Skip to content
Menu
Menu

AI Use in Cybersecurity Jumps To 78% As Detection And Response Problems Rise

SANS found that AI adoption climbed from 50% to 78% in one year, while the share of practitioners reporting significant shortcomings increased from 45% to 63%.

 

Key Takeaways

  • AI use in cybersecurity strategies rose from 50% in 2025 to 78% in 2026, the largest year-over-year increase recorded in the SANS survey.
  • In 2026, 63% of practitioners, the IT and security professionals executing cybersecurity initiatives,  reported problems with AI threat detection and response, up from 45% a year earlier. False positives, difficulty recognizing new threats, and confidently wrong output were among the most common problems.
  • Security teams now have more responsibility for governing AI, but the systems supporting that work have barely changed. 50% of senior security leaders said their organization has a formal AI risk program, compared with 36% of practitioners.

The 2026 SANS AI Survey found that AI use in cybersecurity increased sharply even as more practitioners reported problems with the technology’s ability to detect and respond to threats.

The cybersecurity training and research organization reported that 78% of surveyed practitioners said their employer actively uses AI as part of its cybersecurity strategy, up from 50% in 2025. At the same time, 63% reported significant shortcomings when AI was used to detect or respond to threats, compared with 45% a year earlier.

AI is not yet central to security operations 

Among respondents, 54% described AI as being in early production or at the pilot stage, with only 11% considering it critical to their security work. Another 27% said it had been integrated into daily operations.

 

AI use in cybersecurity outpaces reliability

Nearly two-thirds of practitioners said an AI security tool had sent their team in the wrong direction at least once in the previous 12 months. The report found that 23% experienced this between one and five times, while 42% reported six or more instances.

These AI cybersecurity failures can add work for human analysts who must check the system’s conclusions. The survey found that 73% of practitioners said AI had changed their team’s training requirements, up from 51% in 2025. Human review was also among the controls respondents considered most effective against AI-related attacks.

Security teams are taking on more responsibility for governing AI, but formal programs have barely grown. The share of practitioners whose teams have an AI governance role rose from 68% to 76%, while the share reporting a formal AI risk program increased only from 35% to 36%.

AI use also remains outside formal company rules in many workplaces. Only 41% of respondents said generative AI was used for security tasks under a strict policy, while 39% reported informal use without a policy.

Senior executives viewed their companies as further along. 50% said their company had a formal AI risk program, compared with 36% of practitioners. The report said the difference may reflect programs that have not trickled down to practitioners or different understandings of what counts as a formal program.

The practical gaps were also visible in the survey. 63% of practitioners said their security teams could not clearly track where AI systems were being used or what company data those systems might expose. Another 54% said their company had no established standards for auditing AI systems.

Attackers’ use of AI added another source of pressure. 95% of respondents said attackers were already using AI, with 78% of organizations reporting confirmed or suspected AI-related attacks in the past year.

Recent surveys from Kroll and Netwrix have also found similar governance gaps.

The survey fielded responses from 536 IT and cybersecurity professionals worldwide. A separate survey was completed by 57 chief information security officers and other senior security executives. It included respondents from the technology, cybersecurity, banking, finance, and government sectors.

Clayton Rifkind

Clayton Rifkind is the Founder and Senior Editor of AI Risk Today. He also advises on business development for ESG Today, a leading source of ESG investment news and research for institutional investors and corporate leaders. He has 20+ years of experience in B2B technology, leading strategy and execution of go-to-market plans across software, enterprise platforms, and mobile applications. He founded two consultancies advising startups and Fortune 1000 companies, including Autodesk, Intel, and Microsoft. He began his career in the San Francisco advertising scene working with brands such as Hewlett-Packard, Intel, Microsoft, Symantec, and Wells Fargo. Clayton launched AI Risk Today in 2025 after two decades of watching enterprises adopt transformative technologies, and seeing how often risk, governance, and compliance considerations lagged behind. His reporting draws on primary sources including regulatory filings, court documents, and official announcements, with a focus on what AI developments mean for the executives accountable for managing them. Reach him at Reach him at [email protected] or on LinkedIn.

Essential AI Risk Intelligence

Daily insights on AI governance, regulation, and enterprise risk management. Trusted by Chief Risk Officers and compliance leaders globally.

By subscribing, you agree to receive our daily newsletter. Unsubscribe anytime.

Advertise with AI RIsk Today, Today!