Cybersecurity: Governance Tools Haven’t Kept Up with AI Use

by John Jenkins

July 23, 2026

According to a 2026 SANS Institute survey on AI use in cybersecurity, the use of AI tools in cybersecurity applications has skyrocketed, but governance controls haven’t kept up. This excerpt from SANS’s press release announcing the report explains:

Security teams adopted AI faster in 2026 than in any year before, and the governance and workforce structures meant to support that adoption have not caught up. SANS Institute’s 2026 AI Survey Insights report gives an honest read of where the field is, not where it hopes to be. The report draws on responses from 536 cybersecurity and IT practitioners globally alongside a dedicated module completed by 57 senior security leaders, including CISOs, CSOs, and security vice presidents.

“For two years now, we’ve asked security teams where they actually stand with AI,” said Matt Bromiley, the report’s author and a SANS Certified Instructor. “Both years, the honest answer has been some version of moving fast and working it out as we go. What’s changed in 2026 is how much weight is now sitting behind that answer.”

Red teaming moved from minority to majority practice in a single year: 61% of practitioners now use AI in red team work, up from 33% in 2025. Investigation, response, and application security have kept pace, treated as part of daily operations rather than something teams can shelve if results disappoint. Even so, just 27% of practitioners call their deployment mature production; most are still piloting AI or running it in a supporting role.

Security teams are taking on more governance duties than their infrastructure can support. 76% now hold a governance role for enterprise AI, but more than half say no formal audit frameworks exist to back it up. That shortfall tracks with what practitioners are seeing in production: 63% report significant AI shortcomings in threat detection and response, up from 45% in 2025.

The report also found that the bad guys are exploiting this gap and are using AI tools throughout each stage of the attack life cycle. It says that 78% of organizations reported confirmed or suspected AI-enabled attacks in the past year, and 95% of respondents believe threat actors are using AI.