Fifty-nine percent of UK chief information security officers say attackers now hold the upper hand as artificial intelligence speeds up cyber threats, even though 94% describe their organizations as ready to handle AI-fueled vulnerabilities, according to new research from cybersecurity firm Kai. That self-assurance clashes with how quickly companies actually fix security flaws. The findings point to a widening divide between the velocity of machine-driven attacks and the pace at which security teams can close dangerous gaps.

Kai found that 67% of respondents need more than a week to fix critical vulnerabilities, while 54% said at least one-quarter of their known security flaws stay unpatched for more than 30 days. Among the security leaders surveyed, 59% believe attackers currently have the advantage because of AI adoption and progress, while just 13% said defenders hold the edge. More than half of respondents told Kai their vulnerability and exposure management processes remain at least 50% manual. Meanwhile, 51% of CISOs cited lack of confidence in automated decisions as a major obstacle to greater automation.

The report highlights a growing mismatch between the speed of AI-enabled attacks and security teams' ability to respond, with CISOs still dependent on human labor for much of their vulnerability management work, potentially contributing to slower remediation and growing security backlogs. "Artificial intelligence has changed the economics of cyber conflict in the UK," according to the report, and security leaders responsible for defending the enterprise are feeling the effects firsthand. Kai emphasized that trust, governance, explainability, and accountability stand as central challenges organizations will need to address as they adopt more machine-led security operations.

The research suggests organizations want to shift toward more automated security operations, but lack of trust remains a significant barrier. The report notes that the next phase of enterprise defense will be defined less by whether organizations adopt automation and more by how quickly they can build the confidence to let it act. Most surveyed security leaders expect machine-led operations to play a larger role as organizations become more comfortable validating and governing automated security decisions, Kai said. The companies that meet those conditions first will be the ones that close the gap between the speed of the threat and the speed of the response.

The divide between AI-driven threats and slower remediation could create a larger role for UK managed service providers and managed security service providers in helping customers put security automation into practice, the report suggests. Organizations dealing with large vulnerability backlogs may need more support to rank exposures, speed up remediation, and reduce dependence on manual workflows. At the same time, Kai's findings suggest that adoption will depend on more than simply rolling out additional automation. With CISOs pointing to lack of trust in automated decisions as a major barrier, service providers may need to help customers set up clearer governance and oversight around machine-led security processes. That could shift the conversation for managed service providers from simply offering automation to showing customers how automated actions are monitored, explained, and controlled, with providers that pair faster response with clear oversight and validation processes better positioned to support organizations adopting more machine-led security operations. Trust in automated defense systems may ultimately determine which organizations can respond at the speed their adversaries now operate, reshaping competitive dynamics across the cybersecurity services market.