https://www.sans.org/white-papers/2026-sans-ai-survey-insights

A major new survey from the SANS Institute has revealed that while AI adoption has surged dramatically over the past year, the governance frameworks and workforce capabilities needed to support that growth have failed to keep up. Active AI use in security strategy jumped from 50% to 78% in a single year, the largest year-over-year increase the survey has ever recorded, yet only 27% of practitioners describe their deployments as mature. More troubling still, 63% of practitioners reported significant shortcomings in AI-driven threat detection and response, up from 45% the previous year, and two thirds said AI guidance had steered them in the wrong direction at least once in the past 12 months. The survey, which gathered responses from 536 IT and security professionals globally alongside a separate cohort of 57 senior security executives, found that the industry has committed to AI at pace while quietly accumulating a debt of unresolved reliability, trust and accountability problems underneath it.

The governance picture is where the data gets particularly uncomfortable. Seventy-six percent of security teams now hold a formal governance responsibility for enterprise AI, up from 68% in 2025, yet the share with an actual formal AI risk management program barely moved, sitting at just 36%. A striking 14-point gap also emerged between leaders and practitioners when asked about governance maturity, with 50% of senior executives reporting a formal program compared to only 36% of the practitioners who would be living inside it. Researchers noted that a program invisible to the people doing the work is not functioning as governance in any meaningful sense. Compounding this, 63% of practitioners flagged a lack of visibility into where AI models are being used and what data they can access, and the growing use of AI agents and copilots operating with inherited user permissions has elevated data exposure into a core governance concern rather than a secondary one.

On the offensive side, the findings offer little comfort. Seventy-eight percent of organisations reported confirmed or suspected AI-enabled attacks in the past year, with adversaries deploying AI across phishing, vulnerability exploitation, deepfakes, automated reconnaissance and brute forcing in near-equal measure. Rather than concentrating on a single technique, threat actors appear to be integrating AI across the full attack lifecycle, leaving no single countermeasure capable of addressing the breadth of what organisations are already facing. Red team use of AI nearly doubled from 33% to 61% over the same period, reflecting how rapidly offensive tooling is evolving on both sides of the fence. The survey’s authors concluded that the next 12 months will test whether organisations can close the readiness gap against the deployment pace they have already committed to, and that those treating AI adoption as a finish line rather than a starting point are handing adversaries a standing advantage.

Discover more from Edwin Kwan

Subscribe now to keep reading and get access to the full archive.

Continue reading