AI can’t fix cybersecurity’s hiring problem Organizations are redefining cybersecurity roles through workforce frameworks and placing greater emphasis on verified skills as AI and new regulatory requirements change hiring. The SANS 2026 Cybersecurity Workforce Survey found demand for specialists in new roles more than doubled over the past year, alongside increased hiring for existing cybersecurity skills. AI changes security work AI is reducing manual analysis, automating routine tasks and creating demand for security roles focused on AI governance, engineering and risk. 54% of respondents said they have AI security policies, and only 38% provide comprehensive AI security training. Nearly one in four organizations have no AI governance plans. Nearly three-quarters of organizations said AI has influenced team composition. The most common changes were workflow automation and reduced manual analysis, with relatively few organizations reporting workforce reductions. Employers are adding AI-focused cybersecurity roles, including AI security engineers, AI governance analysts and AI/ML security specialists, while experienced cybersecurity professionals remain the hardest positions to fill. Compliance expands demand for specialists Regulatory requirements are changing what organizations look for when hiring cybersecurity professionals. Companies are adopting workforce frameworks such as NICE and the European Cybersecurity Skills Framework to standardize cybersecurity roles and skills. Top impacts of directives and regulations (Source: SANS) Regulations including NIS2, DORA, DoD 8140, SEC and CMMC are changing hiring priorities and increasing demand for specialist cybersecurity roles. Most of these regulations apply to specific sectors, including critical infrastructure, financial services and defense contractors. “Organizations are building entirely new specialist positions, restructuring teams around regulatory requirements, and facing real enforcement consequences if they don’t,” said James Lyne, CEO of SANS Institute. Certifications are also becoming more important for hiring, audits, client requirements and career development as companies seek to demonstrate cybersecurity skills. Experienced professionals remain difficult to recruit Experienced cybersecurity