Cybersecurity leaders are pouring more money into artificial intelligence (AI) without waiting for clear evidence of what they might be getting in return. According to a recent survey by IANS and Artico, 69% of chief information security officers (CISOs) identified AI as their top priority for new budget dollars in 2026.
The rapid shift of AI from experimentation into production is driving the spending trend. As attackers increasingly use AI to automate and accelerate their operations, organizations are racing to adopt the technology to stay ahead. Fear of being left behind by competitors who have already invested in AI is also a major factor. “Executive teams are afraid of falling behind on AI and putting pressure on functional leaders to embrace the technology,” says Nick Kakolowski, senior research director at IANS.
The survey data shows that CISOs are not waiting for proof of value before investing in AI. Instead, they’re giving it a separate budget line or incorporating it into their broader security spending plans. In fact, 24% of respondents have allocated a dedicated budget for AI, while another 38% fund it through IT, data, or innovation budgets.
But here’s the thing: most organizations are pursuing AI use cases that may not deliver the strongest returns on investment. A recent Gartner survey found that there’s a disconnect between the AI use cases being pursued and those generating tangible value. While C-suite leaders are prioritizing popular AI applications like cybersecurity threat detection and response, it’s actually other use cases – such as intelligent IT asset and cost optimization – that are delivering the most value.
The uncertainty over returns is not slowing down security leaders, however. Many feel that the urgency created by AI-enabled threats outweighs the need to first establish a clear business case for the technology. “The rush to invest in AI for cybersecurity isn’t about chasing speculative returns,” says Sean Murphy, field CISO at F5. “It’s about staying ahead of the curve and mitigating the risk of being breached.”
Ram Varadarajan, CEO at Acalvio, attributes the AI spending trend to fear asymmetry. “A missed breach is visible and career-ending, so buying ‘AI-powered’ security is blame insurance, not a validated bet,” he says. Vendors are selling to this fear, creating a market where peer-following procurement replaces evidence-based procurement.
In practical terms, what does this mean for organizations looking to invest in AI? While it’s true that AI has the potential to reshape security teams and create new opportunities, CISOs should be cautious not to fall into the trap of prioritizing popular AI applications over those that generate tangible value. As Varadarajan notes, “It’s time for security leaders to take a step back, assess their needs, and make evidence-based decisions – rather than following the crowd.” By doing so, they can ensure that their investments in AI are delivering real returns on investment, not just providing a feel-good factor.
Source: Dark Reading — 2026-09-16