Listen to this article
Executive Summary
AI has become the primary force reshaping cybersecurity, and it is reshaping both sides of the fight at the same time: sharpening attacks and, when deployed properly, sharpening defence. The organisations still treating this as a future problem are already behind. The ones closing the gap are doing three things at once: locking down the access controls around their own AI systems, putting AI to work in detection and response today, and rebuilding a skills pipeline that the industry’s own tools are quietly eroding.
94%
of security leaders say AI is the most significant driver of change in cybersecurity in 2026, World Economic Forum Global Cybersecurity Outlook
$6M vs $4.99M
average cost of an AI-enabled breach versus the global average, IBM Cost of a Data Breach Report 2026, AI-driven attacks up 56% year over year
92%
of organisations that suffered an AI-related breach had no proper AI access controls in place, IBM (2026)
41% → 59%
AI security is now the top critical-skills priority cybersecurity teams cite, and 59% report a critical or significant skills gap overall, up 15 points, ISC2 Workforce Study
Core conclusions
- AI is not a future threat to plan for. It is already the largest single factor changing attack and defence, and the gap between adoption and governance is widening, not closing.
- Deploying AI in security operations today has a measurable, already-proven payoff: organisations doing it close breaches roughly two months faster and pay close to $2 million less. Most of the risk sits in access control and oversight, not the technology itself.
- The skills shortage is shifting shape. It is no longer mainly a headcount problem. It is a shortage of the specific expertise needed to run and govern AI-driven security, at the exact moment Gartner warns that over-reliance on automation could erode the foundational skills teams already have.
The four things every security leader needs to know, ten slides
Save it, share it, or send it to whoever is still treating AI cyberdefense as next year’s budget line.










AI is now the biggest factor reshaping both attack and defence
The World Economic Forum’s Global Cybersecurity Outlook 2026, based on responses from over 800 executives across 92 countries, found 94% of leaders naming AI as the single most significant driver of change in cybersecurity this year. That is not a split opinion across a divided industry. It is close to consensus, and the reason is that AI is not helping one side of the fight. It is helping both. The same capability that lets a defender triage ten thousand alerts in minutes lets an attacker generate a convincing spear-phishing campaign, a cloned voice, or a working exploit in a fraction of the time it used to take.
The same report found 87% of leaders naming AI vulnerabilities as the fastest-growing risk category, and a governance gap that is closing too slowly to keep pace: the share of organisations formally assessing the security of an AI tool before deploying it rose from 37% in 2025 to 64% in 2026, real progress, but still leaving more than a third of organisations putting AI systems into production with no security review at all. This is the shape of the problem for most organisations right now, adoption outrunning governance, not AI capability outrunning human capability.
Free tool
AI Trust & Governance Assessment
Score where your organisation actually stands on AI access controls, oversight, and security review, before an incident forces the audit.
What the 2026 data actually shows about AI-enabled attacks
IBM’s 2026 Cost of a Data Breach Report puts numbers on what “AI is helping attackers” means in practice. AI-driven attacks rose 56% year over year and now account for one in four malicious breaches, at an average cost of $6 million, about $1 million above the $4.99 million global average. The attack types doing most of that damage are unglamorous and specific: deepfake impersonation, AI-enabled malware, and AI-generated phishing campaigns, not exotic novel exploits.
The more important finding sits underneath that headline. More than one in five organisations reported a security incident involving their own AI models or applications, and 92% of those breached organisations had no proper AI access controls in place, the root causes reading like a familiar list: compromised APIs, vulnerable applications and plug-ins, and cloud misconfigurations affecting AI workloads. The two costliest AI-specific incident types, model inversion attacks and prompt injection, both exploit exactly that gap. This is not a story about attackers outsmarting defenders with superior AI. It is a story about organisations deploying AI systems with the same access-control discipline they would never accept for a production database, and paying for it.

Shadow AI compounds the problem. IBM found that employees using unapproved AI tools were involved in 43% of security incidents, more than double the prior year’s share, with those incidents involving data loss or compromise roughly half the time and triggering regulatory fines in about one in five cases. The threat here is not that someone’s personal AI assistant gets hacked. It is that an organisation has no visibility into what data left the building through a channel nobody approved.
Deploying AI in security operations already pays off today
The same IBM data that documents the attack side documents a clear, already-proven case for the defence side. Organisations running AI and automation extensively across prevention, detection, investigation, and response closed breaches roughly two months faster and paid close to $2 million less than organisations running none of it. That is not a projection. It is what happened in 2026 to organisations that made the investment, measured against ones that didn’t.
Gartner’s read on where that investment is actually landing matters here. More than half of organisations already use AI agents for threat detection and containment, the two use cases with the fastest, clearest payoff, closing the gap between an alert firing and a human acting on it. Far fewer, under one in five, have extended AI into vulnerability management, which leaves a slower-moving but still serious remediation window open. The practical starting point for most security teams in 2026 is not a wholesale AI SOC rebuild. It is putting AI to work on the highest-volume, most time-sensitive part of the pipeline first: alert triage, enrichment, and initial containment, where the two-month, two-million-dollar advantage is already documented, before extending further.
That said, Gartner has been explicit that not every vendor claiming “AI SOC” capability has it. Its 2026 guidance to buyers is to pilot rigorously, demand transparency into what the system actually does versus what it’s marketed to do, and verify claims before paying an AI premium for what is, underneath, a rules engine with a chatbot in front of it.
Free tool
AI Model Performance & Health Dashboard
Track the reliability of any AI system you’re running in production, security tooling included, against thresholds designed to catch drift before it becomes an incident.
What to plan for as autonomous security agents take on more
The trajectory past today’s alert-triage deployments points toward more autonomy, faster than most governance structures are built to handle. Gartner projects that by 2029, 10% of organisations will run autonomous agents with no human oversight for network security operations, up from under 1% in 2026. That is a real shift in where accountability sits, from a human approving an agent’s recommendation to an agent acting on its own inside a live network, and it is arriving within the planning horizon most security budgets already cover.

Planning for that shift means building the governance now, not after the first autonomous-agent incident forces it. MITRE ATLAS, the structured knowledge base of adversary tactics against AI and machine learning systems, added new case studies in its January 2026 update specifically covering compromised MCP servers, indirect prompt injection through agent-to-agent channels, and malicious autonomous agent deployment, which is the concrete shape of the risk this trajectory is heading toward. A security team planning its 2027 roadmap should be mapping its own AI-agent attack surface against ATLAS the same way it already maps infrastructure against MITRE ATT&CK, before autonomy expands past what anyone is actively reviewing.
Free tool
Board AI Oversight Checklist
Who has override authority over an autonomous security agent, what triggers escalation, and whether that has been tested, before autonomy expands past what anyone is reviewing.
The skills gap is shifting from headcount to AI-specific expertise
ISC2’s latest workforce study, drawing on more than 16,000 cybersecurity professionals globally, found 95% reporting at least one skills need and 59% reporting a critical or significant skills gap, up 15 points on the year before. What has changed is which skill is scarcest. AI security is now the top critical-skills priority cited by respondents, at 41%, ahead of cloud security at 36%. Budget has also overtaken talent availability as the most-cited constraint: 33% of organisations say they cannot adequately staff their teams, and 29% say they cannot afford the skilled hires they’d want to make, which means the gap is not purely a training problem. It is also a resourcing decision leadership has to actually make.
The specific expertise in shortest supply is fairly concrete: people who can red-team an AI system the way ATLAS describes rather than only a traditional network, who understand how prompt injection and model inversion actually work well enough to design controls against them, and who can govern access to AI models and pipelines with the same rigour applied to a production database. None of that is exotic research-lab knowledge. It is standard security discipline, applied to a new class of system, and most teams simply haven’t had the time or budget to build it yet.
There’s a second, quieter risk sitting underneath the shortage, and it cuts the other way. Gartner projects that by 2030, 75% of SOC teams will experience erosion in foundational security analysis skills from over-dependence on automation and AI. The two risks are connected: an organisation that hires too slowly to keep pace with AI-specific threats is under pressure to lean harder on AI tooling to cover the gap, and leaning on it without deliberate investment in keeping analysts sharp is exactly what produces the erosion Gartner is warning about. Closing the skills gap and avoiding that erosion is the same project, not two separate ones: train people to understand what the AI is doing well enough to catch it when it’s wrong, rather than training them to defer to it.
A practical starting checklist
| Discipline | What good looks like | What to avoid |
|---|---|---|
| AI access control | Scoped, audited access to every AI model, pipeline, and plug-in your organisation runs | Treating an AI system as exempt from the access discipline applied to a database |
| AI deployment in security ops | Start with alert triage, enrichment, and containment, where the payoff is already documented | Buying an “AI SOC” platform without piloting what it actually automates |
| Shadow AI visibility | A known inventory of AI tools employees actually use, approved or not | Assuming a policy document stops unapproved tool use |
| Agent autonomy governance | Defined override authority and escalation triggers before autonomy expands | Discovering nobody can pull an autonomous agent back mid-incident |
| Skills investment | Budget for AI-specific security training, not just headcount | Leaning on AI tooling to cover a hiring gap with no plan to keep analysts sharp |
This has to be a standing practice, not a project with an end date
None of the individual pieces here are exotic. Access control, phased AI deployment starting where the payoff is proven, visibility into shadow AI, governance built ahead of autonomy rather than after an incident, and deliberate investment in the specific skills this shift demands, are all standard security discipline. What’s different is the pace: the WEF’s governance-maturity gap, Gartner’s autonomy timeline, and IBM’s access-control failures are all describing the same underlying problem, organisations moving fast on adoption and slow on the controls that make adoption safe.
The organisations that come out of this in a defensible position will not be the ones that adopted AI security tooling first. They’ll be the ones that treated locking down their own AI systems and building the skills to govern them as the same priority as deploying the tooling in the first place, not an afterthought to catch up on later.
Sources
- World Economic Forum. (2026). Global Cybersecurity Outlook 2026.
- IBM. (2026, July 29). IBM Study: One in Four Malicious Breaches Are AI-Enabled, Costing Companies $6 Million on Average.
- IBM. (2026). Cost of a Data Breach Report 2026.
- ISC2. (2025). Cybersecurity Skills Matter More Than Headcount in the AI Era, ISC2 Cybersecurity Workforce Study, reported via CSO Online.
- Gartner. (2026, February 5). Gartner Identifies the Top Cybersecurity Trends for 2026.
- Gartner 2026 Security & Risk Management Summit, reported via Conifers.ai. (2026). AI SOC Takeaways From Gartner’s 2026 Security Summit.
- MITRE. (2026, January). MITRE ATLAS, adversarial threat landscape for AI systems.
The AI Governance & ROI Executive Programme builds exactly this, access controls, AI deployment sequencing, and agent oversight, into your own security operations before autonomy expands on a system you’re accountable for. Details are on the workshops page.
Was this useful?





