 to today: the experiments, the productivity wins, the embarrassing failures, and the strategic observations that matter more than any product demo. It is not a vendor pitch, not a tool showcase, and not a compliance lecture. It is what a hands-on operator wishes someone had told him in 2023.
We walk through four distinct eras.
2022 to 2023: the parlour-trick era.​ Everyone experimented on toy problems. What worked (narrative writing, first-draft summaries). What embarrassingly did not (hallucinated CVEs, fabricated config syntax). The honest takeaway on reliability and where the early wins actually lived.
2024: the plumbing era.​ AI stopped being a chat box and started becoming workflow. The bottleneck moved from the model to your data hygiene. What broke when we tried to automate real ops work, and why accountability became the hardest problem to solve.
2025: the compounding era.​ Agentic tools, persistent context and orchestrated workflows changed the job itself. The gap between AI-native and AI-hesitant practitioners widened fast. What structured, high-volume work finally became viable, and what still absolutely cannot be delegated.
2026: the reckoning.​ AI fatigue arrives. Vendor noise becomes overwhelming. Real return on investment separates from theatre. Data sovereignty, leakage and over-automation blowback emerge as the genuine risks. The practitioners who thrive are the ones who have learned what not to automate.
The session closes with five plain-English questions every senior leader should be asking their security and IT teams right now: questions that cut through vendor noise and surface whether their AI adoption is actually defensible, or whether they are just buying expensive autocomplete.
Attendees will leave with a grounded mental model for assessing AI claims, a realistic picture of what AI-assisted SecOps actually looks like in 2026, and a short list of practical questions to ask their own teams on Monday morning. There are no live demos, no vendor logos, no client names, and no tool endorsements, just a candid account from someone who has spent four years doing the work, and who is willing to say out loud what most practitioners only discuss privately.
There's More Where This Came From
Browse hundreds of sessions and build an agenda around the topics that matter to you.








