This is something that I worry about as well for my junior incident responders at my company.
We have a culture that I’ve pushed to always understand what the model is doing, even if you have to go back after the response action is done and walk through it step by step.
I encourage everyone to use AI to the extent that they feel comfortable and can do their jobs but I feel it’s necessary to always be able to do what the LLM has done if you don’t have access to it