Artificial intelligence has become a daily tool for 40% of security teams, while another 56% are actively testing it, according to Prophet Security's State of AI in Security Operations 2026 report, which surveyed more than 250 cybersecurity professionals. Only 4% of teams have no plans to adopt the technology. For organizations already running AI in their security operations, the shift is delivering measurable changes in how alerts are handled, threats are hunted, and analysts spend their time.
The typical security team processes around 100 alerts each day, but larger organizations face close to 1,000, with more than a quarter of teams handling over 500 daily, the report finds. Many teams operate with fewer than ten analysts, while some massive organizations employ over 100. Investigating a single alert thoroughly takes an average of 75 minutes, and alerts often sit unexamined for nearly an hour before anyone starts looking. Attackers can break out and move laterally through a network in 29 minutes, turning the two-hour cycle from alert to resolution into a containment crisis rather than just an efficiency gap. About 28% of alerts are never investigated at all, and 60% of respondents admitted that an alert they ignored or missed later escalated into a serious incident such as a data breach or system downtime. For a third of those respondents, this happened three or more times in the past year. Up to 40% of organizations have disabled certain security alerts entirely because they lacked the staff to review them.
More than half of security professionals—56%—observed an increase in AI-driven attacks over the past year, particularly in finance and healthcare, the report states. The most frequent threats include AI-generated phishing emails, deepfake audio and video scams, large-scale credential-stuffing campaigns, and AI-produced malware. For the first time, both securing AI systems and deploying AI for security have become top priorities, surpassing traditional concerns like cloud and data security. Teams cite faster response times (73%), improved detection coverage (71%), doing more with existing staff (56%), and reduced analyst burnout (37%) as the main drivers. Nearly three-quarters—72%—of teams using AI say it has cut investigation time by at least 25%, which translates to roughly 25 minutes saved per alert. Teams also report better around-the-clock coverage, fewer false positives, and more time for analysts to focus on advanced work.
Most AI users—72%—attempted to build their own internal AI tools, but almost half of these homegrown projects were eventually abandoned, never reached production, or were replaced by commercial products, according to the report. Building in-house brought no speed advantage: teams that tried a DIY approach reported investigation-time gains of 25% or more at the same rate as AI users overall (73% versus 72%). While most teams say AI's conclusions align with a human expert's judgment most of the time, 57% still require a human to review every AI decision before closing an alert. Most teams—44%—use AI to recommend actions for humans to execute, and 30% allow it to handle low-risk automated remediation independently. Not one respondent grants AI full, unsupervised autonomy. When AI frees up analyst time, about half of teams use it to actively hunt for hidden threats, and 38% have discovered malicious activity that automated tools missed. Teams that hunt weekly or more report a 49% success rate, compared to 8% for teams that never hunt.
Despite fears that AI would eliminate jobs, 57% of respondents expect their team size to remain unchanged, and 9% anticipate growth, the report concludes. Instead of layoffs, companies are shifting roles: as AI handles basic triage, human analysts are moving into more advanced positions such as incident response, threat hunting, and defense testing. The biggest obstacle is regulatory: 44% of teams worry about data privacy and how AI models are trained, while another 41% struggle with explainability—needing to understand why the AI reached its conclusion. The report suggests these concerns can be addressed by thoroughly evaluating AI vendors rather than waiting on the sidelines. The most successful teams follow a clear pattern: they use AI to investigate everything, validate its work systematically, gradually grant it more autonomy as it earns trust, and use the time saved to actively hunt for threats. The question is no longer whether security operations will adopt AI, but how quickly teams can build the trust and processes to deploy it safely. Organizations that move decisively on vendor evaluation and role redesign will gain an edge, while those paralyzed by privacy concerns risk falling behind adversaries who face no such hesitation.

