AI Security Spending Jumps as Fear Outpaces Proof of Value

A graphic illustration of a man holding money in one hand and an AI icon in the other hand
Source: chiewr via Getty Images

Organizations are pouring more money into AI for cybersecurity without waiting for clear evidence of what they might be getting in return.

Multiple factors are driving the spending trend. These include the rapid shift of AI from experimentation into production, the growing use of AI by attackers to automate and accelerate their operations, and in some cases, fear of being left behind as other organizations race to adopt the technology.

AI Has Become Top Priority for New Security Budget Dollars

IANS and Artico recently surveyed more than 500 chief information security officers (CISOs) on their organizations' cybersecurity spending plans for 2026. The data showed average security budgets grew just 5% in 2026, from 4% in 2025, while the median budget remained flat for a second consecutive year.

Against that backdrop, 69% of CISOs identified AI as their single biggest priority for net new budget dollars, while 24% have given AI a separate security budget line. Meanwhile, 38% have made it part of their broader security spending, and another 38% fund it through IT, data, or innovation budgets.

The survey suggested AI is more likely to reshape security teams than replace them. Some 91% of CISOs expected AI to make their teams more productive over the next 12 months, while 81% expected it to create demand for new cybersecurity roles and skills. Many CISOs expect AI to take over more repetitive tasks, while security professionals will take on higher-value work such as anomaly detection, threat investigation, and making higher-level decisions around emerging threats.

"Formally associating spending with AI in the structure of the budget is having an even larger influence on spend than expected," says Nick Kakolowski, senior research director at IANS. Giving AI its own budget line appears to be making it easier for many organizations to get more funding for AI, he says. In addition to concerns about AI rapidly changing the threat landscape, many "executive teams are afraid of falling behind on AI and putting pressure on functional leaders to embrace the technology," he says about the spending trend.

Most Pursued AI Uses Cases Are Not the Ones Delivering Most Value

The increased investments in AI for cybersecurity is happening despite some uncertainty over the value organizations might be deriving from it. Data from a recent Gartner survey of more than 1,000 IT professionals from organizations with revenues of $50 million or higher suggested a disconnect between the AI use cases organizations are pursuing most aggressively and those generating the strongest returns.

"The most widely pursued AI use cases are rarely the ones delivering the highest positive returns," Gartner noted. For instance, while C-suite leaders identified cybersecurity threat detection and response as the most frequently pursued AI use case, the one delivering the most value was the use of AI for intelligent IT asset and cost optimization, Gartner noted. "Functional leaders are frequently falling into the trap of prioritizing “popular” or heavily hyped AI applications over those that generate tangible value."

Ram Varadarajan, CEO at Acalvio, says fear asymmetry is what is driving the AI spending trend. "A missed breach is visible and career-ending, so buying "AI-powered" security is blame insurance, not a validated bet," he says. Vendors sell to that fear, and once AI becomes the market's baseline expectation, "peer-following procurement replaces evidence-based procurement," he says.

The AI Fear Factor

But the uncertainty over returns and value is not necessarily slowing security leaders when it comes to investments in AI in cybersecurity. For many, the urgency created by AI-enabled threats is outweighing the need to first establish a clear business case for the technology.

Sean Murphy, field CISO at F5, says the rush to invest in AI for cybersecurity isn't about chasing speculative returns. Rather, it stems from the stark reality that AI operationalization has moved out of the lab and straight into production.

"That means the threat landscape is accelerating at a pace that human defenders simply cannot match," he says. "Attackers are already operating at machine speed, and attempting to defend at human speed is not sustainable or a winning play."

In fact, most CISOs aren't waiting around for a clear ROI case for AI in cybersecurity because they are scared, adds David Lindner, CISO of Contrast Security. "Attackers are already using AI to write sharper phishing emails, mutate malware, and hunt for flaws in code faster than any team of humans can match," he says. "Wait for the business case to firm up and you're really just telling your board you plan to lose slower."

The ROI Challenge

In addition, several security experts say measuring ROI on security investments has never been easy because unlike revenue-generating investments, the biggest benefit of a security investment is something that doesn't happen, like a data breach or operational disruption. The challenge becomes even greater when multiple layers of controls contribute to preventing the same attack.

Measuring return on security investment, or ROSI, has always been difficult, because it's measuring loss avoidance, where ROI is generally viewed as a way to compare and prioritize efforts designed to make or save money, says Daniel Kennedy, principal research analyst at S&P Global Market Intelligence. While a general conversation around the ROI of AI investments for enterprises is valuable, the security conversation in particular should be centered on how to secure AI so it can be used by employees safely and where to integrate AI into security tooling, SecOps, or in the review of generated code for example, Kennedy says.

Ronald Lewis, head of cybersecurity governance at Black Duck, says the key to extracting optimal value from AI investments in cybersecurity lies in understanding the "difference between the art of the possible and the art of the feasible. AI is not the answer to every problem, and not every use case will deliver meaningful business value."

Organizations should resist the temptation to deploy AI simply because it is available and instead focus on areas where it can demonstrably improve outcomes, reduce risk, or eliminate repetitive manual work, he says. The market is being flooded with new AI-enabled products, some of which will deliver transformative value while others will simply add cost and complexity. Leaders need to be able to distinguish between the two.

"The winners will not necessarily be the organizations that adopt AI the fastest, but those that adopt it most thoughtfully," Lewis says. "Strong governance, clear accountability, appropriate controls, and measurable business outcomes remain essential."

source: DarkReading