Every workforce plan written in the last two years has an AI section. Most of them describe hiring machine learning engineers.
The labour data does not support that as the main event, and the gap between the plan and the data is where budgets get wasted.
Two numbers that point in different directions
From the World Economic Forum's Future of Jobs Report 2025: 86 percent of employers expect AI and information processing technologies to transform their business by 2030, and AI and big data sits at the top of the ranking of fastest-growing skills to 2030. Networks and cybersecurity is second.
From the US Bureau of Labor Statistics: employment of information security analysts is projected to grow 29 percent between 2024 and 2034, much faster than the average for all occupations.
The first number is about expectation. The second is a projection of actual employment in an actual occupation, and it is the one attached to a specific job title.
Employers expect AI to change everything. The role the labour projections show growing fastest in that domain is the one that secures it.
That is not a contradiction. It is a description of how technology adoption creates employment, which is rarely where the excitement is.
Why security is where the demand actually lands
The mechanism is straightforward once stated.
Adopting AI means moving more data into more systems, connecting more things to each other, exposing more interfaces, and depending on more external providers. Every one of those expands the attack surface.
Add the specific problems the technology introduces. Models trained on data that must not leak. Systems that can be manipulated through their inputs. Outputs that look authoritative and can be wrong. Supply chains of models and components whose provenance is hard to verify.
And add the organisational reality: AI adoption pushes capability into the hands of people across the business who are not security-trained, at speed, often through tools procured outside IT.
So a wave of AI adoption produces a wave of security work, and the security work is measurable in headcount in a way that the AI work often is not.
For a workforce plan, the implication is uncomfortable but useful: if an organisation is resourcing an AI program without proportionately resourcing security, it is building the thing and not the thing that keeps it safe.
The three layers of AI capability an organisation needs
Most plans conflate these, and they have completely different headcounts, skill profiles and training routes.
| Layer | What they do | Headcount needed |
|---|---|---|
| Building | Develop and train models, research | Very few, and only in some organisations |
| Applying and integrating | Deploy, integrate, operate, monitor, secure | Substantial |
| Using and evaluating | Work with the systems, judge output quality, know the limits | Very large, approaching everyone |
The first row is where the recruitment attention goes and it is the smallest. Most organisations do not need to train models. They need to use models built by others, safely and correctly.
The second row is real engineering and it is not the same as the first. Deploying a system, monitoring whether it degrades, handling failure modes, managing cost, and securing it are infrastructure and operations skills rather than research skills.
The third row is the largest and the least addressed.
The layer almost nobody staffs
Evaluation deserves a section of its own, because it is the capability whose absence causes the most damage and it appears in almost no workforce plan.
These systems produce fluent, confident output that is sometimes wrong. The wrongness is not signposted. It looks exactly like the correct output.
Which means the value of the system depends entirely on someone being able to tell the difference, and that someone has to understand the domain, not the model.
A model that drafts a maintenance procedure is useful if a competent engineer checks it and dangerous if nobody does. A system summarising clinical literature is useful to someone who could have read the literature. The judgement is the safety mechanism, and the judgement lives in domain expertise.
This produces the most important staffing conclusion in this article.
A domain expert with good AI literacy is usually more valuable than an AI specialist with no domain knowledge. The domain expert can tell when the answer is wrong. The specialist cannot, and will ship it.
Which reframes the training question. Instead of hiring scarce, expensive machine learning specialists, train the metallurgist, the process engineer, the clinician and the analyst you already employ to work with these systems competently and sceptically. That population is large, already employed, and holds the thing that cannot be trained quickly.
The AI, data and computing domain
Astra Trainer's first domain runs eight directions: computer science, software engineering, artificial intelligence and machine learning, data science and analytics, cybersecurity, cloud computing and DevOps, IT systems and computer networks, and blockchain and distributed systems.
Cybersecurity and cloud sit alongside the AI direction deliberately, because the layers above are what an organisation actually has to staff together. Tracks run from fundamentals to applied work, so the same catalog serves a domain specialist acquiring literacy and an engineer moving into security. You can see the eight directions here.
Who can be trained into this, and who cannot
Into security, which is the acute shortage. Network and systems administrators are the shortest path and the most obvious, since they already understand the infrastructure being defended. Software engineers move into application security readily. Compliance, audit and risk professionals bring the governance half and need the technical half. Help desk and support staff, frequently overlooked, know the estate and the users and how things actually break, which is a genuine advantage.
Into the applying and integrating layer. Software engineers and data engineers are close. So are infrastructure and operations people, because much of running an AI system in production is an operations problem wearing new vocabulary.
Into the using and evaluating layer. Almost any domain expert, and this is the highest-return training in most organisations because the population is large and the distance is short. What they need is not model architecture. It is knowing what these systems do, where they fail, how to interrogate an output, what not to put into them, and when to escalate.
Into building. Realistically, people with a strong quantitative background, and it is a long route. For most organisations this is the wrong thing to be doing.
On security certification and on AI-specific risk. Many security roles carry recognised certifications and some sectors require specific credentials. Training builds the capability and prepares people for those pathways rather than replacing them. Separately, an AI literacy program that teaches people to use these tools without teaching what must not be put into them, and what cannot be relied on coming out, has made the organisation's risk profile worse rather than better. The limits belong in the first lesson, not an appendix.
Why AI training goes stale faster than anything else
A practical problem specific to this domain.
Tools, interfaces and capabilities change on a timescale of months. Training built around a particular product is out of date quickly, and a program designed as a one-off event will be teaching something obsolete within a year.
Two design responses.
Teach the durable layer. What these systems fundamentally are, why they fail in the ways they do, what the data and privacy implications are, how to evaluate an output. That survives a product cycle. The button locations do not.
Make it continuous rather than an event. This is the domain where ongoing short-form learning genuinely outperforms a course, because the field moves faster than course revision cycles. A workforce doing a few minutes daily stays roughly current. A workforce that did a two-day course in 2025 does not.
The same applies with even more force to security, where the threat landscape is adversarial and changes continuously by design.
What to take from this
Employers expect AI to transform their business, and the occupation the projections show growing fastest in this domain is information security analyst at 29 percent.
Separate the three layers. Almost nobody needs to build models. Everybody needs people who can apply, integrate, secure and evaluate them.
Evaluation is the least staffed and most consequential layer, and it requires domain knowledge rather than model knowledge.
Train the domain experts you already employ. A metallurgist with AI literacy beats an AI specialist with no metallurgy, because only one of them can tell when the answer is wrong.
And build the program around the durable layer and run it continuously, because anything taught around a specific tool has a shelf life measured in months.
What is the biggest AI skills gap?
In labour projections, security. Information security analyst employment is projected to grow 29 percent from 2024 to 2034. AI adoption expands the attack surface faster than organisations staff for it.
Do we need to hire machine learning engineers?
Most organisations need very few people who build models and a great many who can apply, integrate, secure and evaluate systems built by others. Plans that resource the first and skip the others are the common failure.
Who is best placed to move into cybersecurity?
Network and systems administrators are the shortest path, followed by software engineers into application security and compliance or audit professionals who need the technical half. Support staff are frequently overlooked and know the estate well.
Should we train domain experts in AI, or hire AI specialists?
For the evaluation layer, train the domain experts. Telling whether an output is wrong requires knowing the field, and the fluency of these systems means an unqualified reviewer will pass errors through.
How do we keep AI training current?
Teach the durable layer rather than a product interface, and run it continuously rather than as an event. Astra Trainer's AI, data and computing domain covers eight directions including cybersecurity and cloud, and you can see them here.
