Group Purchasing
Group Purchasing

SANS 2025 AI Survey: Measuring AI’s Impact on Security Three Years Later

SANS 2025 AI Survey: Measuring AI’s Impact on Security Three Years Later (PDF, 2.52MB)Published: 03 Sep, 2025
Created by:

The SANS 2025 AI Survey: Measuring AI's Impact on Security Three Years Later, published by SANS Institute in September 2025, measures how security teams have adopted artificial intelligence three years after generative AI entered mainstream use. The survey draws on responses from security practitioners across incident response, application security, red teaming, governance, and workforce roles, examining where GenAI adoption has taken hold and where it still lags.

Key findings:

  • 81% of security professionals are concerned about AI-powered threats, yet only half of organizations use AI for cybersecurity tasks at all
  • Only 33% use AI to investigate incidents and just 26% use it to respond to them, despite widespread expectation that AI will reshape security operations
  • 66% report that AI systems generate excessive false positives, adding to analyst alert fatigue
  • 15% use generative AI for red teaming, the lowest adoption of any security discipline surveyed, largely due to ethical concerns about privacy and unintended harm
  • 75% expect AI to complement existing tools like SIEM, SOAR, and EDR over the next three years, with only 13% expecting it to fully replace them
  • Only 35% of organizations have a formal AI risk management and compliance program in place, even though 68% believe cybersecurity should have a role in governing AI use
  • 83% are concerned about highly personalized AI-driven social engineering attacks, and 73% are concerned about deepfakes
  • 71% worry employees will pass sensitive data to GenAI platforms such as ChatGPT, risking exposure to other users of the same platform
  • 37% of organizations currently use AI in application security, with static analysis security testing (SAST) the most AI-augmented tool at 65%
  • 51% say AI has affected training requirements for their security team, and 54% have observed job-related changes from AI integration
  • 65% say their teams need more specialized AI and cybersecurity training, and 64% stress the importance of continuous learning
  • 67% anticipate growing demand for professionals with combined AI and cybersecurity expertise over the next three years

The findings point to a consistent gap between how much security teams worry about AI-driven threats and how much they've actually put AI to work defending against them. Adoption clusters around lower-complexity tasks like alert enrichment and anomaly detection, while higher-impact uses such as incident investigation, code review, and red teaming lag behind due to integration challenges, false-positive rates, and unresolved governance questions. Training and workforce development are emerging as the primary response, with organizations betting on upskilling existing staff rather than fully automating security functions.

Respondents were based primarily in the United States (51%) and Europe (20%), spanning the technology (15%), government (14%), cybersecurity (14%), and banking and finance (13%) sectors, with the largest single segment coming from organizations with fewer than 100 employees (18%).

SANS 2025 AI Survey Webcast & Forum: Measuring AI's Impact on Security Three Years Later

Related Webcast

This webcast is built on insights from one of our most anticipated cybersecurity surveys of the year—offering an in-depth look at how the community is adopting, adapting to, and defending against artificial intelligence in all its forms.

Man presenting webcast

Meet Your Author

Ahmed Abugharbia
Ahmed Abugharbia

Ahmed AbuGharbia

Certified Instructor

Ahmed AbuGharbia, SANS Instructor and SEC545 author, helps practitioners secure generative AI systems by identifying risks, understanding model behavior, and applying practical security controls.

Read more about Ahmed AbuGharbia