Security Teams Are Moving Faster Than Their AI Policies
A new survey from the SANS Institute paints a stark picture: cybersecurity professionals are racing to deploy artificial intelligence, but the safety nets meant to keep that deployment under control aren’t keeping up.
The 2026 SANS AI Survey Insights report, based on responses from 536 global cybersecurity and IT practitioners plus 57 security leaders, found that 78% of organizations now actively use AI in their cybersecurity strategy. That’s a jump from 50% just a year earlier. But the same survey reveals a troubling parallel trend: 63% of respondents reported “significant shortcomings” in threat detection and response — up sharply from 45% in 2025.
“For two years now, we’ve asked security teams where they actually stand with AI,” said Matt Bromiley, the report’s author and a SANS certified instructor. “Both years, the honest answer has been some version of moving fast and working it out as we go. What’s changed in 2026 is how much weight is now sitting behind that answer.”
The AI governance gap is real — and it’s widening.
Trust in AI Decisions Hits a Wall
One of the report’s most striking findings: trust in AI decisions (40%) has replaced “wiring AI into existing systems” as the top barrier to deeper integration. Teams aren’t just struggling to plug AI into their workflows anymore. They’re questioning whether they can rely on the outputs.
That trust deficit is compounded by a governance vacuum. Only half (50%) of the cybersecurity leaders surveyed said their organization has a formal AI governance program in place. Meanwhile, 44% described themselves as being in the early stages of drafting policy — and some respondents claimed to be in both categories at once, suggesting confusion over what “governance” actually means in practice.
AI governance isn’t just a buzzword. Without clear rules on data access, model validation, and incident response, organizations are essentially flying blind with powerful — and fallible — tools.
Where AI Is Actually Helping (and Where It’s Not)
It’s not all bad news. The survey identified two areas where AI is delivering clear value for network defenders: behavioral detection (48% of respondents reported effective use) and user awareness training (45%). These are practical, measurable wins.
But the threat landscape is shifting just as fast. 78% of organizations reported confirmed or suspected AI-enabled attacks in the past year. The most common incidents involved deepfakes, vulnerability exploitation, phishing, and adversarial attacks on AI models themselves. Attackers are weaponizing the same technology defenders are trying to harness.
The Upskilling Crunch
Perhaps the most urgent finding concerns the workforce. Three-quarters of respondents (73%) said AI has changed their training requirements, up from 51% in 2025. That’s a massive shift in just 12 months.
“You can’t fix these gaps without people who can catch what the tools miss,” Bromiley said. “The teams that invest in upskilling now are also the ones positioned to get more out of the AI they have already bought, because the people running it know when to trust it and when to step in.”
SANS argues the next year is critical. The report recommends a three-point investment plan:
- AI validation infrastructure — focusing on “precision, recall, and continuous comparison” rather than simply buying more tools
- Operationalizing governance — treating sensitive-data access and AI data exposure as core controls, not afterthoughts
- Workforce development — handled as an immediate operational need, not a medium-term hiring goal
Closing the Gap Means Slowing Down — Just a Little
The numbers tell a clear story. Adoption is surging. Threats are evolving. And too many organizations are still making up their AI policies as they go.
For security teams, the path forward isn’t about abandoning AI — it’s about building the governance, trust, and skills to use it responsibly. That means investing in people as much as technology, and treating AI upskilling as a here-and-now priority rather than a future project.
As Bromiley put it: “Moving fast is fine — but you need to know where you’re going.”