AI Risk #1 Cybersecurity Concern Among Companies
Arctic Wolf survey finds 35% ranked AI-related risks first, while 51% now require AI capabilities when choosing or renewing cybersecurity products.
Key Takeaways
- 35% ranked AI and its associated privacy risks as their leading cybersecurity concern, compared with 25% for ransomware and related threats.
- 51% require AI capabilities when choosing or renewing cybersecurity products.
- 63% confirmed a major cybersecurity incident in the previous year, while another 7% believed an incident may have gone undetected.
- Blocking malicious internet addresses was the only security task that a majority trusted AI to perform without human involvement.
Cybersecurity company Arctic Wolf’s 2026 AI & Cybersecurity Trends Report found AI cybersecurity risks were the number one cyber concern for survey respondents for the second year in a row. AI-related risks widened their lead over ransomware and related threats from 8 percentage points in 2025 to 10 points this year.
Companies increasingly view AI as a cybersecurity risk while also expecting security products to use it as part of their defenses.
AI becomes a requirement for security products
51% said AI capabilities are now required when choosing or renewing cybersecurity products. Another 43% said they strongly consider them, while 5% said AI has little influence on their decisions.
Most organizations are already testing or using AI in cybersecurity. However, their level of adoption varies.
44% were evaluating or testing AI for cybersecurity. Another 22% had deployed it in limited parts of their security operations, while 34% used it across multiple security workflows or had made it central to their cybersecurity strategy.
Only 14% said AI was central to their cybersecurity operations.
Companies keep humans involved in most AI decisions
The survey asked which security tasks respondents would trust AI to perform without human supervision.
Blocking malicious internet addresses or website domains at a firewall was the only task to receive majority support, at 53%.
Fewer than half trusted AI to independently classify security alerts, lock compromised accounts, fix known software weaknesses or dismiss alerts it considered harmless.
Data privacy was the most common reason for that hesitation, selected by 51%. Another 49% cited AI’s lack of human judgment.
Cyber incidents keep pressure on security buyers
63% confirmed that their organization experienced at least one major cybersecurity incident during the previous 12 months. Another 7% believed an incident may have occurred without being detected.
Among organizations that confirmed an incident, 48% lost time or productivity for at least two weeks.
The report defined a major incident broadly. It included events that caused financial, operational, data, legal, or reputational harm, required changes to security policies, or needed outside recovery assistance.
Despite those incidents, 96% expressed confidence that their security teams could keep up with the volume and complexity of current threats.
For now, only 14% have made AI central to their cybersecurity operations, and most still require a person to approve actions taken inside company systems.
The report surveyed 1,350 IT and security decision-makers about their security priorities, recent incidents, and use of AI in cybersecurity.