The newly released 2026 SANS AI survey reveals that cybersecurity AI adoption has surged significantly over the past year, even as governance frameworks struggle to keep pace.
Security teams adopted artificial intelligence tools faster in 2026 than in any previous year, creating a distinct gap between deployment and organizational oversight. The report draws on insights from 536 global IT practitioners and 57 senior security leaders to outline these operational challenges.
According to the data, the rapid integration of these technologies has outpaced the development of necessary workforce structures. Many organizations are deploying tools without establishing clear guidelines for their use. This trend has forced security teams to manage complex systems while simultaneously trying to define their operational boundaries.
Key Findings from the SANS AI Survey
The SANS AI survey highlights a massive shift in how security professionals utilize automated tools for offensive testing. Specifically, red teaming moved from a minority to a majority practice in a single year, with 61% of practitioners now using AI in red teamwork, up from 33% in 2025. Despite this rapid growth, only 27% of respondents describe their current deployments as mature production systems.
Most organizations continue to run these tools in pilot phases or supporting roles. Meanwhile, application security and incident response functions are increasingly treated as daily operations. This shift indicates that security departments are committing to these technologies long-term, rather than treating them as temporary experiments.

The Governance and Audit Gap
As organizations rush to implement new tools, security teams are taking on governance duties that exceed their current infrastructure capabilities. The report states that 76% of practitioners now hold a governance role for enterprise artificial intelligence systems. However, more than half of these professionals report that no formal audit frameworks exist to support their oversight responsibilities.
This lack of structured auditing correlates with a rise in operational failures. Notably, 63% of practitioners reported significant shortcomings in threat detection and response, a substantial increase from the 45% reported in 2025. Without proper validation, tools may fail to deliver the expected security benefits.
Adversaries Use AI in Attack Cycles
Threat actors are not waiting for corporate governance to mature before deploying automated tools. Adversaries are actively integrating these technologies into multiple stages of the attack life cycle, including reconnaissance, exploitation, and social engineering. Consequently, 78% of organizations reported confirmed or suspected attacks enabled by these technologies over the past year.
Furthermore, 95% of respondents believe that threat actors are actively using automated tools to bypass traditional defenses. This widespread adoption by adversaries pressures defensive teams to accelerate their own deployments, often at the expense of thorough testing and risk assessment.
Human Expertise and Future Outlook
Despite the focus on automation, human expertise remains the primary defense against modern threats. Nearly half of the surveyed practitioners identified behavioral detection as their most effective control. This was followed closely by user awareness training at 45% and human analyst review at 39%.
“You can’t fix these gaps without people who can catch what the tools miss. The teams that invest in upskilling now are also the ones positioned to get more out of the AI they have already bought, because the people running it know when to trust it and when to step in.”
Matt Bromiley, SANS Certified Instructor
This emphasis on human oversight is driving a shift in professional education and training. The SANS AI survey notes that 73% of practitioners reported changes in their team’s training requirements in 2026, up from 51% in 2025. To close the readiness gap, the report recommends building validation infrastructure, moving governance into operational controls, and treating workforce development as an immediate operational priority.





