Estimated reading time: 6 minutes
AI security spending has moved to the front of the queue. Most security leaders still face flat or shrinking budgets.
IANS and Artico Search found that 69% of surveyed CISOs selected AI among their priorities for additional security funding. Respondents could choose several priorities. AI attracted the most selections. The organizations released their 2026 Security Budget Benchmark Report on September 15. Its findings put a fashionable investment inside a familiar financial squeeze.
“AI has changed the cybersecurity investment conversation,” said Nick Kakolowski, senior research director at IANS.
For underwriters, that conversation needs an operational answer. What changes inside the insured business after the software arrives?
Cybersecurity Budgets Reveal A Divided Market
Average security budgets grew 5% in 2026, compared with 4% in 2025. Median growth remained at zero. Some 45% of respondents reported flat budgets. Another 10% reported cuts.
Ownership helps explain the split. Venture-backed companies reported average growth of 14%. Private-equity-backed companies averaged 10%. Government and nonprofit organizations each averaged 1%.
Among CISOs with growing budgets, 48% cited increased business or operational risk as a driver. Only 3% pointed to a major breach in their industry. Meanwhile, 78% of respondents with shrinking budgets cited companywide cost-cutting.
The finance department still has a vote. Its decisions follow the wider business.
Looking ahead, 64% expect their security budgets to grow in 2027. Only 45% achieved an increase this year. That gap gives CFOs a reason to test planned purchases against approved funding.
For brokers, those findings support renewal discussions grounded in changing operations, customer requirements, and exposure. A larger budget can support stronger defenses. Its allocation explains where the organization expects those improvements.
AI Security Investment Needs A Budget Line
Only 24% of organizations track AI separately within security budgets, either as a line item or a subcategory. Another 38% embed AI within the broader security budget. The remaining 38% fund it through IT, data, or innovation budgets.
About 70% of organizations tracking AI separately reported increased AI funding. That figure fell to 42% where organizations embedded AI in security budgets. It reached 31% where other departments supplied funding.
The figures associate visibility with funding momentum. They leave the direction of cause and effect unresolved.
Kakolowski described organizations “using business interest in AI as a lever” to secure resources for security initiatives.
For CFOs, the label deserves scrutiny. Buying AI-powered defense and protecting the company’s own AI use can address different exposures. A useful budget explains both purposes, assigns responsibility, and identifies the expected result.
Take The Cyber Insurance News Survey
Respondents get the results first.
AI Spending Brings Software Close To Payroll
Software, including AI, now consumes 35% of the average security budget, up from 29% last year. Staff and compensation account for 37%, down from 39%.
The report introduced AI as a separate spending category this year. That line accounts for 3% of total spending, half the six-point difference in software’s share. Software hosted outside the company grew from 22% to 25% of the budget.
Year-to-year comparisons therefore need to account for that category change. A falling payroll share can also accompany rising payroll spending when the overall budget grows.
Software is closing on salaries. The harder question concerns the work each dollar buys.
AI Security Staffing Depends On New Skills
Over the next 12 months, 91% of CISOs expect AI to improve team productivity. Some 81% expect demand for new roles and skills.
Meanwhile, 69% expect AI to leave the need for existing staff unchanged. Some 53% expect AI to reduce the need for additional staff.
Those answers describe forecasts. Measuring the eventual employment effects will require follow-up.
Steve Martano, an IANS faculty member and Artico Search partner, described changes in hiring and responsibilities. He said CISOs want staff to “find anomalies, elevate relevant threats and make judgment calls.”
That distinction matters when a tool closes an alert, recommends a response, or ranks a possible threat. Someone needs the skills, authority, and time to question its conclusion.
Our coverage of Anthropic’s monitoring failures examined a retrospective test where a model’s explanation weakened another AI system’s detection. That finding gives buyers a concrete question: can their reviewers challenge automated decisions using independently checked evidence?
AI Security Spending Needs Operational Proof
The report recommends clear AI budget lines, comparisons with similar organizations, and funding for retraining. Martano urged organizations to “establish clear governance, and invest in developing new skills.”
Governance already distinguishes respondents planning aggressive AI investment. Among those expecting AI spending growth above 10%, 70% report clear ownership of enterprise AI governance. Among respondents planning no AI-specific spending, 34% report that clarity.
These groups enter the spending cycle with different foundations. The survey measures their reported practices and plans. Establishing how those differences affect losses requires separate evidence.
Get The Cyber Insurance News Upload
Subscribe to our weekly newsletter!
Our Nationwide AI governance coverage examined uneven adoption of basic controls for employees’ AI use. IANS adds the budget perspective through a different sample of security leaders.
Underwriters can ask what changed after deployment: missed threats, false alarms, escalation times, human overrides, and response authority. Brokers can carry those answers into renewal discussions alongside the organization’s changed activities and exposures.
General counsel can ask who retains the record of an automated decision and its human review. Those records help reconstruct an incident, identify responsibility, and explain why a person accepted the software’s recommendation.
AI has won a place in the budget. Underwriters need evidence of what that money delivers.
FAQ: AI Security Spending
Who Took Part In The IANS Survey?
IANS and Artico Search collected responses from more than 500 security executives between April and August 2026. Some 92% worked in the United States. Organizations used their own definitions of security and IT budgets, which limits precise comparisons.
Does The 69% Figure Measure AI’s Budget Share?
It measures respondents selecting AI as a priority for additional funding. The question allowed multiple selections. The report’s separate AI spending category accounts for 3% of the average security budget.
What Do CISOs Expect AI To Change About Staffing?
Most expect better productivity and demand for new skills. Some 53% expect reduced demand for additional staff. These findings describe expectations for the next year.
How Can Underwriters Assess AI Security Investment?
Ask which controls changed, who supervises automated decisions, and how the organization measures results. Compare those answers with deployment records, response exercises, and documented human interventions.
Related Cyber Insurance Posts
- Ransoms Above $10m Went From 15 To 59 In Two Years
- Cybersecurity Budgets Flatline as Cyber Threats Beat On, New Report Finds(Opens in a new browser tab)
- How Rising Cybersecurity Spending Powers Defense and Tech Stocks(Opens in a new browser tab)
- The Role Of The CISO Hits A Boardroom Access Wall, 2026 Report Finds(Opens in a new browser tab)
- Cyber Risk Management Surge: New Report Shows Rising Threats and Bigger 2026 Security Budgets(Opens in a new browser tab)