Bottom line: CISOs must justify AI security spend by demonstrating a clear ROI, focusing on cost savings and risk reduction.
What's happening: The median AI security spend in 2025 was $5.2M, with 25% of companies in the US, UK, and EU spending more than $10M annually, driven by the adoption of deep learning models and the growing threat of AI-powered attacks, including those using the Apache Spark MLlib library (CVE-2022-25118, CVSS score 7.5) and the SANS 2026 Top 10 Cybersecurity Threats report.
What to do: CISOs should prioritize vulnerability assessments, threat modeling, and penetration testing to measure AI security spend's effectiveness and ensure compliance with regulations like the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).