2026 Survey: Why Humans Still Outrank AI Defenses

The 2026 SANS AI Survey: Why AI-Enabled Attacks Still Need a Skeptical Human Analyst

Security teams handed a growing share of their daily workload to generative AI this year, and the tools let them down often enough that practitioners noticed. The 2026 SANS AI Survey, drawn from 536 IT and security professionals, puts a number on both sides of that trade: adoption is up, reliability has not caught up to it, and the professionals closest to the problem are converging on an old answer to a new question — a trained, skeptical human still catches what the model misses.

The survey lands at an inflection point. Generative AI moved from pilot projects to daily production use across security operations centers in the span of about a year, taking on log triage, alert summarization, vulnerability prioritization, and incident write-ups.

At the same time, 78% of organizations reported AI-enabled attacks against them, with under half of those confirmed through forensic evidence and the rest still sitting in the suspected column. Kiteworks tracks this same tension in enterprise data environments: the faster organizations adopt AI, the more exposed they become to ungoverned data flows, unverified content reaching models, and decisions made on context nobody checked. The SANS findings describe the security operations version of that same problem.

What the survey measured, and what a working incident responder told Help Net Security about applying it under pressure, points to a question every security and data governance team is now facing: how do you calibrate trust in a tool that’s usually right but occasionally, confidently, wrong?

Kiteworks secure data exchange addresses a related but distinct piece of that problem. When AI systems — SOC copilots or autonomous agents — reason over sensitive content, someone needs to have verified that content first, controlled who and what can access it, and logged the whole chain, instead of just assuming it’s trustworthy.

Key Takeaways

1. AI adoption in security operations jumped sharply, but trust didn’t keep pace.

Active generative AI use among security practitioners reached 78% in 2026, up from roughly half the field a year earlier, while 63% now report significant shortcomings in AI-driven threat detection and response.

2. AI-enabled attacks now touch most organizations.

The 2026 SANS AI Survey found 78% of organizations detected AI-enabled attacks in the past year, with 45% confirmed and another 33% suspected but unproven.

3. Two-thirds of practitioners have been misled by AI guidance at least once in the past year.

Nine percent said it happened more than twenty times, a reminder of how often confident-sounding AI output turns out to be wrong.

4. Attacker speed, not attacker sophistication, is what’s compressing defender response time.

AI-assisted intrusions can move from initial foothold to lateral movement within minutes, eliminating the dwell time that detection thresholds and on-call rotations are built around.

5. Practitioners rank human-centered controls above AI-specific tools for stopping AI-enabled threats.

Behavioral detection, security awareness training, human analyst review, and zero trust architecture all outrank specialized AI defenses in the survey’s effectiveness rankings.

You Trust Your Organization is Secure. But Can You Verify It?

Read Now

Adoption Outpacing Reliability: The Trust Gap Security Teams Can’t Ignore

The headline adoption number is stark on its own. Active use of generative AI in cybersecurity work reached 78% of practitioners in 2026, up from about half the field a year earlier. In practical terms, that means most security teams now run some portion of their daily workflow through an AI layer, whether that’s a copilot summarizing an alert queue, a model scoring vulnerability severity, or an assistant drafting the first pass of an incident report.

Reliability did not keep pace with that growth. Sixty-three percent of practitioners report significant shortcomings when AI detects or responds to threats, a share well above what the same survey found a year earlier. The failures aren’t random noise — they cluster around three recurring patterns: false positives that waste analyst time, difficulty recognizing novel or unfamiliar threats that don’t match training data, and confidently delivered output that turns out to be simply wrong.

Matt Bromiley, a SANS certified instructor and incident responder, described where practitioners have learned to draw the line. “Our data shows practitioners are comfortable letting AI classify threats or prioritize vulnerabilities, and far less comfortable letting it confirm a true positive or judge behavioral anomalies,” he told Help Net Security.

That distinction matters: it separates tasks with a large, well-labeled training corpus from judgment calls that depend on context an AI model rarely has full visibility into. “These tools track that they are good at structured problems and weak at novel, context-dependent calls,” Bromiley said. “You build the instinct by learning a tool’s failure profile and verifying in proportion to what being wrong costs you.”

That instinct — knowing when a model’s confidence should be trusted and when it should be checked — is exactly the skill the survey suggests the industry hasn’t scaled fast enough. Adoption outran the security awareness training and risk assessment work needed to use these tools safely, and the gap shows up directly in the misdirection numbers below.

When AI Guidance Misleads: The Cost of Confident Wrong Answers

One survey respondent compared working with AI tools to managing a digital intern — useful, occasionally sharp, but requiring a second set of eyes before anything goes out the door. Bromiley put himself in the same camp. “I cannot agree more with this: ‘measure twice, cut once,'” he said. “Unfortunately, most teams aren’t instrumented to build that instinct.”

The scale of the problem backs up the metaphor. Two-thirds of practitioners have been misdirected by AI guidance at least once in the past year, and 9% said it happened more than twenty times. That is not a story about AI being unhelpful. It is a story about AI being confidently wrong often enough that verification must be built into the workflow rather than left to individual judgment.

Confidently wrong output is a particular hazard in security operations because the cost of acting on it isn’t symmetric. A false positive wastes an hour. A missed true positive, confirmed instead as benign by an AI system nobody double-checked, can leave an active intrusion running for days. The resulting data breach exposure — particularly for organizations handling PII, PHI, or regulated financial records — compounds the security failure with regulatory notification and remediation obligations that run on their own timeline.

Part of the underlying issue is data provenance: models generate confident answers from whatever context they’re given, and if that context is incomplete, stale, or drawn from unverified sources, the output looks just as authoritative as it would from clean data. This is where data governance and audit trail practices intersect with AI reliability — an analyst can calibrate trust in a model’s output more easily when they can trace exactly what data the model saw and confirm nothing in that chain was tampered with, misclassified, or simply wrong to begin with. Where that traceability doesn’t exist, teams are left calibrating trust in the output alone, with no way to check the input.

Bromiley’s training argument extends this point. “As an instructor, I can attest that the classroom does more than people give it credit for,” he said. “You can teach failure modes, instrumentation, what to verify before acting, and how to run a system in parallel long enough to see where it drifts. What you can’t lecture into someone is calibration, meaning how much doubt a given output has earned. Good training just compresses those reps into a place where being wrong is cheap.” Training builds the checklist. Only experience — ideally supervised, low-stakes experience — builds the judgment to apply it under pressure.

The Compressed Timeline: How AI-Assisted Attacks Erase Defender Dwell Time

The offensive side of the survey puts a deadline on all of this. Bromiley described an incident where the defining factor wasn’t the attacker’s technique — it was tempo. “I worked at one where the tempo was what caught us off guard,” he said.

The intrusion began as a supply chain risk management failure: a malicious package compromised through the software supply chain gave the attacker a foothold inside a trusted software environment. From there, the intrusion moved from internal reconnaissance to lateral movement within minutes, with the adversary deploying scripts in quick succession. “The pace felt fast — the adversary was also bringing in scripts that were clearly commented and had good step-through instructions, matching the hallmark traits of a ‘friendly AI-developed script,'” Bromiley said.

He was careful about how far to take that read. “I’d be careful about the attribution. We assessed those scripts as likely AI-generated based on their structure and the speed of iteration, not because we recovered proof,” he said.

That distinction lines up with how the survey itself frames the numbers: of the 78% of organizations reporting AI-enabled attacks, 45% confirmed it through evidence and 33% only suspected it.

Bromiley’s case sits in the second group — a reasonable inference, not a forensic certainty, and the survey’s authors are explicit about keeping that line intact.

What he wants defenders to internalize isn’t the attribution question — it’s the math. “What changed was cadence. Recon-to-lateral-movement usually buys defenders time because it’s slow and manual. Here, it bought very little time,” Bromiley said. “Detection thresholds and on-call rotations assume some attacker dwell, and that assumption is what is compressed.” 

Reconnaissance-to-lateral-movement is normally the slowest, most manual stage of an intrusion, and the delay it introduces is the window a security team typically uses to catch up. Remove that delay and the margin for error disappears with it.

Advanced persistent threats built around AI-assisted tooling don’t need a novel technique to be dangerous — they just need to move faster than the response process was built to handle. A SIEM platform ingesting real-time egress and lateral movement telemetry is the detection layer that converts compressed dwell time from an insurmountable speed disadvantage into a visible, alertable signal.

What Practitioners Trust: Behavioral Detection, Human Review, and Zero Trust Win

Looking back at the incident, Bromiley listed what the team wished it had in place before the first alert fired. “They wanted an accurate inventory of their software supply chain, egress logging that made the recon stage visible in real time, and service accounts scoped so the foothold couldn’t reach as far as it had, which aligns with survey results,” he said.

Those three priorities map directly onto what the broader survey found when it asked practitioners to rank the controls they trust most against AI-enabled threats. Behavioral detection, security awareness training, human analyst review, and zero trust architecture rank at the top. Specialized AI-specific tooling ranks last. “Behavioral detection works because it watches what an attacker does, not what the script wrote,” Bromiley said. “Speed doesn’t require a novel countermeasure; rather, it removes the slack that lets teams improvise past a missing one.”

The pattern here is consistent: defenders trust controls that constrain what an attacker — human or AI-assisted — can actually do inside an environment, over controls that try to out-analyze the attacker’s tooling.

An access controls model built on least privilege and role-based access control limits how far a compromised service account can travel regardless of how fast the attacker moves. Attribute-based access control (ABAC) adds the context-awareness layer that RBAC alone cannot provide: access decisions that evaluate content sensitivity, user role, and device posture simultaneously at the moment of each request, so a compromised account operating outside its normal behavioral profile triggers a policy block rather than inheriting the full scope of its standing permissions.

Third-party risk management practices that maintain an accurate software supply chain inventory close the exact gap that let Bromiley’s malicious package in undetected. None of these are AI-specific defenses. They are foundational security controls that happen to hold up regardless of whether the attacker on the other side is a person or a script.

Building Calibrated Skepticism: Training, Governance, and the Human-in-the-Loop

The survey’s central finding, distilled, is that the industry has a calibration problem, not an intelligence problem. AI systems are good enough to be trusted with structured, well-bounded tasks and not yet good enough to be trusted with judgment calls that depend on full context. The practitioners who navigate this well aren’t the ones avoiding AI — they’re the ones who’ve learned, often the hard way, which outputs need a second look and which don’t.

That calibration doesn’t happen in a vacuum. It depends on the analyst being able to see what the AI saw: what data fed the model, whether that data was current and verified, and who else touched it before the model reasoned over it.

This is where governance stops being a compliance exercise and becomes a reliability tool. AI data governance that enforces policy at the point where content reaches a model — rather than after the fact — reduces the odds that an AI system generates a confident answer from stale, unauthorized, or tampered data in the first place.

Data classification applied to the content AI systems can access is the prerequisite control: a governance layer cannot enforce differentiated access policies on data it has not categorized. Kiteworks Compliant AI applies exactly this kind of control at the data-to-AI boundary. It filters and governs what content generative and agentic systems can reach, so the answer an analyst sees is built on content someone actually verified, not whatever the model happened to find.

The same principle extends to agentic AI. As security teams begin connecting AI agents directly to internal systems and data stores through protocols like MCP, the calibration challenge Bromiley describes doesn’t go away — it compounds, because an agent acting on bad context can take action, not just offer advice.

A Secure MCP Server that governs what an agent can read, logs every access, and enforces the same policy controls that apply to human users gives security teams a way to extend calibrated trust to autonomous systems the same way Bromiley describes building it in human analysts: by knowing the failure profile, instrumenting for it, and verifying in proportion to what being wrong costs.

Closing the Readiness Gap: Governance as the Missing Layer

The survey’s authors frame the next 12 months as a test of whether organizations can close the readiness gap against the AI deployment they’ve already committed to. Three priorities stand out: validation that actually tracks precision and recall rather than vendor claims, governance moved into the controls analysts touch every day rather than left in policy documents, and workforce development treated as an immediate operational need rather than a training budget line item for next year.

Bromiley’s incident makes the stakes concrete. The tempo of an AI-assisted intrusion consumes the exact time defenders have spent the past year building the instincts to use.

Closing that gap isn’t a matter of buying a better AI detection tool — the survey is explicit that AI-specific controls rank last in practitioner trust. It’s a matter of shrinking the space where confidently wrong output, whether from an attacker’s tooling or a defender’s own AI assistant, can do damage before a human catches it.

Data governance that verifies content before it reaches a model, audit trail visibility into what an AI system actually accessed, and access controls that limit blast radius all shrink that window.

A documented incident response plan that explicitly models the “AI agent acted on bad context” scenario — with defined rollback procedures and human escalation thresholds — is the operational complement to the governance architecture: it defines what happens after detection, not only how detection works.

None of these replace the skeptical analyst the survey keeps coming back to. They give that analyst something reliable to be skeptical about.

To learn more about governing what data reaches your AI systems and keeping a verifiable audit trail of every access, schedule a custom demo today.

Frequently Asked Questions

The 2026 SANS AI Survey polled 536 IT and security professionals about how they use generative AI in cybersecurity work and how reliable that AI has been in practice. It measures adoption rates, where practitioners trust AI output versus where they verify it manually, how often AI guidance has misdirected them, and how organizations are experiencing AI-enabled attacks. The findings tie closely to the kind of risk assessment and data governance practices that determine whether AI deployments are trustworthy in the first place. Organizations subject to regulatory compliance obligations — HIPAA, GDPR, CMMC — should treat the survey’s data provenance findings as directly applicable: the same governance gaps that produce confidently wrong AI outputs in a SOC context are the gaps that expose regulated data to AI-mediated risk.

Practitioners trust AI most on structured, well-labeled problems like classifying threats or prioritizing vulnerabilities, where training data is abundant and the task has clear right answers. Confirming a true positive or judging a behavioral anomaly requires context-dependent judgment that AI models handle poorly, which is why 63% of survey respondents reported significant shortcomings in AI-driven detection and response. Strong access controls and verified data provenance help narrow that gap by ensuring the AI is reasoning over accurate, current information. Data minimization applied to what AI systems can access — restricting each model to the minimum data required for its designated task — also reduces the surface area over which a confidently wrong answer can do operational damage.

In the incident Bromiley described, a supply chain compromise moved from initial foothold to lateral movement within minutes rather than the days or weeks that manual reconnaissance typically takes. Detection thresholds and on-call rotations are built around an assumption of attacker dwell time, and AI-assisted tooling removes much of that buffer. Reducing reliance on that buffer requires controls like zero trust architecture and egress visibility that don’t depend on catching an attacker mid-recon. A SIEM with real-time telemetry ingestion and behavioral baselining is the detection infrastructure that converts the compressed dwell time from an overwhelming speed advantage into a flagged anomaly — organizations that lack this visibility layer are structurally blind to the attack pattern the survey documents.

Behavioral detection, security awareness training, human analyst review, and zero trust architecture rank highest in practitioner trust, while AI-specific tooling ranks last. The common thread is that these controls constrain what an attacker can actually do inside an environment rather than trying to out-analyze the attacker’s tooling. Third-party risk management practices, including an accurate software supply chain inventory, also feature prominently in what practitioners say they need. ABAC policies that evaluate content sensitivity and user context at every request — not only at initial authentication — are the access control implementation that delivers the least-privilege enforcement the survey’s top-ranked controls assume.

AI systems generate confident-sounding answers from whatever context they’re given, and if that context is stale, unverified, or unauthorized, the output looks just as authoritative as it would from clean data. Enforcing governance at the point where content reaches a model — through tools like Kiteworks Compliant AI and a governed Secure MCP Server for agentic access — gives analysts a verifiable audit trail of what the AI actually saw, making it easier to calibrate how much trust a given output has earned. A documented incident response plan that covers AI agent misfire scenarios — including the runbook for when an AI system acted on bad or unauthorized data — is the operational layer that converts that governance infrastructure from a preventive control into a full response capability.

Additional Resources

Get started.

It’s easy to start ensuring regulatory compliance and effectively managing risk with Kiteworks. Join the thousands of organizations who are confident in how they exchange private data between people, machines, and systems. Get started today.

Table of Content
Share
Tweet
Share
Explore Kiteworks