Even with artificial intelligence spending expected to reach into the trillions, those dollars are not filtering down to internal cybersecurity teams as quickly. Security budgets are expected to grow by an average of 5 percent in 2026, compared with 4 percent last year, according to a recent survey of industry leaders.
At the same time, 55 percent of CISOs report flat or declining budgets this year. While nearly seven out of 10 security leaders noted that AI is a major priority for new budgets heading into 2027, AI alone accounts for about 3 percent of security spending, while software and AI combined represent 35 percent of the security budget – about two percentage points behind staff and compensation.
Additionally, about 38 percent of organizations fund AI security outside the security budget through areas such as IT, data or innovation, according to the report published by cyber-risk consulting company IANS Research and recruiting firm Artico Search. The data includes responses from 500 CISOs and security leaders from interviews conducted between April and August.
The research suggests that while overall AI spending is still increasing, some of the capabilities CISOs and their internal security teams are using are coming from other budgets within their organizations. This trend could change how security leaders approach their budgets in 2027 and beyond, especially as cybersecurity teams are increasingly tasked with securing these AI technologies and assessing risk.
“Another implication of investing in emerging technologies is that security is gaining tailwinds from other investments in AI and broader technology, meaning some security capabilities are particularly funded out of someone else’s budget,” Steve Martano, IANS Faculty and partner in Artico Search’s cyber practice, noted in the report.
An uncertain economy is also driving tighter evaluations of cybersecurity return on investment, as well as greater scrutiny of security spending, including hiring and recruiting talent, said Robb Reck, chief information, trust and security officer at Pax8.
“Rather than expanding teams, organizations today are looking to AI to increase their existing workforce's effectiveness. Still, leaders need to remain careful, continuing to gauge how AI adoption will ultimately affect team dynamics and resource needs,” Reck told Dice.
Budgeting Cybersecurity in an AI World
As AI spending becomes an increasingly pressing priority, CISOs and internal security teams face three pressure points in their cybersecurity budgets, said Collin Hogue-Spears, senior director of solution management at security firm Black Duck. These include:
- The first is pressure from the board, which mandates that enterprise AI is already a top CEO priority. Security then gets its budget because nobody can defend the rest of the program without it.
- The second pressure point is capacity. Alert backlogs and unfilled seats were constraints before AI arrived, so teams buy the throughput they cannot hire for.
- The third is the attacker-side clock. Since the board believes the other side already has the tool, a matching purchase needs no ROI model. That means AI becomes an arms-race purchase rather than a capital-budget purchase.
This also means developing new budget proposals that document how AI agents work and what it takes to secure them, as well as how they affect the rest of the organization.
“Security leaders must price the work the model actually does. Hold back a set of alerts the model never sees, then compare: what did each correctly closed alert cost, and how often was the auto-close right? Run a board slide that turns a quiet quarter into a win for the model and the first auditor who asks for the comparison group takes it apart,” Hogue-Spears told Dice. “Measure what the model closed, not what the quarter avoided.”
Some of today’s largest cybersecurity expenditures are coming from investments in application security, security operations and AI usage governance, principally driven by automated code patching and the need to protect corporate models from data leakage.
At the same time, dedicated budgets are increasingly carved directly out of existing money earmarked for Security Operations Centers (SOCs) and legacy automation allocations to help fund the so-called "token budgets" and autonomous agentic tools, said Acalvio CEO Ram Varadarajan.
In many cases, fear of a data breach or attack is driving spending, and CISOs might see AI as a way to offset those concerns.
“Fear asymmetry drives the spend. If a missed breach is visible and career-ending, buying ‘AI-powered’ security is blame insurance, not a validated bet,” Varadarajan told Dice. “Sell to that fear, and once ‘AI’ becomes the market's baseline expectation, peer-following procurement replaces evidence-based procurement, which explains why the most popular use cases aren't the best-performing ones.”
AI ROI, however, is harder to measure because CISOs and security teams are pricing the absence of a rare, adversarial event, not counting throughput.
“A quiet quarter could mean the tool works, or that attackers just haven't tried yet, and against a live, adapting adversary, there's no clean control group to prove,” Varadarajan added.
For many CISOs, spending on AI tools and platforms to help with cybersecurity, even as budgets stagnate or only increase marginally, is seen as a necessary way to stay ahead of current trends and avoid falling behind.
“We've learned lessons from the past of trying to ‘bolt’ security onto technology adoption, so many security leaders are rightfully trying to be early and secure the adoption of this technology at the earliest possible aspects of the lifecycle as they can,” Chris Hughes, vice president of security strategy at Noma Security, told Dice. “They also do not want to be caught flat-footed with the board or executive leadership when they are asked what their AI security strategy is, especially among all the FUD and hype around AI and cyber, agent breakouts, cyber risks, and widespread AI-driven vulnerability discovery that has broken into the mainstream narrative beyond cyber circles.”
Security Budgets and Hiring
The pressure to do more with existing cybersecurity budgets is also reshaping the security workforce. While organizations are not broadly cutting security positions because of AI, they are changing the skills they seek, with greater demand for professionals who can apply AI to cybersecurity work.
The IANS and Artico data show that while cybersecurity budgets are flat – which can also affect decisions on talent recruitment, hiring and retention – AI is not taking cybersecurity professionals' jobs. About 75 percent of respondents noted they didn't anticipate cutting positions on their security teams due to AI adoption.
The results also reinforced two other trends for cybersecurity professionals: Entry-level jobs are being automated, and organizations are looking for security pros – even in mid-level roles – with AI skills.
“Demand is shifting toward people with deeper security, AI and business judgment, while entry-level roles are being reduced or redesigned. That is unfortunate, because the routine work AI absorbs is also where people build institutional knowledge and become experienced defenders,” Mika Aalto, co-founder and CEO at Hoxhunt, observed. “At the same time, every AI agent we connect to internal systems is effectively a synthetic employee, and if it is mistaken or compromised, it can become an insider threat operating at machine speed.”
Pax8’s Reck also noted that cybersecurity professionals who use AI to augment their work can create a better understanding of how these virtual chatbots and agents work, which makes them more valuable even as budgets for hiring stay flat.
“Security professionals who treat AI as something that will amplify their work, rather than threaten it, are the ones landing roles, even with tighter security budgets,” he added.