← All Articles

AI Is Now the Weapon and the Shield in Cybersecurity. Most Organisations Are Behind on Both.

1 September 202614 min readSecuritySharePDF

Listen to this article

AI Is Now the Weapon and the Shield in Cybersecurity. Most Organisations Are Behind on Both.

0:00

Executive Summary

AI has become the primary force reshaping cybersecurity, and it is reshaping both sides of the fight at the same time: sharpening attacks and, when deployed properly, sharpening defence. The organisations still treating this as a future problem are already behind. The ones closing the gap are doing three things at once: locking down the access controls around their own AI systems, putting AI to work in detection and response today, and rebuilding a skills pipeline that the industry’s own tools are quietly eroding.

94%

of security leaders say AI is the most significant driver of change in cybersecurity in 2026, World Economic Forum Global Cybersecurity Outlook

$6M vs $4.99M

average cost of an AI-enabled breach versus the global average, IBM Cost of a Data Breach Report 2026, AI-driven attacks up 56% year over year

92%

of organisations that suffered an AI-related breach had no proper AI access controls in place, IBM (2026)

41% → 59%

AI security is now the top critical-skills priority cybersecurity teams cite, and 59% report a critical or significant skills gap overall, up 15 points, ISC2 Workforce Study

Core conclusions

  • AI is not a future threat to plan for. It is already the largest single factor changing attack and defence, and the gap between adoption and governance is widening, not closing.
  • Deploying AI in security operations today has a measurable, already-proven payoff: organisations doing it close breaches roughly two months faster and pay close to $2 million less. Most of the risk sits in access control and oversight, not the technology itself.
  • The skills shortage is shifting shape. It is no longer mainly a headcount problem. It is a shortage of the specific expertise needed to run and govern AI-driven security, at the exact moment Gartner warns that over-reliance on automation could erode the foundational skills teams already have.

AI is now the biggest factor reshaping both attack and defence

The World Economic Forum’s Global Cybersecurity Outlook 2026, based on responses from over 800 executives across 92 countries, found 94% of leaders naming AI as the single most significant driver of change in cybersecurity this year. That is not a split opinion across a divided industry. It is close to consensus, and the reason is that AI is not helping one side of the fight. It is helping both. The same capability that lets a defender triage ten thousand alerts in minutes lets an attacker generate a convincing spear-phishing campaign, a cloned voice, or a working exploit in a fraction of the time it used to take.

The same report found 87% of leaders naming AI vulnerabilities as the fastest-growing risk category, and a governance gap that is closing too slowly to keep pace: the share of organisations formally assessing the security of an AI tool before deploying it rose from 37% in 2025 to 64% in 2026, real progress, but still leaving more than a third of organisations putting AI systems into production with no security review at all. This is the shape of the problem for most organisations right now, adoption outrunning governance, not AI capability outrunning human capability.

Free tool

AI Trust & Governance Assessment

Score where your organisation actually stands on AI access controls, oversight, and security review, before an incident forces the audit.

What the 2026 data actually shows about AI-enabled attacks

IBM’s 2026 Cost of a Data Breach Report puts numbers on what “AI is helping attackers” means in practice. AI-driven attacks rose 56% year over year and now account for one in four malicious breaches, at an average cost of $6 million, about $1 million above the $4.99 million global average. The attack types doing most of that damage are unglamorous and specific: deepfake impersonation, AI-enabled malware, and AI-generated phishing campaigns, not exotic novel exploits.

The more important finding sits underneath that headline. More than one in five organisations reported a security incident involving their own AI models or applications, and 92% of those breached organisations had no proper AI access controls in place, the root causes reading like a familiar list: compromised APIs, vulnerable applications and plug-ins, and cloud misconfigurations affecting AI workloads. The two costliest AI-specific incident types, model inversion attacks and prompt injection, both exploit exactly that gap. This is not a story about attackers outsmarting defenders with superior AI. It is a story about organisations deploying AI systems with the same access-control discipline they would never accept for a production database, and paying for it.

Flowchart of the AI-related breach process: deployment of an AI system without proper access controls, exploitation through compromised APIs, vulnerable apps and plug-ins, or cloud misconfigurations, leading to model inversion attacks and prompt injection attacks
Same gap, three entry points. 92% of AI-related breaches trace back to one missing control, not a more capable attacker.

Shadow AI compounds the problem. IBM found that employees using unapproved AI tools were involved in 43% of security incidents, more than double the prior year’s share, with those incidents involving data loss or compromise roughly half the time and triggering regulatory fines in about one in five cases. The threat here is not that someone’s personal AI assistant gets hacked. It is that an organisation has no visibility into what data left the building through a channel nobody approved.

Deploying AI in security operations already pays off today

The same IBM data that documents the attack side documents a clear, already-proven case for the defence side. Organisations running AI and automation extensively across prevention, detection, investigation, and response closed breaches roughly two months faster and paid close to $2 million less than organisations running none of it. That is not a projection. It is what happened in 2026 to organisations that made the investment, measured against ones that didn’t.

Gartner’s read on where that investment is actually landing matters here. More than half of organisations already use AI agents for threat detection and containment, the two use cases with the fastest, clearest payoff, closing the gap between an alert firing and a human acting on it. Far fewer, under one in five, have extended AI into vulnerability management, which leaves a slower-moving but still serious remediation window open. The practical starting point for most security teams in 2026 is not a wholesale AI SOC rebuild. It is putting AI to work on the highest-volume, most time-sensitive part of the pipeline first: alert triage, enrichment, and initial containment, where the two-month, two-million-dollar advantage is already documented, before extending further.

That said, Gartner has been explicit that not every vendor claiming “AI SOC” capability has it. Its 2026 guidance to buyers is to pilot rigorously, demand transparency into what the system actually does versus what it’s marketed to do, and verify claims before paying an AI premium for what is, underneath, a rules engine with a chatbot in front of it.

Free tool

AI Model Performance & Health Dashboard

Track the reliability of any AI system you’re running in production, security tooling included, against thresholds designed to catch drift before it becomes an incident.

What to plan for as autonomous security agents take on more

The trajectory past today’s alert-triage deployments points toward more autonomy, faster than most governance structures are built to handle. Gartner projects that by 2029, 10% of organisations will run autonomous agents with no human oversight for network security operations, up from under 1% in 2026. That is a real shift in where accountability sits, from a human approving an agent’s recommendation to an agent acting on its own inside a live network, and it is arriving within the planning horizon most security budgets already cover.

Timeline of AI autonomy in network security operations: 2026, minimal autonomy, fewer than 1 percent of organisations run fully autonomous AI agents; 2029, growing autonomy, 10 percent of organisations deploy autonomous AI agents with no human oversight; 2030, skill erosion, 75 percent of SOC teams projected to lose foundational security analysis skills to over-reliance on automation
Under 1% today, 10% by 2029, and Gartner’s own warning sits on the same curve: 75% of SOC teams losing foundational skills by 2030 if the automation isn’t paired with deliberate training.

Planning for that shift means building the governance now, not after the first autonomous-agent incident forces it. MITRE ATLAS, the structured knowledge base of adversary tactics against AI and machine learning systems, added new case studies in its January 2026 update specifically covering compromised MCP servers, indirect prompt injection through agent-to-agent channels, and malicious autonomous agent deployment, which is the concrete shape of the risk this trajectory is heading toward. A security team planning its 2027 roadmap should be mapping its own AI-agent attack surface against ATLAS the same way it already maps infrastructure against MITRE ATT&CK, before autonomy expands past what anyone is actively reviewing.

Free tool

Board AI Oversight Checklist

Who has override authority over an autonomous security agent, what triggers escalation, and whether that has been tested, before autonomy expands past what anyone is reviewing.

The skills gap is shifting from headcount to AI-specific expertise

ISC2’s latest workforce study, drawing on more than 16,000 cybersecurity professionals globally, found 95% reporting at least one skills need and 59% reporting a critical or significant skills gap, up 15 points on the year before. What has changed is which skill is scarcest. AI security is now the top critical-skills priority cited by respondents, at 41%, ahead of cloud security at 36%. Budget has also overtaken talent availability as the most-cited constraint: 33% of organisations say they cannot adequately staff their teams, and 29% say they cannot afford the skilled hires they’d want to make, which means the gap is not purely a training problem. It is also a resourcing decision leadership has to actually make.

The specific expertise in shortest supply is fairly concrete: people who can red-team an AI system the way ATLAS describes rather than only a traditional network, who understand how prompt injection and model inversion actually work well enough to design controls against them, and who can govern access to AI models and pipelines with the same rigour applied to a production database. None of that is exotic research-lab knowledge. It is standard security discipline, applied to a new class of system, and most teams simply haven’t had the time or budget to build it yet.

There’s a second, quieter risk sitting underneath the shortage, and it cuts the other way. Gartner projects that by 2030, 75% of SOC teams will experience erosion in foundational security analysis skills from over-dependence on automation and AI. The two risks are connected: an organisation that hires too slowly to keep pace with AI-specific threats is under pressure to lean harder on AI tooling to cover the gap, and leaning on it without deliberate investment in keeping analysts sharp is exactly what produces the erosion Gartner is warning about. Closing the skills gap and avoiding that erosion is the same project, not two separate ones: train people to understand what the AI is doing well enough to catch it when it’s wrong, rather than training them to defer to it.

A practical starting checklist

DisciplineWhat good looks likeWhat to avoid
AI access controlScoped, audited access to every AI model, pipeline, and plug-in your organisation runsTreating an AI system as exempt from the access discipline applied to a database
AI deployment in security opsStart with alert triage, enrichment, and containment, where the payoff is already documentedBuying an “AI SOC” platform without piloting what it actually automates
Shadow AI visibilityA known inventory of AI tools employees actually use, approved or notAssuming a policy document stops unapproved tool use
Agent autonomy governanceDefined override authority and escalation triggers before autonomy expandsDiscovering nobody can pull an autonomous agent back mid-incident
Skills investmentBudget for AI-specific security training, not just headcountLeaning on AI tooling to cover a hiring gap with no plan to keep analysts sharp

This has to be a standing practice, not a project with an end date

None of the individual pieces here are exotic. Access control, phased AI deployment starting where the payoff is proven, visibility into shadow AI, governance built ahead of autonomy rather than after an incident, and deliberate investment in the specific skills this shift demands, are all standard security discipline. What’s different is the pace: the WEF’s governance-maturity gap, Gartner’s autonomy timeline, and IBM’s access-control failures are all describing the same underlying problem, organisations moving fast on adoption and slow on the controls that make adoption safe.

The organisations that come out of this in a defensible position will not be the ones that adopted AI security tooling first. They’ll be the ones that treated locking down their own AI systems and building the skills to govern them as the same priority as deploying the tooling in the first place, not an afterthought to catch up on later.


Sources

  1. World Economic Forum. (2026). Global Cybersecurity Outlook 2026.
  2. IBM. (2026, July 29). IBM Study: One in Four Malicious Breaches Are AI-Enabled, Costing Companies $6 Million on Average.
  3. IBM. (2026). Cost of a Data Breach Report 2026.
  4. ISC2. (2025). Cybersecurity Skills Matter More Than Headcount in the AI Era, ISC2 Cybersecurity Workforce Study, reported via CSO Online.
  5. Gartner. (2026, February 5). Gartner Identifies the Top Cybersecurity Trends for 2026.
  6. Gartner 2026 Security & Risk Management Summit, reported via Conifers.ai. (2026). AI SOC Takeaways From Gartner’s 2026 Security Summit.
  7. MITRE. (2026, January). MITRE ATLAS, adversarial threat landscape for AI systems.

The AI Governance & ROI Executive Programme builds exactly this, access controls, AI deployment sequencing, and agent oversight, into your own security operations before autonomy expands on a system you’re accountable for. Details are on the workshops page.

Was this useful?

Terence Kok
Before You Go

The number I keep coming back to isn't the $6 million breach cost or the 56% jump in AI-enabled attacks. It's 92%, the share of AI-related breaches that happened at organisations with no proper AI access controls at all. Every other statistic in this piece is about a fast-moving threat. That one is about a door nobody locked. You do not need a bigger AI budget to fix that. You need to decide it is not optional.

Terence Kok