The gap between deployment of artificial intelligence (AI) tools in cybersecurity and confidence in those tools is widening as organisations struggle to establish governance for effective implementation, a global survey shows.
Active use of AI in cybersecurity strategy among IT and security professionals rose from 50% to 78% in one year, according to 2026 SANS AI Survey Insights by SANS Institute, an information and cybersecurity training company. At the same time, increased deployment has produced more failures.
Sixty-three per cent of practitioners reported significant AI shortcomings in threat detection and response, up from 45% in 2025, and two-thirds said AI guidance has steered them wrong at least once in the past year. Only 27% of practitioners labelled their AI deployment as mature, and most said that AI remained in a supporting role or pilot phase.
One comment from an anonymous respondent underscored the lack of trust in AI for important work: “We tend to treat our AI as a digital intern and check its work.”
The AI shortcomings leave organisations vulnerable to adversaries. According to the survey, 78% of organisations experienced confirmed or suspected AI-enabled attacks in the past year. Despite 95% of leaders believing that cyber attackers are already using AI, only 16% have shifted to defending against AI-driven threats.
SANS Institute surveyed 536 IT and security practitioners globally and an additional 57 senior security executives, including chief information security officers.
Half of leaders surveyed said their organisations have a formal AI risk programme; on the practitioner level, just 36% said the same.
“A programme that the people doing the work cannot see is not governing much in practice,” the survey said.
Is AI working? Yes, nearly half of respondents say it has created time and cost savings from reduced manual work. One metric not tracked as often: the share of real threats caught by AI.
“Efficiency is the easiest benefit to see and the easiest to overweight,” the survey said. “An AI system can cut analyst workload sharply while still missing a meaningful fraction of genuine threats, and a team watching only efficiency may not notice until an incident forces the issue.”
— To comment on this article or to suggest an idea for another article, contact Steph Brown at Stephanie.Brown@aicpa-cima.com.
