121 AI in Cybersecurity Statistics for 2026

AI is now used in cybersecurity by both attackers and defenders. Attackers use it to write phishing emails, build malware and run intrusions faster. Defenders use it to detect threats, triage alerts and patch code. Here are 121 statistics that show where things stand in 2026.

Top AI in Cybersecurity Statistics

How Many Organizations Use AI in Cybersecurity?

The answer depends on what you measure. Surveys report different adoption rates depending on whether they count security toolkits, full SOC teams or individual practitioners.

1. Generative AI now plays a role in 77% of security stacks, according to a 2026 survey of more than 1,500 security leaders and practitioners (Darktrace, State of AI Cybersecurity 2026).

2. 40% of security teams run AI in their security operations centre today, 56% are evaluating or piloting it, and 4% have ruled it out (Prophet Security, State of AI in the SOC 2026).

3. 78% of security practitioners now use AI as part of their security strategy, up from 50% in 2025 (SANS Institute, 2026 AI Survey, via Industrial Cyber).

How mature are those AI deployments?

4. Only 27% of security practitioners describe their AI deployment as mature production (SANS Institute, 2026 AI Survey).

5. Another 33% of security practitioners call their AI deployment early production and 21% are still experimenting (SANS Institute, 2026 AI Survey, via Industrial Cyber).

6. Only 43% of security operations centres have an AI adoption strategy in place (SOC-CMM, 2026 SOC Maturity Report).

7. 18% of security operations centres now use AI agents, a 118% increase year over year (SOC-CMM, 2026 SOC Maturity Report).

Source: SOC-CMM, 2026 SOC Maturity Report, p. 44, around 200 SOCs surveyed

8. Only 14% of security professionals allow AI to take independent remediation actions in the SOC with no human in the loop (Darktrace, State of AI Cybersecurity 2026).

What do security teams actually use AI for?

9. Incident investigation is the most common AI use case in security operations, cited by 47% of practitioners (SANS Institute, 2026 AI Survey, via Industrial Cyber).

10. Log analysis is the most common generative-AI task in security teams at 56% of practitioners, while threat hunting is among the least common at 23% (SANS Institute, 2026 AI Survey, via Industrial Cyber).

11. 47% of security professionals name vulnerability management as an area where AI is having the greatest impact (Darktrace, State of AI Cybersecurity 2026: Cybersecurity Tools).

12. Among the half of organizations that have a security operations centre and have deployed AI agents in it, 56% use those agents for threat hunting and 54% for automated response and containment, against just 18% for vulnerability scans and management (IBM, Cost of a Data Breach Report 2026, Figure 37).

13. 61% of security practitioners now use AI in red team work (SANS Institute, 2026 AI Survey).

14. Security analysts spend an average of 8.6 hours a week overseeing AI outputs (Torq, 2026 AI SOC Leadership Report).

15. 97% of CISOs and security leaders are confident AI can handle triage, but only 35% are actually using it for that (Torq, 2026 AI SOC Leadership Report).

High confidence paired with low actual deployment suggests many teams have not yet moved AI triage from testing to production.

Where is AI adoption heading?

16. Gartner forecasts that by 2028, 70% of large security operations centres will pilot AI agents for Tier 1 and Tier 2 work, but only 15% will achieve measurable improvements without structured evaluation (Gartner, “Validate the Promises of AI SOC Agents”, via Help Net Security).

17. Gartner predicts more than 75% of enterprises will use AI-amplified cybersecurity products for most security use cases by 2028, up from less than 25% in 2025 (Gartner, information security spending forecast).

18. 65% of organizations list adding AI-powered security tools among their top priorities over the next 12 months for defending against AI-powered threats (Darktrace, State of AI Cybersecurity 2026: Cybersecurity Tools).

AI in Cybersecurity Market Size and Spending

Three different markets overlap in this section: total cybersecurity spending, AI applied to security and securing AI itself. The numbers below are not comparable across those categories.

19. Global security spending is projected to reach $308 billion in 2026, growing 11.8% year over year (IDC, Worldwide Security Spending Guide).

20. IDC forecasts global security spending will reach $430 billion by 2029 (IDC, Worldwide Security Spending Guide).

21. The United States will lead worldwide security spending in 2026 at $150 billion, followed by Western Europe at $69 billion and Asia/Pacific excluding Japan and China at $26 billion (IDC, Worldwide Security Spending Guide).

22. Security software is the fastest-growing technology group in 2026 at 14% year-over-year growth and accounts for more than 50% of total security spending (IDC, Worldwide Security Spending Guide).

How big is the market for securing AI itself?

23. The market for securing AI is projected to reach almost $4.8 billion in 2027, a 68.7% increase over 2026 (Gartner, securing AI forecast).

24. Gartner forecasts the securing AI market will reach almost $7.7 billion by 2028 (Gartner, securing AI forecast).

25. Within the securing AI market, Gartner forecasts 2027 spending of $851 million on AI application security, $749 million on AI usage control, $462 million on AI governance platforms, $429 million on AI gateways and $2,292 million on other securing AI products (Gartner, securing AI forecast).

Source: Gartner, Forecast: Information Security and Risk Management, Worldwide, 2022–2028, Table 1

26. According to MarketsandMarkets, the AI in cybersecurity market is valued at $25.53 billion in 2026 and is expected to reach $50.83 billion by 2031, a CAGR of 14.8% (MarketsandMarkets).

How much money is going into security startups?

Funding data below spans different time windows and startup categories.

27. Startups at the intersection of AI and security raised $855 million across more than 150 reported seed-stage rounds in 2026 through late July (Crunchbase News, AI Seed Investors Flock To Cybersecurity).

28. Privacy and cybersecurity startups raised $10.6 billion across all stages in the first half of 2026, including $4.4 billion in the second quarter (Crunchbase News, cybersecurity startup funding in H1 2026).

29. 75 cybersecurity M&A transactions were announced in the first quarter of 2026, with disclosed deal value of $2.2 billion (Kroll, Cybersecurity M&A Industry Insights, Spring 2026).

30. Overall cyber spending grew 12% in 2025, well above the 7% that had been expected, and more than 80% of surveyed security leaders plan to keep increasing budgets into 2027 (BCG).

What is actually driving security spending?

31. Investing in AI-powered security solutions is the most cited factor driving cybersecurity spending, named by 54.1% of security leaders (Wiz, The 2026 CISO Budget Benchmark).

32. Countering AI-driven threats ranks third among factors driving cybersecurity spending, named by 46.9% of security leaders (Wiz, The 2026 CISO Budget Benchmark).

33. 45% of security leaders say AI is already having a significant impact on their cloud security defences, 55% expect it eventually, and 0% say it never will (Wiz, The 2026 CISO Budget Benchmark).

AI-Powered Phishing, Deepfakes and Social Engineering

Phishing is where AI-powered attacks have the clearest track record so far.

34. 78% of organizations reported confirmed or suspected AI-enabled attacks in the past year, and 95% of respondents believe threat actors are using AI (SANS Institute, 2026 AI Survey).

35. 86% of phishing attacks observed over a six-month period were AI-driven, across more than 3,000 unique threat actors, in research published in April 2026 (KnowBe4, Phishing Threat Trends Report Volume Seven).

Are AI-generated phishing emails more effective than human-written ones?

36. Fully AI-automated spear-phishing emails achieved a 54% click-through rate against study participants, matching human expert phishers and beating a 12% control group (Heiding et al., arXiv).

37. An automated large-language-model tool produced target reconnaissance that was accurate and useful in 88% of cases, and inaccurate for only 4% of participants (Heiding et al., arXiv).

These two results and the next two measure different things. The first comes from a controlled lab trial comparing AI to a single human expert. The second comes from large-scale phishing simulations benchmarked against elite red teams.

38. In a March 2025 test, AI-generated phishing simulations were 24% more effective than those written by elite human red teams (Hoxhunt).

39. AI phishing performance relative to elite human red teams improved by 55% between 2023 and 2025, from 31% less effective than those teams in 2023 (Hoxhunt).

How much money are AI-assisted scams taking?

40. The FBI’s Internet Crime Complaint Center logged 22,364 complaints referencing AI in 2025, with adjusted losses of $893,346,472 (FBI, IC3 2025 Internet Crime Report).

41. Investment-fraud complaints with a reported AI nexus accounted for more than $632 million in 2025 losses reported to the FBI, out of more than $8 billion lost to investment scams overall (FBI, IC3 2025 Internet Crime Report).

42. Businesses reported more than $30 million in 2025 losses to business email compromise scams involving AI (FBI, IC3 2025 Internet Crime Report).

How common are deepfake attacks?

43. Deepfakes accounted for one in five biometric fraud attempts on Entrust’s identity-verification platform in the year to September 2025 (Entrust, 2026 Identity Fraud Report).

44. Deepfaked selfie attempts rose 58% in 2025 on Entrust’s identity-verification platform (Entrust, 2026 Identity Fraud Report).

45. Researchers verified 821 deepfake attacks in the first half of 2026, drawn from 1,760 news reports (Resemble AI, H1 2026 Deepfake Threat Report).

46. Verified direct financial losses from deepfake incidents catalogued in the first half of 2026 totalled $6.95 million (Resemble AI, H1 2026 Deepfake Threat Report).

That figure only counts losses that researchers could verify from public reporting.

Voice phishing is also rising, though the next metric tracks all voice-based social engineering, not only deepfakes.

47. CrowdStrike observed vishing intrusions rising 2x in the first half of 2026 against the second half of 2025 (CrowdStrike, 2026 Threat Hunting Report).

Can people spot a deepfake?

48. Across 56 studies covering 86,155 participants, people detected deepfakes with 55.54% accuracy, which the authors found was not significantly better than chance (Diel et al., Computers in Human Behavior Reports).

Source: Diel et al., Computers in Human Behavior Reports, Vol. 16, 2024, meta-analysis of 56 studies, 86,155 participants

AI-Powered Malware and Autonomous Attacks

Beyond phishing, AI is shaping how malware gets built and how quickly intrusions move.

49. CrowdStrike observed 89% more attacks by AI-enabled adversaries in 2025 than in 2024 (CrowdStrike, 2026 Global Threat Report).

50. CrowdStrike observed adversaries abusing legitimate generative-AI tools inside more than 90 organizations in 2025, injecting malicious prompts to generate credential- and cryptocurrency-stealing commands (CrowdStrike, 2026 Global Threat Report).

How fast do intrusions move now?

51. The average eCrime breakout time CrowdStrike observed fell to 29 minutes in 2025, 65% faster than in 2024 (CrowdStrike, 2026 Global Threat Report).

52. The fastest breakout time CrowdStrike observed in 2025 was 27 seconds (CrowdStrike, 2026 Global Threat Report).

53. 88% of CrowdStrike-observed exploitation of vulnerabilities with a public proof-of-concept happened within 48 hours of that proof-of-concept going live, in the first half of 2026 (CrowdStrike, 2026 Threat Hunting Report).

54. CrowdStrike observed zero-days exploited before public disclosure rising 42% year over year in 2025 (CrowdStrike, 2026 Global Threat Report).

55. In one case investigated by Unit 42, an attacker running an automated AI loop compressed weeks of intrusion tradecraft, using more than 50 MITRE ATT&CK techniques, into less than 10 hours (Unit 42, Palo Alto Networks).

56. In the second quarter of 2026, Google’s threat intelligence team watched attackers move from compromising a cloud resource to running an agent-enabled mass credential harvesting campaign in under six hours (Google Threat Intelligence Group, AI Threat Tracker September 2026).

Are attacks running themselves yet?

57. In the GTG-1002 espionage campaign, AI executed roughly 80 to 90 percent of all tactical work independently, with humans left in a supervisory role (Anthropic, Disrupting the first AI-orchestrated cyber espionage campaign).

58. The GTG-1002 campaign, which Anthropic attributes with high confidence to a Chinese state-sponsored group, targeted roughly 30 entities, with a handful of intrusions confirmed successful (Anthropic, Disrupting the first AI-orchestrated cyber espionage campaign).

59. An exposed agentic command-and-control framework found by Google was built to organize, validate and manage more than 23,800 harvested secrets in real time, including API keys for cloud and AI services (Google Threat Intelligence Group, AI Threat Tracker September 2026).

60. One actor tracked by Anthropic dumped more than 2,100 Azure AD token sets across more than 40 corporate tenants in about 34 hours (Anthropic, Countering misuse of AI: September 2026).

61. A single extortion actor using an AI coding agent hit at least 17 organizations and demanded ransoms that sometimes exceeded $500,000 (Anthropic, Detecting and countering misuse of AI: August 2025).

Can AI write malware?

62. Google’s threat intelligence team documented five malware families with novel AI capabilities in 2025 — FRUITSHELL, PROMPTFLUX, PROMPTLOCK, PROMPTSTEAL and QUIETVAULT — three of them seen in live operations and two still experimental (Google Threat Intelligence Group, AI Threat Tracker November 2025).

63. One week into the project, the AI-built VoidLink malware framework had already grown past 88,000 lines of code (Check Point Research).

64. A single LLMjacking campaign generated nearly 200,000 API requests in two minutes (CrowdStrike, 2026 Threat Hunting Report).

Who is doing this?

65. Google identified state-backed threat groups from more than 20 countries using Gemini, with the highest volume of usage coming from Iran and China (Google Threat Intelligence Group, January 2025).

66. OpenAI has disrupted and reported more than 40 networks violating its usage policies since it began public threat reporting in February 2024 (OpenAI, Disrupting malicious uses of AI: October 2025).

AI on Defense: Detection, Investigation and Vulnerability Discovery

Defenders are using AI too. Early results from controlled trials and production deployments show measurable gains in speed and accuracy.

67. Among security teams already using AI, 72% said it cut alert investigation time by 25% or more, and 18% reported a reduction of more than half (Prophet Security, State of AI in the SOC 2026).

68. In a randomized controlled trial with 167 security analysts, analysts working with Microsoft’s Security Copilot phishing triage agent produced up to 6.5 times as many true positives per analyst minute as a control group, and 77% better verdict accuracy (Bono, Microsoft, arXiv).

69. In a 2024 randomized controlled trial of 147 experienced security professionals, those using an AI security assistant finished the task set 22% faster and were 7% more accurate (Microsoft, Randomized Controlled Trial for Copilot for Security).

70. A multi-agent large-language-model triage system cut the false-positive rate from 24.9% to 14.2% against the strongest single-agent baseline on production security-operations workflows (Wei et al., CORTEX, arXiv).

These results come from different settings: a practitioner survey, two controlled trials and a production deployment. That mix is worth keeping in mind when comparing them. The next set measures AI against a different task: finding and fixing vulnerabilities in code.

Can AI find and fix vulnerabilities on its own?

71. In DARPA’s AI Cyber Challenge final, autonomous systems identified 86% of the planted vulnerabilities, up from 37% at the semifinals, and patched 68% of the 63 (DARPA, AI Cyber Challenge final results).

72. Teams’ autonomous systems in DARPA’s AI Cyber Challenge submitted patches in an average of 45 minutes (DARPA, AI Cyber Challenge final results).

73. Beyond the planted bugs, the systems discovered 18 real vulnerabilities in open source software and produced 11 patches for them (DARPA, AI Cyber Challenge final results).

74. Google DeepMind’s CodeMender agent upstreamed 72 security fixes to open source projects in its first six months, including to projects as large as 4.5 million lines of code (Google DeepMind).

75. Autonomous AI agents submitted more than 560 valid vulnerability reports on HackerOne over the 12 months to June 2025 (HackerOne, 9th Annual Hacker-Powered Security Report).

76. 70% of surveyed security researchers now use AI tools in their workflow (HackerOne, 9th Annual Hacker-Powered Security Report).

Where is AI still falling short?

77. 63% of security practitioners reported significant AI shortcomings in threat detection and response in 2026 (SANS Institute, 2026 AI Survey).

78. 76% of security practitioners now hold a governance role for enterprise AI, but more than half say no formal audit frameworks exist to back it up (SANS Institute, 2026 AI Survey).

Data Breach Costs and AI

Data breaches are getting more expensive. AI shows up on both the cost and the savings side of the ledger.

79. The global average cost of a data breach reached a record $4.99 million in 2026, a 12% rise over the prior year (IBM, Cost of a Data Breach Report 2026).

80. Organizations in the United States recorded the highest average breach cost of any country or region studied, at a record $11.5 million (IBM, Cost of a Data Breach Report 2026).

81. Losses reported to the FBI’s Internet Crime Complaint Center reached $20.877 billion in 2025, across 1,008,597 complaints (FBI, IC3 2025 Annual Report).

Does AI actually reduce breach costs?

82. Organizations making extensive use of security AI and automation averaged $4.00 million per breach against $5.93 million for those using none, a gap IBM puts at $1.93 million (IBM, Cost of a Data Breach Report 2026).

Source: IBM, Cost of a Data Breach Report 2026, Figure 34, 602 breached organizations

83. Breached organizations using security AI and automation extensively identified and contained breaches in 215 days, against 280 days for those not using them at all (IBM, Cost of a Data Breach Report 2026).

84. Across all breached organizations, the average breach lifecycle was 247 days in 2026 — 183 days to identify and 64 days to contain (IBM, Cost of a Data Breach Report 2026).

What do AI-related breaches cost?

Two types of AI-related breach show up in the data below. The first is attacks where threat actors used AI as a tool. The second is breaches that targeted an organization’s own AI systems.

85. Malicious breaches driven by AI averaged $6.04 million against $5.03 million for malicious breaches without AI, which IBM describes as AI adding $1 million to the average malicious breach (IBM, Cost of a Data Breach Report 2026).

86. Breaches involving model inversion were the costliest AI-related type at $6.07 million, followed by prompt injection at $5.89 million (IBM, Cost of a Data Breach Report 2026).

Source: IBM, Cost of a Data Breach Report 2026, Figure 27, organizations reporting an AI-related incident

How does ransomware fit in?

87. 39% of breached organizations reported their systems were hit by ransomware in 2026, continuing a four-year rise from 24% in 2023 (IBM, Cost of a Data Breach Report 2026).

88. Organizations hit by ransomware reported an average recovery cost of $1.7 million per incident in 2026, up 11% year over year (Sophos, The State of Ransomware 2026).

89. The median ransom payment fell to $769,000 in 2026 from $1 million a year earlier, with 48% of victims whose data was encrypted paying up (Sophos, The State of Ransomware 2026).

On-chain payments and survey-reported costs measure different things. The next figure tracks confirmed blockchain transactions across the ransomware ecosystem, not individual survey responses.

90. Ransomware operators received more than $820 million in on-chain payments during 2025, an 8% decline from the prior year (Chainalysis, 2026 Crypto Crime Report).

Shadow AI and GenAI Data Risk

Employees adopt AI tools faster than their organizations can write policies for them.

What is shadow AI and how common is it?

91. Security incidents involving shadow AI, meaning employees using unapproved AI tools, rose to 43% in 2026 from 20% a year earlier, and carried an average breach cost of $5.39 million (IBM, Cost of a Data Breach Report 2026).

92. The average organization logged 223 generative-AI data policy violations a month in the 13 months to October 2025, while the top 25% averaged 2,100 (Netskope, Cloud and Threat Report 2026).

93. 47% of enterprise generative-AI users were still using personal AI accounts at work in the 13 months to October 2025, down from 78% a year earlier (Netskope, Cloud and Threat Report 2026).

94. ChatGPT alone triggered 410 million data loss prevention policy violations across enterprise traffic in 2025 (Zscaler ThreatLabz, 2026 AI Security Report).

95. 16.9% of sensitive data exposures in enterprise generative-AI use happened through personal accounts, across a dataset of 22,458,240 prompts sent in 2025 (Harmonic Security, AI Usage Index 2025).

Are organizations governing AI use at all?

96. 64% of organizations had a process to assess the security of AI tools before deploying them in 2026, up from 37% in 2025 (World Economic Forum, Global Cybersecurity Outlook 2026).

97. 87% of cybersecurity leaders named AI-related vulnerabilities the fastest-growing cyber risk of 2025 (World Economic Forum, Global Cybersecurity Outlook 2026).

98. Data leaks from generative AI are now the leading AI concern for security leaders at 34%, ahead of adversarial capabilities at 29% — a reversal from 2025, when adversarial capabilities led at 47% against 22% for genAI data leaks (World Economic Forum, Global Cybersecurity Outlook 2026).

Source: World Economic Forum, Global Cybersecurity Outlook 2026, Figure 9, 804 respondents

AI as an Attack Surface: Models, Agents and MCP

AI systems themselves are now targets. Organizations that deploy models, agents and orchestration layers create new attack surface in the process.

99. 21% of breached organizations reported a security incident involving one of their own AI models or applications in 2026, up from 13% the year before, and 92% of them lacked proper AI access controls (IBM, Cost of a Data Breach Report 2026).

100. 2,130 AI-related vulnerabilities were disclosed in 2025, a 34.6% year-over-year increase (Trend Micro, TrendAI State of AI Security Report).

Are AI agents a new attack surface?

101. At least 57% of organizations have deployed self-hosted AI agent technologies (Wiz Research, State of AI in the Cloud 2026).

102. 80% of the cloud environments Wiz observed had Model Context Protocol servers running in them (Wiz Research, State of AI in the Cloud 2026).

103. Trend Micro found 1,467 exposed Model Context Protocol servers on the public internet, 1,227 of them running the long-deprecated Server-Sent Events transport (Trend Micro, TrendAI State of AI Security Report).

104. 68% of organizations that run self-hosted AI models pull those models in through third-party software (Wiz Research, State of AI in the Cloud 2026).

105. The AI Incident Database logged 148 new AI incidents between May and July 2026, covering incidents 1471 through 1618 (AI Incident Database).

Cybersecurity Jobs, Skills and AI

The cybersecurity workforce is changing. AI is reshaping which skills employers want and which roles they hire for.

Will AI replace cybersecurity jobs?

106. 56% of cybersecurity professionals who use AI say it has reduced the need for entry-level roles, while 53% say it is creating new entry-level opportunities (ISC2, Rethinking AI’s Impact on Cybersecurity Roles).

107. Senior-titled cybersecurity postings across the G7 grew 65.0% in October 2025 through March 2026, while junior-titled postings grew 5.9% (AI Workforce Consortium).

108. US employment of information security analysts is projected to grow 21% from 2025 to 2035, adding 40,600 jobs to a 2025 base of 192,900 (U.S. Bureau of Labor Statistics).

109. 73% of cybersecurity professionals say AI will create the need for more specialized cybersecurity skills (ISC2, 2025 Cybersecurity Workforce Study).

How big is the cybersecurity workforce, really?

110. ISC2 stopped publishing an estimate of the global cybersecurity workforce gap in its 2025 study (ISC2, 2025 Cybersecurity Workforce Study).

111. CyberSeek’s first global cybersecurity employment baseline put the worldwide workforce at an estimated 4,970,000 people in 2025, within a range of 4.4 million to 5.5 million (CyberSeek).

112. US employers posted 514,359 cybersecurity job listings in the 12 months from May 2024 through April 2025 (CyberSeek).

113. The CyberSeek supply-demand ratio for the US cybersecurity workforce stood at 74% for the 12 months ending April 2025 (CyberSeek).

Is AI now a required cybersecurity skill?

114. 28.5% of G7 cybersecurity job postings required AI skills between October 2025 and March 2026, twice the 14.2% share of a year earlier (AI Workforce Consortium).

115. AI was the most pressing skills need inside security teams in 2025, cited by 41% of respondents, ahead of cloud security at 36% (ISC2, 2025 Cybersecurity Workforce Study).

116. 33% of digital trust professionals say their organization trains all employees on AI, up from 22% a year earlier (ISACA, 2026 AI Pulse Poll).

117. Job postings that require AI skills advertise salaries 28% higher, nearly $18,000 more a year, across all occupations in Lightcast’s global postings data (Lightcast).

118. 25% of organizations are turning to AI and automation to mitigate their cybersecurity skills shortage (ISC2, 2025 Cybersecurity Workforce Study).

What is AI doing to the people who run security?

119. 65% of cybersecurity professionals using AI spent more time in the past year deciding when to trust AI-generated recommendations, and 63% spent more time validating AI outputs (ISC2, Rethinking AI’s Impact on Cybersecurity Roles).

120. 66% of cybersecurity professionals say their role is more stressful now than it was five years ago (ISACA, State of Cybersecurity 2025).

121. 39% of organizations imposed cybersecurity hiring freezes in the 12 months to 2025, roughly flat on the prior year (ISC2, 2025 Cybersecurity Workforce Study).

Conclusion

Every major survey and threat report now includes an AI section, and many of the numbers above appeared for the first time this year. The data is still catching up to how fast the technology is moving. One thing is clear: the organizations that track and govern their AI use are in a better position than those that do not. We will update this page as new data comes out.