Cyber budgets flatline as CISOs shift new spending to AI
AI is absorbing new security spending even as budgets stall, forcing CISOs to rethink how they deploy people, automation and risk dollars.
Cybersecurity leaders are being asked to secure a rapidly changing AI environment without a corresponding expansion in resources.
That tension is highlighted in the 2026 Security Budget Benchmark Report from IANS Research and Artico Search. According to the report, security budgets grew by an average of 5% this year, while 45% of organizations reported no increase and 10% reported a decrease. At the same time, 69% of CISOs identified AI for security as their top priority for new budget dollars.
The findings point to a difficult balancing act in which AI is creating new security requirements, but CISOs cannot assume they will receive substantially more funds or personnel to address them.
The answer, experts say, is to change how organizations use the resources they already have.
Make the security case in business terms
For CISOs facing constrained budgets, the first step is to connect security investment directly to the organization's business strategy rather than presenting AI security as just another technology expense.
"The most effective way to get the budget and resourcing needed to lead a business-enabling security function is to tell the story of security in the context of business objectives," Steve Martano, IANS Faculty and Partner at Artico Search, told TechTarget Cybersecurity.
"Where a company is on the AI journey, the growth trajectory and market positioning all have security implications. By saying 'yes, we are eager to support these initiatives and here's what the security implications are…' a CISO can tell a business-driven security story."
That approach reflects what IANS found to be driving spending decisions. Increased business or operational risk was cited by 48% of CISOs with growing budgets, compared with just 3% who pointed to a major industry breach as a primary driver.
Rather than asking the board to fund "AI security," the implication is that CISOs need to explain what business risk an investment addresses, what it costs and what exposure remains if the organization does not make it.
Automate the work that does not require judgment
AI is also changing the economics of security staffing. IANS found that 91% of CISOs expect AI to make their security teams more productive over the next 12 months. Meanwhile, 81% expect AI to create demand for new roles and skills, while 69% do not expect it to reduce existing security headcount.
That suggests the immediate impact is more likely to be a redistribution of work than mass replacement.
"We're seeing two changes," said Nick Kakolowski, senior research director at IANS. "Leaders are considering hiring individuals who are stretch candidates for roles if they have the right soft skills, expecting AI to fill in some of the technical skill gaps. We are also seeing a growing need for roles around building, assessing and managing AI capabilities within the security team."
The opportunity, therefore, is to use automation for repetitive work while focusing human expertise on tasks where judgment matters.
Ivan Milenkovic, vice president of Risk Technology at enterprise security firm Qualys, argues that vulnerability management provides a good example. Of the 48,172 vulnerabilities disclosed in 2025, Qualys identified 357 that were remotely exploitable, actively weaponized and backed by working exploit code.
"AI is very good at removing that work: sorting findings against live exploitation, reading a patch and what it is likely to break, deploying the safe ones without a human in the loop," Milenkovic told TechTarget Cybersecurity.
Milenkovic said AI can also search an organization's asset inventory for potential issues, assess patches and automatically deploy lower-risk fixes, allowing security teams to focus on the vulnerabilities that represent more significant exposure.
Put governance alongside AI adoption
The challenge extends beyond security teams to the wider organization. Businesses are struggling to establish controls quickly enough as employees adopt AI into their day-to-day workflows.
Separate research from Absolute Security, based on a survey of 1,001 CISOs in the U.S. and UK, found that 60% said board pressure to adopt AI was outpacing their ability to govern and secure it. The same research found that 83% of organizations were already piloting or running agentic AI in security operations.
That creates another area where security leaders need to make careful investment decisions.
"AI has left IT teams in a race to regain control," said Vimal Raj, head of technical, UK and Ireland at ManageEngine.
He added that organizations need to prioritize "upskilling, including AI literacy" and greater integration between IT and business teams, rather than attempting to deploy AI everywhere as quickly as possible.
The objective, he said, should be to identify where AI can genuinely improve operations and provide employees with approved, governed tools.
Give the board choices, not another shopping list
For CISOs operating under budget constraints, the common thread is not simply to ask for more money for AI, but to show what that money changes.
Milenkovic argues that CISOs should frame security spending in terms of business exposure: which systems are affected, what those systems are worth to the organization and what downtime or disruption would cost.
That leads to a more conventional business risk discussion, one that can be aligned with the organization's existing risk appetite policy.
"Go and read [the policy], then change the ask you make to the board," he said. "Provide three options, each with a cost, a risk it removes and a risk you would still be carrying."
As AI becomes a larger share of security investment, the central challenge for CISOs may not be convincing the business that AI matters, but demonstrating which AI investments actually reduce risk, which work should be automated, and where human expertise needs to be redirected.
IANS' findings suggest the pressure will continue. Although only 45% of CISOs saw their security budgets increase in 2026, 64% expect an increase in 2027.
Ultimately, the organizations making the most of that spending may be those that treat AI not simply as another security product category but as a catalyst for redesigning how security teams work.