Businesses Rush to Adopt AI Security Tools, But Few Have a Plan for AI-Related Incidents
New research from ISACA has found that while more organisations are using AI to help detect and respond to cyber threats, very few have prepared for incidents involving AI itself. The 2026 State of Cyber report found 71% of organisations have never run an AI-specific incident response exercise, only 3% have mature runbooks for such incidents, and 30% have not started addressing the issue at all. These gaps matter because AI-related incidents can include sensitive data leaking through AI tools, AI-powered phishing and fraud, or employees misusing generative AI.
The report shows adoption is outpacing readiness. More than a third of organisations now use AI to automate threat detection and response, an increase on last year, with similar numbers using it for routine security tasks and endpoint protection. Security teams are heavily involved in this shift, with over half helping to implement AI tools or shape AI policy. ISACA warns that attackers are moving just as fast, using AI to automate attacks that once took much longer to carry out.
The pressure is also showing on cybersecurity staff. Among those surveyed, 38% reported more attacks than the previous year and over half expect an attack in the next 12 months, with AI-assisted social engineering the most common threat. Many professionals said their jobs have become more stressful due to rising complexity, understaffing, underfunding and unrealistic workloads.