https://www.sans.org/mlp/ssa-security-awareness-report
The 11th annual SANS Security Awareness and Culture Report, drawing on responses from more than 1,700 security awareness practitioners across the globe, has revealed that AI has rocketed from the fourth to the second highest human risk concern in a single year, sitting just behind social engineering which remains the dominant threat at 77% of respondents. The findings paint a picture of an industry caught between rapid technological change and chronically under-resourced programs, with lack of time remaining the top challenge for the fifth consecutive year. Over 70% of security awareness teams reported adopting AI to some extent, primarily for content creation and communications, yet the report found that employees are adopting AI far faster than the policies and training designed to govern its use. Practitioners described a pattern now being called shadow AI, where staff routinely paste sensitive internal documents, customer data and source code into unauthorised public tools not out of malicious intent, but simply because the tools make their work faster and the friction of stopping to ask whether they should disappears under deadline pressure.
The report identifies three distinct AI risk categories that security teams need to address separately. The first is generative AI misuse, where employees are treating tools like ChatGPT and Gemini as authoritative sources rather than fallible assistants, bypassing critical thinking and security checks in the process. The second is vibe coding, the practice of using AI to generate and deploy software code without any programming knowledge or security review, which the report warns could expand exponentially as people discover how simple the process is. The third and most concerning is agentic AI, where automated bots act on behalf of users with little or no human oversight, potentially handling sensitive data and interacting with critical systems without any of the checks applied to human employees. The report notes that while these risks sound technical, organisations already have the foundational tools to manage them since existing data handling and access policies apply equally to AI agents as they do to people.
Beyond AI, the report reinforces a message that has been building across its 11-year history: program maturity is fundamentally a function of team size and time, not technology. Organisations need at least three dedicated full-time staff to meaningfully change workforce behaviour, and at least 4.3 to begin shifting organisational culture, with the most mature programs typically running for more than a decade with teams of six or more. Practitioners who moved away from punitive, fear-based approaches and toward positive reinforcement and peer recognition consistently reported dramatic improvements, with one organisation seeing phishing reporting rates rise nearly 40% after switching from catching failures to publicly celebrating good security behaviours.