The finding was never the valuable part. Closing the loop is.

A huge share of knowledge work is diagnosis without cure: an audit, an assessment, a list of findings handed to someone else who may or may not act on it. Closed-loop AI agents, which detect a problem and then fix it in the same motion, do not just automate the diagnosis. They collapse the gap between knowing and doing, and that gap is where a whole category of work has been quietly living. The report was always a failure mode we agreed to call a deliverable.

Consider the most normal thing in the world of professional work: someone gets paid to find problems and write them down. The security audit. The code review. The consultant's assessment. The compliance finding. The monitoring alert. In each case, an expert examines a system, identifies what is wrong, produces a document or a ticket, and hands it to someone else, whose job is to maybe do something about it. We call these things deliverables. We have never quite admitted that a finding nobody acts on is worth nothing at all.

On July 27, Microsoft shipped something that makes that uncomfortable fact impossible to ignore. It is called Project Perception, and it coordinates three kinds of security agents in a continuous loop: red agents that hunt for ways in, blue agents that investigate and decide what actually matters, and green agents that go fix it. The point is not that any one of those steps is new. The point is that they are wired together with no human hand-off between finding and fix. A vulnerability gets discovered, triaged, and remediated as one continuous motion, not three departments and a backlog.

Read that as a security story and you will miss it. The real signal is what happens to the deliverable in the middle. Perception's own designers put it plainly: the goal is that a finding becomes a fix without a hand-off at every step. That sentence is quiet, and it is the whole thing.

The finding was never the bottleneck. The hand-off was.

Here is the fact the security industry has spent a decade politely not saying out loud. We got very good at finding problems and stayed terrible at fixing them.

The numbers are brutal and specific. By Edgescan's accounting, roughly 45 percent of enterprise vulnerabilities are never fixed at all. Verizon's 2026 breach report found that only 26 percent of known, actively exploited vulnerabilities were fully remediated, down from 38 percent the year before. Read those two numbers together and the picture is undeniable: the constraint was never detection. Companies are drowning in findings. What they cannot do is close them.

So all the effort the industry poured into finding things faster, better scanners, more sensors, sharper detection, was pouring water into a bucket with no bottom. Every new finding that does not become a fix is not an asset. It is a liability with a timestamp, a documented weakness now sitting in a backlog where an attacker can reach it before the next sprint planning meeting does.

And the flood is rising. AI now writes a large share of enterprise code, and by Veracode’s testing that code carries 2.74 times more vulnerabilities than human-written code. So the same wave of AI that is supposed to help is also generating findings faster than any human hand-off could ever clear them. Detection was never going to save a system that cannot close what it finds. If anything, more detection now makes the gap worse.

This is the thing closed-loop agents actually attack. Not the finding. The gap after it. And that gap is not empty space. It is full of work, and full of people whose job is to carry a problem from the person who spotted it to the person who might fix it.

Diagnosis without cure is a bigger category than it looks

Once you see this shape, you see it everywhere, and that is what makes this more than a security story.

An enormous amount of what gets sold as knowledge work is diagnosis that stops short of cure. The consulting deck that names the problem and leaves the doing to the client. The audit that produces findings and moves on. The analytics dashboard that surfaces an anomaly and waits for a human to care. The QA process that files the bug. The monitoring tool that fires the alert. In every one of these, the valuable-seeming artifact, the report, the deck, the ticket, the alert, is actually just a hand-off dressed up as an output. Its entire purpose is to move a problem across a gap to someone else.

For decades that hand-off was unavoidable, because the finding and the fix required different skills, different systems, different people, and there was no way to connect them except a document and a meeting. So we built professions, whole industries, in the gap. We normalized diagnosis-without-cure as a legitimate category of paid work, because the alternative did not exist.

Closed-loop agents are the alternative existing. When the same system that spots the problem can also enact the fix, the document in the middle stops being a deliverable and becomes friction. Nobody needs the finding written down if the finding is already being fixed. This is the quiet threat closed-loop AI agents pose, and it is not to the people who do the fixing. It is to the work that lived in the gap, the translating, the ticketing, the routing, the chasing, which does not get automated so much as it stops having a reason to exist.

The move already has a precedent, and it already won

If this sounds like a radical prediction, it is actually a rerun of something software already did to itself, on purpose, and never looked back.

Not long ago, building software and running it were two separate worlds with a wall between them. Developers wrote code and threw it over that wall to an operations team, along with, yes, documents: release notes, runbooks, tickets. The hand-off was where everything broke. Things got lost, blamed, delayed. Then the industry did something structural. It tore down the wall and wired the two sides into one continuous loop, code flowing to production and signals flowing back, with automation closing the gap that humans used to bridge by hand. We called it DevOps, and continuous integration, and it did not make the hand-off more efficient. It abolished the hand-off as a step. The role whose job was to carry work across the wall did not get a better tool. It got absorbed into the loop.

Project Perception is that same move, aimed at security. A finding that ends in a pull request is worth more than a finding that ends in a report, because one changes the system and the other changes a document. And what DevOps proved is that once you can close the loop, the version of the work that produced documents for humans to act on does not survive the comparison. It is simply worse, and it goes away.

And this is not one company’s bet. The whole security industry is converging on the same idea, under a name that is quietly telling: agentic remediation. Vendors from BigID to Legit Security to Endor Labs are all racing to ship agents that do not stop at flagging a vulnerability but generate the fix, open the pull request, and confirm it worked. When Microsoft, a pack of startups, and the analysts covering them all independently arrive at “the finding has to become the fix,” that is not a product launch. It is a direction the whole field has decided to walk.

What I'd actually do about it

If your work, or your team's work, or your product, produces findings that someone else is supposed to act on, the strategic question is no longer how to make better findings. It is how to close your own loop before someone closes it for you.

Concretely. Look hard at anything you ship that is a diagnosis handed off for someone else to cure, a report, a recommendation, an alert, a ticket, and ask what it would take to make it end in an action instead of a document. If you build products, the ones that will command a premium are the ones that do not stop at telling the customer what is wrong, they fix it, or tee up the fix so completely that approving it is one click. If you sell expertise, the version of it that survives is the version wired to act, not the version that produces a deck and wishes the client luck. And be honest about which parts of your own operation exist only to move a finding from one desk to another, because those are the parts the loop comes for first.

None of this means findings stop mattering. It means the finding, on its own, stops being something anyone will pay for.

The honest objection

The strongest pushback is that closing the loop is exactly where this gets dangerous, and it is right. A wrong finding that ends in a report wastes an afternoon. A wrong finding that ends in an automated fix can take down production, and a system that acts at machine speed can be wrong at machine speed. The hand-off we are so quick to call waste was also a checkpoint. A human in the gap was, sometimes, the thing that caught the mistake before it shipped. Microsoft itself keeps a person in the loop with Perception, and that is not a courtesy, it is load-bearing.

That caveat is real, and it bounds how fast this happens, but it does not reverse the direction. The lesson of DevOps was not that you remove the human from the loop. It was that you move the human from doing the hand-off to governing the loop, from carrying findings across the gap to setting the rules for what the loop is allowed to do on its own. The oversight does not disappear. The clerical middle does.

So I will concede what I cannot prove. Some of these loops will prove too risky to close all the way, and in those domains the human-reviewed finding survives longer than I would guess, because being wrong slowly is safer than being wrong fast. But the direction is set, and the expensive mistake is to keep investing in being the best in the world at producing a document whose entire job was to be handed to someone else. That document was never the deliverable. Closing the loop was. We just could not do it before, so we sold the next best thing and called it the work.

‍

Gino Ferrand is the founder and CEO of Tecla, which builds and operates AI systems for U.S. companies and staffs the senior engineering teams behind them, across the U.S. and Latin America. He writes Founder's View, a weekly operator's take on the AI news that actually changes how technology companies build. This piece began as an issue of his newsletter, Redeployed. Talent is everywhere; opportunity is not.

‍

Gino Ferrand
By 
Gino Ferrand
Gino Ferrand
Gino is an expert in global recruitment having spent the last 10 years leading Tecla and helping world-class tech companies in the U.S. hire top talent in Latin America.
Categories
AI Production Insights
Insights
Reviews
Recruiting
Case Studies
LATAM Reports
Management
Mobile Hero Image
Combine AI speed with LatAm engineering talent.
Software Developer
See how much you'll save with AI-enhanced nearshore teams
Calculate my Savings
Go to Top

Hire the best AI-driven tech talent with Tecla

Premium, vetted, time-zone aligned.

Checkmark
Checkmark
Checkmark
By submitting, you are agreeing to our Privacy Policy and Terms of Service
Thank you!
Someone from our team will be in touch within 24 business hours.
Something went wrong while submitting, please try again
x
X

Tell us where you're stuck

Checkmark
Checkmark
-
No commitment. We'll follow up within 1 business day.
By submitting, you are agreeing to our Privacy Policy and Terms of Service
Thank you!
Someone from our team will be in touch within 1 business day.
Something went wrong while submitting, please try again
X