Precisely. If we want to keep our systems safe, we need not an extra AI, but strict adherence to well-established practices. Vulnerability in networks comes from lackluster execution of well-known, well-documented security measures.
Leave AI as an extra level of pentesting, it already does such things brilliantly.