What the Data Says About AI in Security Operations in 2026
13:30 · August 27, 2026 · Hacker News AI Section

AI is officially mainstream in security operations. According to Prophet Security's State of AI in Security Operations 2026 report (produced from ViB’s survey of 250+ cybersecurity pros), 40% of security teams now use AI daily. Another 56% are currently testing it out, and only 4% have no plans to adopt it. For the teams already using AI, what is actually changing? Here are the ten biggest
Summary
A 2026 survey of more than 250 cybersecurity professionals, conducted for Prophet Security, shows that AI has moved into routine use in security operations. Forty percent of teams now apply it daily, while 56 percent are actively testing deployments and only 4 percent have no adoption plans. The same teams report receiving roughly 100 alerts per day on average, with larger organizations handling up to 1,000 and more than a quarter exceeding 500. Investigation of a single alert still averages 75 minutes, and nearly 28 percent of alerts go unexamined, a gap that 60 percent of respondents link to subsequent incidents such as data breaches or downtime.
More than half of respondents observed an increase in AI-driven attacks over the past year, particularly in finance and healthcare. Common vectors include AI-generated phishing, deepfake scams, credential-stuffing campaigns, and machine-written malware. At the same time, security teams cite operational drivers for their own AI use: faster response (73 percent), improved detection coverage (71 percent), and the ability to handle workload without expanding headcount (56 percent).
Teams that have adopted AI report measurable gains. Nearly three-quarters indicate at least a 25 percent reduction in investigation time, freeing analysts for threat hunting that yields higher detection rates when performed weekly. However, internal development efforts have proved fragile: 72 percent of users attempted to build their own tools, yet 46 percent of those projects were later abandoned or replaced by commercial offerings. Most organizations still require human review of every AI decision, and no respondent grants full unsupervised autonomy; instead, AI functions mainly as a recommender or handler of low-risk remediation steps.
The leading obstacles remain regulatory and technical. Forty-four percent of teams cite data-privacy concerns around model training, and 41 percent struggle with explainability. Team sizes have remained stable, with 57 percent expecting no change, while analysts shift toward higher-value tasks such as incident response and defense testing. The survey data therefore portray a measured transition in which AI narrows the gap between alert volume and investigative capacity without displacing human oversight.
Why it matters
Directly addresses AI security risks, privacy concerns, and regulatory hurdles relevant to EU data protection rules; Dutch teams can apply adoption metrics, mitigation strategies, and vendor evaluation criteria for GDPR/AI Act compliance.












