Cybersecurity AI use jumps, but maturity and governance lag Security teams are embracing AI to keep pace with attackers, but gaps in maturity, detection, and governance remain. Key takeaways - Cybersecurity teams are adopting AI faster as attackers use it to scale and speed up attacks. - AI maturity remains low, with only 27% of survey respondents describing their implementation as mature. - Governance, detection, and training gaps are limiting how effectively organizations can use AI in cybersecurity. - Security teams need practical controls, faster vulnerability remediation, and human oversight to reduce AI-related risk. A global survey of 536 cybersecurity and IT practitioners finds cybersecurity teams are now more aggressively adopting artificial intelligence (AI) tools and platforms in the hopes of leveling a playing field that has generally been lopsided for as long as anyone can remember. Conducted by the SANS Institute, the survey finds, for example, 61% of respondents now use AI to augment the capabilities of red teams that are trying to discover and remediate vulnerabilities before adversaries can exploit them. Why AI maturity remains a cybersecurity challenge However, only slightly more than a quarter (27%) describe their implementation of AI as mature, which suggests that in terms of AI capabilities many cybersecurity teams may be still far behind adversaries that are clearly using AI to launch more sophisticated attacks faster than ever. In fact, the survey finds more than three-quarters (78%) of respondents reported confirmed or suspected AI-enabled attacks in the past year, with nearly all (95%) believing threat actors are using AI. How AI-enabled attacks are changing vulnerability risk More troubling still, as more advanced AI models become available, cybercriminals will increasingly be able to discover and exploit vulnerabilities in a matter of hours. While access to the latest AI models from Anthropic and OpenAI is