ORGANISATIONS are increasing spending on artificial intelligence (AI) for cybersecurity despite limited evidence that the technology is delivering clear returns. An IANS and Artico survey of more than 500 chief information security officers found that average security budgets rose 5% in 2026, up from 4% in 2025, while median budgets remained unchanged for a second year.
AI was the single biggest priority for new security funding for 69% of respondents; 24% had a separate AI security budget, while others funded it through security, IT, data or innovation budgets.
The survey found that 91% of CISOs expected AI to improve team productivity over the following 12 months, and 81% expected it to create demand for new cybersecurity roles and skills rather than replace staff. However, Gartner research involving more than 1,000 IT professionals at organisations with revenues of at least $50 million suggested that the most popular AI applications do not always produce the greatest value.
Cybersecurity threat detection and response was among the most pursued uses, while intelligent IT asset and cost optimisation reportedly generated the strongest returns.
Security leaders and industry experts attributed the spending partly to fear of AI-enabled attacks, including faster phishing, malware development and vulnerability discovery, and concern about falling behind competitors. They also noted that security return on investment is inherently difficult to measure because its main benefit is often an incident that never occurs.
Experts advised organisations to prioritise demonstrable risk reduction and reduced manual effort, supported by governance, accountability, controls and measurable outcomes, rather than adopting AI solely because it is available.