The gap between adoption and trust in artificial intelligence (AI) tools in cybersecurity is widening, a global survey finds, as organizations struggle to establish governance for effective adoption.
The active use of AI in cybersecurity strategies by IT and security professionals has increased from 50% to 78% in one year. 2026 SANS AI Survey Insights By SANS Institute, an information and cybersecurity training company. At the same time, increased adoption is creating more failures.
63% of practitioners report significant shortcomings in AI in threat detection and response, up from 45% in 2025, and two-thirds say AI guidance has misled them at least once in the past year. Only 27% of practitioners consider their company’s AI implementation to be mature, with the majority saying AI remains in a supporting role or in a pilot stage.
One comment from an anonymous respondent highlighted the lack of trust in AI in critical jobs. “We tend to treat AI as digital interns and check their work.”
AI shortcomings make organizations vulnerable to adversaries. Research shows that 78% of organizations have experienced or suspected an AI-powered attack in the past year. Even though 95% of leaders believe cyber attackers are already using AI, only 16% have moved to defend against AI threats.
The SANS Institute surveyed 536 IT and security professionals around the world, as well as 57 senior security executives, including chief information security officers.
Half of the leaders surveyed said their organization has a formal AI risk program. At the practitioner level, only 36% said the same answer.
“Programs that are invisible to those doing the work are actually less governed,” the study says.
Is AI working? Yes, almost half of respondents said they had less manual work and saved time and money. One metric that is less tracked is the percentage of actual threats captured by AI.
“Efficiency is the most visible benefit and the one most likely to be overestimated,” the study states. “AI systems can significantly reduce analyst workload while missing important parts of true threats. Teams that only monitor efficiency may not notice until an incident causes a problem.”
— If you would like to comment on this article or suggest an idea for another article, please contact Steph Brown. Stephanie.Brown@aicpa-cima.com.
