Header Logo
Log In
← Back to all posts

Volume 145

Aug 03, 2026

Volume 145 | May 19, 2026

Reminder to JOIN the The PhySec Collective community Slack channel to network, engage, and be part of something big! You can sign up here.


Sometimes, my Briefs focus on what I'm currently thinking about rather than offering deep dives and this is one of those times (they are also sometimes the Briefs that get the most engagement).

Right now, four main topics are on my mind (amongst other things, like: audio in security and badges have more in common than they think, access as infrastructure, platform vs platforming, secondary effects of big tech in security, how product distribution was a feature but now its a bug, can security scale, why we don’t just promote hybrid, ambient access, why Ring went viral but smart locks didn’t and won’t, etc). I’ve thought through two (to a point), which I’ll focus on here. The other two are still just ideas for discussion, so I’ll quickly mention those first.

The first is JCI's sale of its security business units. I’d love to hear how it is going from the inside out. Because from what I am hearing from convos outside in (I’ve had 4 and counting) its a bit train-wrecky and there is a need for someone on the comms side to get involved (along with the bankers and lawyers). This type of thing makes it really tough for the team executing on a daily basis and the quicker its resolved, the better for everyone involved.

The second is related but broader and focused on our inability as an industry to support external R&D. Companies like JCI, Honeywell, Genetec, Motorola, Allegion, and ASSA ABLOY should invest much more in smaller R&D companies. dormakaba and HID recently have and JCI did in the past but what I am saying is different. Others compete with, or ignore, young firms. The math on internal innovation is getting worse. The math on minority investments, partnerships, and acquisitions of small teams is better. Pretending smaller companies are not 'eating the future' does not stop it. (And since more or less no seed and Series A VCs exist in our space, its an opportunity). I plan to dig into these more in future Briefs.

Now to the two things I actually want to spend time on:

What Cursor is doing to software, and what that means for us (maybe)

Something is happening in enterprise software, and I do not think (most of) our industry has grasped its meaning. Brief background on Cursorbefore I jump into it. Cursor is a code editor built on AI. There is news of a recent deal: SpaceX is either acquiring Cursor for $60 billion later this year or paying $10 billion for a partnership. A small team using Cursor can now ship software that previously required a 50-person engineering group two years ago. Configuration, setup, integration, scaffolding, and testing loops once took months of senior engineering hours. Now, AI agents do it with a developer in real time. You describe what you want, and the agent builds it, flags problems, and iterates. The human guides, decides, and ships.

The economic unit of software production has fundamentally changed. Not incrementally…fundamentally.

I think this really matters to our industry. It is not just about building software faster and cheaper, although that is true. The complexity barrier that needed large, specialized teams has dropped. The friction that justified the headcount is being removed. When friction goes away in one part of an industry, everything downstream reorganizes around the new reality.

The same force transforming software engineering is affecting access control configuration, as an example. After installation on a 24-door law firm system, everything starts from scratch: building access groups and assigning profiles to partners, associates, staff, and IT for the server room. Schedules, lockdown profiles, elevator integration, audit trail reporting, and HR connections all need to be set up, including deactivating credentials after termination. A good integrator and technician complete this over 2 to 4 onsite days, followed by inevitable remote support sessions for client changes.

That labor is what AI is coming for. Not eventually. Soon. Like now.

The honest range of displacement (my numbers), depending on the deployment type and complexity, is somewhere between 60 and 90% of current post-install configuration hours for standard commercial deployments. The configuration labor currently at the integrator level will be substantially automated. Is it not? The components exist today. The first generation of true configuration agents for standard deployment types is 12 to 24 months away. Maybe sooner?

This has secondary effects. IT managed service providers have long circled around physical access control, kept out by hardware, configuration access, and complexity. AI-native configuration removes that friction. Now, the MSP or enterprise software SI managing a customer’s network, endpoints, automation, and identity can easily add physical access, without hiring a traditional Security Integrator. This creates a real competitive problem that is coming faster than most Security Integrators expect.

The Security Integrator who will struggle is the one whose profit lies in post-install programming. The ones who have and will build real businesses know configuration was/is never the point. The customer relationship was/is the point, and they have it. Advisory work, managed services, monitoring, policy consulting, annual reviews, and system expansion…these are where future integrator revenue will grow.

For manufacturers and software companies, the first platform to ship AI-native configuration will have a time-to-value advantage. It will be easier to sell and expand, and harder to remove. Companies that don't invest here will find themselves at a product disadvantage within a few years.

If AI agents handle configuration, cloud platforms manage infrastructure, and open standards ensure interoperability, the barrier for building a physical access control software company is at an all-time low. Two experts with the right platform could build a vertical-specific business without a large team…just by understanding the customer, building the right software, and letting agents handle setup. Of course, market entry and execution takes significant work, but is software still the bottleneck? I don’t think so (and we under appreciate virality and momentum).

The two-person access control software company is not a thought experiment. It is a business plan waiting for the right founders to pick it up and a truckload of capital to be shoveled into it.

I’m pretty sure I’ll be on the right side of history on this one. You?


What it tells us about our actual buyer

I mentioned a bit about the Gallup report, called State of the Global Workplace 2026, which was published recently. Every year, it is a must-read for me (I’ve written 2 prior Briefs on this report in 2024 and 2025). In it, you will find that global employee engagement dropped to 20% in the 2026 report, the 2nd consecutive annual decline and the lowest since 2020. Every region declined or held flat. Not 1 region improved. This is the first time in the survey's history that engagement has declined for 2 years in a row.

The deeper finding is the manager crisis (and being a manager-led industry, it pays to listen to the report). Manager engagement collapsed from 30% in the 2024 report, to 27% in the 2025 report, to 22% in the 2026 report. 9 points in 3 years. Gallup says directly that lower manager engagement accounts for most of the overall decline, and that AI is accelerating it. Organizations cutting management layers to deploy AI are increasing team sizes, and larger spans of control directly reduce manager engagement.

Here is why I care, and I think you should too. The people buying, specifying, and managing physical security systems are the same managers Gallup is describing. A 22% engaged manager carrying a larger team span, facing AI disruption, more stress and loneliness, and operating in a “no hire, no fire” job climate, is not enthusiastic about a complex, friction-heavy access control deployment. That manager wants less friction, not more configuration.

Three things stand out.

First, the AI adoption finding is directly relevant to how we sell. Gallup found that employees whose managers actively champion AI are nearly 9 times more likely to say AI has transformed how work gets done. The same dynamic applies to physical security. An access control platform that requires a disengaged, overloaded manager to champion it internally will fail deployment after deployment. The industry’s obsession with features assumes an engaged buyer. The data says most buyers are not engaged.

16% of the workforce is actively disengaged, which raises insider threat risks. Security focused solely on perimeter defense are insufficient for this reality.

Managers carry more emotional weight than their teams. Security that adds complexity increase stress; those that lighten the load are more likely to succeed.

Where these two land together

Both of these threads point to the same place. The Cursor parallel says the friction inside the integrator and the manufacturer is about to be removed (I really believe this). The Gallup data says the friction inside the buyer was already too high. There is a real opportunity to meet the needs of a stressed, time-constrained, disengaged manager with a system that is easy to deploy, operate, and live with.

Less complexity + less labor + less burden on a buyer who is already carrying too much = a design brief or product brief along with the go-to-market brief.


 

Click on the above image and use code sxst3gkbkn to hear the audio version.


PS: I am sure some of you may forward this, but please do so sparingly and encourage others to sign up here. Thank you!

Volume 150
Volume 150 | July 29, 2026 Reminder to JOIN the The Secured Collective community Slack channel to network, engage, and be part of something big! You can sign up here. Welcome to the Access Control Executive Brief Volume 150! As Semisonic sang in "Closing Time"… "Every new beginning comes from some other beginning's end."And here we are.One. Hundred. Fifty. I have written that number (more ...
Volume 149
Volume 149 | July 8, 2026 Reminder to JOIN the The PhySec Collective community Slack channel to network, engage, and be part of something big! You can sign up here. iLOQ published its 2025 Annual Report last week, and with my trip to Oulu, Finland canceled due to weather, I figured I'd cover their report instead. Inside the ESG appendices and IFRS statements is a cleaner test of my three c...
Volume 148
Volume 148 | June 29, 2026 Reminder to JOIN the The PhySec Collective community Slack channel to network, engage, and be part of something big! You can sign up here. It was a treat to spend the day with ALOA Security Professionals Association. I'm grateful to Dave O'Toole for spearheading the opportunity to be there. Dave is an absolute legend in this industry, and if the locksmith trade c...
Footer Logo
© 2026 The Access Control Collective.
All Rights Reserved.
Privacy Policy Terms of Use

Join Our Free Trial

Get started today before this once in a lifetime opportunity expires.