New data from SANS Institute’s 2026 AI Survey Insights report identified that the use of AI (artificial intelligence) in cybersecurity has accelerated sharply, but organizations are struggling to keep governance and operational safeguards aligned with adoption. The survey found that 61% of cybersecurity practitioners now use AI in red team activities, up from 33% in 2025, while 76% have an enterprise AI governance role. Yet more than half said formal audit frameworks are not in place, and only 27% described their AI deployment as mature production.
The survey also points to growing concerns over AI-related security failures as attackers increasingly incorporate AI across the attack lifecycle. 63% of respondents reported significant AI shortcomings in threat detection and response, up from 45% in 2025, while 78% said their organizations experienced confirmed or suspected AI-enabled attacks during the past year. The report, based on responses from 536 cybersecurity and IT practitioners and 57 senior security leaders, also found that 73% said AI changed their teams’ training requirements in 2026, highlighting the growing need for stronger validation, operational governance and workforce skills as adoption expands.
“For two years now, we’ve asked security teams where they actually stand with AI,” Matt Bromiley, the report’s author and a SANS Certified Instructor, said in a media statement. “Both years, the honest answer has been some version of moving fast and working it out as we go. What’s changed in 2026 is how much weight is now sitting behind that answer.”
The 2026 AI Survey Insights survey reported that AI adoption in cybersecurity has risen sharply, with the share of practitioners using AI as part of their security strategy increasing from 50% in 2025 to 78% in 2026, according to the survey findings shown. However, only 27% of practitioners described their AI deployment as mature production, with most still piloting AI or using it in a supporting role. The findings also show that 63% of practitioners reported significant AI shortcomings in threat detection and response, up from 45% in 2025, while two-thirds said AI guidance had steered them wrong at least once in the past year.
The 2026 AI Survey Insights identified governance and trust as growing challenges as AI adoption expands. 76% of security teams now have a governance role for enterprise AI, up from 68% in 2025, but governance maturity did not show a corresponding increase. 40% of respondents identified transparency in AI decisions as a top concern, while 38% pointed to the efficacy of AI provided by commercial vendors. The findings also show that 73% of practitioners said AI changed their teams’ training requirements in 2026, up from 51% the previous year.
At the same time, AI is becoming more prominent in offensive cybersecurity activity. 61% of practitioners now use AI in red team work, up from 33% in 2025, turning AI use in red teaming from a minority to a majority practice within a year. The survey also found that 78% of organizations reported confirmed or suspected AI-enabled attacks in the past year, while 95% of respondents believe threat actors are using AI. The attacks span phishing, exploitation, deepfakes and reconnaissance, and 52% identified preventing automated attacks from causing real damage in production as a leading operational concern.
Active AI use in cybersecurity strategy rose from 50% in 2025 to 78% in 2026, the largest year-over-year move the survey has seen. The share of organizations with no plans to adopt fell from 9% to 4%.
For most of the industry, the decision to use AI in security has been made; the remaining 18% are mostly planning to start rather than holding out. Deployment depth is the more revealing number. Among the 78% using AI, a third (33%) call it early production, meaning deployed but not essential and another 21% are still experimenting. Most practitioners sit between testing and light operational use, which means that shallow deployment produces a partial picture. Organizations see enough value to keep investing but not enough depth to surface the failure modes that only appear at scale, which can leave confidence sitting on a thin floor.
“In 2025, a real share of the field was still argu