Security teams are turning to AI to survive alert overload The World Economic Forum white paper “Empowering Defenders: AI for Cybersecurity” identified AI as the biggest driver of change in cybersecurity for 94% of survey respondents. The paper found that 77% of organizations already use AI in cybersecurity, with much of the activity focused on phishing detection, anomaly monitoring, vulnerability management and incident response. “AI has the potential to shift the balance towards defenders,” said Akshay Joshi, Head of the Centre for Cybersecurity, World Economic Forum. “Organizations that treat it as a strategic capability instead of a standalone tool will be better placed to turn growing cyber risk into resilience and competitive advantage.” AI is moving deeper into security operations Security operations centers are changing quickly as teams push more alert handling and investigation work into automated systems. AI tools are being used to filter alerts, summarize investigations and help analysts process large volumes of telemetry and threat data. The report noted that 76% of cybersecurity professionals reported exhaustion in 2025, and 55% of teams reported understaffing. Threat detection remains one of the most common deployment areas. Security tools are examining communication patterns, language cues and impersonation tactics to identify suspicious messages and unusual behavior that older detection methods may miss. Software and cloud security teams are folding automated analysis into routine vulnerability and configuration reviews. Development and infrastructure teams are using AI to identify insecure code, detect configuration weaknesses and prioritize vulnerabilities in large environments. Operational pressure behind adoption is growing on both sides of the threat landscape. Attackers are using automation to speed up reconnaissance, malware development and large-scale campaigns. Defensive teams are pushing more analysis and investigation work into automated systems. Organizations using AI extensively in security shortened breach lifecycles by approximately 80 days and reduced average