SANS found that AI adoption climbed from 50% to 78% in one year, while the share of practitioners reporting significant shortcomings increased from 45% to 63%.
Key Takeaways
- AI use in cybersecurity strategies rose from 50% in 2025 to 78% in 2026, the largest year-over-year increase recorded in the SANS survey.
- In 2026, 63% of practitioners, the IT and security professionals executing cybersecurity initiatives, reported problems with AI threat detection and response, up from 45% a year earlier. False positives, difficulty recognizing new threats, and confidently wrong output were among the most common problems.
- Security teams now have more responsibility for governing AI, but the systems supporting that work have barely changed. 50% of senior security leaders said their organization has a formal AI risk program, compared with 36% of practitioners.
The 2026 SANS AI Survey found that AI use in cybersecurity increased sharply even as more practitioners reported problems with the technology’s ability to detect and respond to threats.
The cybersecurity training and research organization reported that 78% of surveyed practitioners said their employer actively uses AI as part of its cybersecurity strategy, up from 50% in 2025. At the same time, 63% reported significant shortcomings when AI was used to detect or respond to threats, compared with 45% a year earlier.
AI is not yet central to security operations
Among respondents, 54% described AI as being in early production or at the pilot stage, with only 11% considering it critical to their security work. Another 27% said it had been integrated into daily operations.
AI use in cybersecurity outpaces reliability
Nearly two-thirds of practitioners said an AI security tool had sent their team in the wrong direction at least once in the previous 12 months. The report found that 23% experienced this between one and five times, while 42% reported six or more instances.
These AI cybersecurity failures can add work for human analysts who must check the system’s conclusions. The survey found that 73% of practitioners said AI had changed their team’s training requirements, up from 51% in 2025. Human review was also among the controls respondents considered most effective against AI-related attacks.
Security teams are taking on more responsibility for governing AI, but formal programs have barely grown. The share of practitioners whose teams have an AI governance role rose from 68% to 76%, while the share reporting a formal AI risk program increased only from 35% to 36%.
AI use also remains outside formal company rules in many workplaces. Only 41% of respondents said generative AI was used for security tasks under a strict policy, while 39% reported informal use without a policy.
Senior executives viewed their companies as further along. 50% said their company had a formal AI risk program, compared with 36% of practitioners. The report said the difference may reflect programs that have not trickled down to practitioners or different understandings of what counts as a formal program.
The practical gaps were also visible in the survey. 63% of practitioners said their security teams could not clearly track where AI systems were being used or what company data those systems might expose. Another 54% said their company had no established standards for auditing AI systems.
Attackers’ use of AI added another source of pressure. 95% of respondents said attackers were already using AI, with 78% of organizations reporting confirmed or suspected AI-related attacks in the past year.
Recent surveys from Kroll and Netwrix have also found similar governance gaps.
The survey fielded responses from 536 IT and cybersecurity professionals worldwide. A separate survey was completed by 57 chief information security officers and other senior security executives. It included respondents from the technology, cybersecurity, banking, finance, and government sectors.

