Group Purchasing
Group Purchasing

SANS 2026 AI Report

The 2026 SANS AI Report describes a field that made a sound bet on AI and is now finding out what it costs to keep, as we saw adoption rise sharply in the past year. The governance, validation, and workforce depth needed to support that scale did not keep up. Adversaries adopted AI as fast as defenders, sometimes faster.

Top Takeaways

78%

already facing AI-enabled attacks, not just anticipating them

16%

of leaders shifted priority to defend against AI

63%

report real shortcomings in AI threat detection

73%

say AI changed their team’s training requirements in 2026

Survey Methodology and Respondent Profile

Published by SANS Institute in July 2026, the report draws on insights from 536 security practitioners and 57 senior leaders globally.

Verticals & Region

Respondents represented technology (24%), cybersecurity (12%), banking and finance (9%), and government (8%) organizations, with the largest concentration of operations in the United States (46%).

Vendor Neutrality

Sponsors funded the research but had no role in survey design or analysis.

Meet the Author

Matt Bromiley
Matt Bromiley

Matt Bromiley

Security R&D at Prophet Security

Matt Bromiley is a Lead Solutions Engineer at LimaCharlie and SANS Certified Instructor. He serves as a GIAC Advisory Board member, a SME for the SANS Security Awareness, and a technical writer for the SANS Analyst Program.

Read more about Matt Bromiley

Thank You To Our Sponsors

Key Findings from the SANS 2026 AI Report

  • Active AI use in cybersecurity jumped from 50% to 78% in a year, the largest increase this survey has recorded, though only 27% of practitioners call their deployment mature production.
  • 78% of organizations report confirmed or suspected AI-enabled attacks, and 95% believe threat actors are already using AI.
  • 63% of practitioners report significant AI shortcomings in threat detection and response, up from 45% in 2025.
  • 76% of security teams now hold a governance role for enterprise AI, up from 68% in 2025, but the share with a formal risk program barely moved.
  • 61% now use AI in red team work, up from 33% in 2025, the steepest single-year jump in the survey.
  • Among leaders, 63% shifted priority toward AI for defense, while only 16% shifted toward defending against AI threats.

Related Webcast: Poisoned Wells and Pure Springs: Drawing Security and Compromise from the same AI Source

Four years after the public debut of ChatGPT, the cybersecurity landscape has entered a new phase—where AI is no longer just a tool, but a battleground.

White Microphone Blue Background

Research: SANS Research: AI in Cybersecurity

Explore the SANS AI Report Archive

2026 marks the third edition of the SANS AI Report. Explore the past few years to track how AI adoption, governance maturity, and adversarial use have shifted year over year.

FAQs

78% of organizations now actively use AI in their cybersecurity strategy, up from 50% in 2025, according to the 2026 SANS AI Survey. Only 27% call their deployment mature production.

Yes. 78% of organizations report confirmed or suspected AI-enabled attacks in the past year, and 95% of respondents believe threat actors are already using AI, according to the 2026 SANS AI Survey.

Not consistently yet. 63% of practitioners report significant AI shortcomings in threat detection and response, up from 45% in 2025, per the 2026 SANS AI Survey.

No. 50% of senior leaders report a formal AI risk management program, compared with only 36% of practitioners, a 14-point perception gap identified in the 2026 SANS AI Survey.

73% of practitioners say AI changed their team's training requirements in 2026, up from 51% in 2025, a 22-point jump according to the 2026 SANS AI Survey. 

Yes. 61% of practitioners now use AI in red team work, up from 33% in 2025, the steepest single-year jump the 2026 SANS AI Survey has recorded.