AI Adoption Is Outpacing Readiness: What the 2026 SANS Survey Means for New Zealand Organisations

Key takeaways

  1. AI use in cybersecurity has risen sharply, but most deployments are still experimental or in early production, and reported failures are increasing as use expands.
  2. Governance is not keeping pace. Leaders are more likely than practitioners to believe a formal AI risk programme exists, while substantial AI use is still happening without clear policy or operational oversight.
  3. AI-enabled attacks are already being observed, but the controls practitioners find most effective remain familiar: behavioural detection, staff awareness, human review, least privilege and multi-factor authentication.

Artificial intelligence is now embedded in cybersecurity operations, from log analysis and incident investigation to threat detection, red teaming and application security. The 2026 SANS AI Survey suggests that the debate has moved on from whether organisations will use AI. The harder question is whether they can use it reliably, securely and under governance that works in practice.

The survey found that 78% of practitioners were actively using AI as part of their cybersecurity strategy, up from 50% in 2025. Yet adoption has moved faster than operating maturity, trust and workforce capability. Most AI deployments remain relatively shallow, reported shortcomings have increased, and governance programmes have barely advanced even as security teams take on more responsibility.

For New Zealand organisations, particularly firms handling confidential client information, the findings point to a practical priority: strengthen the controls around AI already in use before expanding it into more sensitive or autonomous work.

Adoption has accelerated, but maturity remains limited

The jump from 50% to 78% active use in one year is the largest recorded by the SANS survey. AI is already supporting everyday security tasks. Respondents most commonly used generative AI to analyse logs, explain threats, write code, create training material and draft security policies.

Deployment depth tells a more cautious story. Among organisations using AI, 33% described their deployment as early production and 21% as experimental or pilot. Only 27% considered it mature production, while 11% said AI was mission-critical and 7% reported fully autonomous use.

This matters because limited deployments can demonstrate value without revealing all the failure modes that appear at scale. As AI is given access to more systems, more data and more consequential workflows, errors become harder to contain. A tool that produces a weak summary is inconvenient. A tool that misclassifies a genuine threat, recommends the wrong incident response action or exposes confidential information can create material harm.

The survey also found a policy gap. Only 41% of organisations reported using generative AI for security tasks under strict policy, while 39% said use was informal and not governed by policy. That informal activity is likely to be difficult to inventory, monitor or audit.

For professional services firms, this is especially important. AI features are increasingly built into familiar productivity, security and software platforms. Staff may adopt them without viewing the decision as a new technology deployment, even when prompts, uploaded documents or connected systems contain client information.

The central problem has shifted from integration to trust

In 2025, respondents saw integration with existing systems as the leading obstacle. In 2026, the main concerns were transparency and trust in AI decisions, cited by 40%, the efficacy of commercial AI products at 38%, and hallucination at 34%.

These concerns are supported by respondents’ operational experience. Sixty-three percent reported significant shortcomings when AI was used to detect or respond to threats, up from 45% in 2025. About two-thirds said an AI security tool had led their team in the wrong direction at least once during the previous 12 months.

The survey does not suggest that AI has no value. Organisations continue to move it into incident investigation, anomaly detection, automated response and forensic work because it can improve speed and capacity. The warning is that productivity gains do not prove reliability.

Many organisations are still measuring AI primarily through efficiency. Time and cost savings were the most commonly tracked measure, at 45%. Only 25% tracked recall, meaning the proportion of genuine threats the system detected, and just 17% formally tracked false-positive rates. An AI system can reduce manual effort while still missing important threats, so efficiency must be measured alongside accuracy, coverage and the consequences of error.

Human review remains essential, but it needs to be designed rather than assumed. Reviewers require enough subject knowledge, time and authority to challenge an AI output. A nominal approval step adds little protection if staff are expected to accept the system’s recommendation or cannot see the evidence behind it.

Governance is expanding on paper faster than in practice

Security teams are increasingly being asked to govern enterprise AI. Seventy-six percent of practitioner respondents said their team now had an AI governance role, up from 68% the previous year. However, only 36% reported a formal AI risk management and compliance programme, almost unchanged from 35% in 2025. A further 43% said they were still in the early stages of developing governance policies.

The difference between leadership and practitioner views is revealing. Half of senior security leaders said a formal AI risk programme existed, compared with 36% of practitioners answering the same question. This 14-point gap suggests that a programme recognised at leadership level may not yet be visible in day-to-day workflows, approvals, monitoring or accountability.

Third-party assurance shows a similar tension. Sixty-nine percent of organisations said they conducted AI-specific third-party assessments. Yet 47% of that group also trusted vendors to manage their own AI risks without auditing them. A questionnaire or contractual promise is not enough if an organisation cannot establish how a provider handles its information, tests model changes, manages subcontractors, controls access and responds to security incidents.

New Zealand’s Office of the Privacy Commissioner is clear that the Privacy Act 2020 applies when organisations use AI tools. It recommends completing a Privacy Impact Assessment before use and updating it regularly. This means AI governance cannot sit solely with IT or cybersecurity. Privacy, legal, risk, procurement, information management and business owners all have a role where personal or confidential information is involved.

MBIE’s voluntary Responsible AI Guidance for Businesses provides a broader local reference point for organisations developing their governance approach. The important next step is to turn principles and policy into controls that can be seen and tested in procurement, system access, staff workflows and assurance reporting.

AI-enabled attacks are present, but the fundamentals still work

Seventy-eight percent of SANS respondents said their organisation had observed confirmed or suspected AI-enabled attacks during the previous year. Ninety-five percent believed threat actors were using AI. Reported techniques were spread across deepfake content, AI-assisted vulnerability exploitation, AI-generated phishing, attacks on AI models, automated reconnaissance and AI-powered brute forcing.

The breadth of these techniques is more important than any single category. AI is not creating one new attack type with one matching control. It is helping attackers make familiar activity faster, cheaper, more convincing and easier to scale.

This aligns with the New Zealand National Cyber Security Centre’s June 2026 warning that AI is lowering barriers for malicious actors and shrinking the time between vulnerability discovery and exploitation. The NCSC urged leaders to assess risk and accountability, strengthen foundational controls, resource cyber leaders and stay engaged as the threat develops.

The SANS findings support that approach. The defences respondents rated most effective against AI-driven threats were behavioural detection, user awareness training, human analyst review, zero trust and multi-factor authentication. AI-specific security controls ranked lower.

The lesson is not that specialist AI controls are unnecessary. Organisations deploying models or agents may need protections against prompt injection, data poisoning, insecure tool use and model manipulation. But these should sit on top of sound identity security, least privilege, patching, monitoring, incident response and recovery arrangements.

What this means for your organisation

  1. Create a usable AI inventory. Record approved and unapproved tools, embedded AI features, connected data sources, business owners, users and the decisions each system can influence. Include personal accounts and free services where staff may be using them for work.
  2. Set controls according to consequence. Classify AI uses by the sensitivity of the data involved and the impact of an incorrect output. Require stronger testing, approval, logging and human review where AI can affect clients, security decisions, legal obligations or access to sensitive information.
  3. Measure reliability as well as efficiency. Define what success and failure look like before deployment. For security tools, this should include missed threats, false positives, output quality, override rates and performance drift, not only time saved.
  4. Strengthen vendor assurance. Establish where data is processed and retained, whether it is used to train models, which subprocessors are involved, how model or service changes are communicated, and what evidence supports security and performance claims. Reassess material providers over time rather than relying on a one-off review.
  5. Prepare people and incident plans. Train staff to recognise unreliable or manipulated AI output and to escalate concerns. Add AI-enabled phishing, deepfake impersonation, prompt injection, compromised AI agents and accelerated vulnerability exploitation to incident exercises and response playbooks.

The next stage of AI adoption is operational discipline

The SANS survey presents a balanced picture. AI is already delivering useful capability, and organisations are unlikely to reverse course. At the same time, confidence is uneven, failures are common, governance remains immature and attackers are adopting the same technology.

For New Zealand organisations, responsible adoption now depends less on producing another high-level policy and more on making governance visible in everyday work. That means knowing where AI is used, controlling what it can access, testing whether it performs as claimed, keeping accountable people in consequential decisions and preparing for AI-enabled incidents.

The organisations that do this well will not necessarily be those deploying AI fastest. They will be those able to show that AI is producing value within clear, tested and enforceable boundaries.

Survey scope

The 2026 SANS AI Survey received 536 responses from IT and security professionals globally. A separate survey module was completed by 57 CISOs and other senior security executives. All practitioner respondents confirmed that their organisation was implementing or planning to implement AI. The sample was not designed to measure AI use specifically in New Zealand, so its figures should be treated as indicators of international cybersecurity practice rather than estimates of local prevalence.

Sources

About the author

Campbell McKenzie is a Director at Incident Response Solutions, a New Zealand firm experienced in cyber incident response, digital forensics, investigations and technology risk. Through KiwiGen.AI, Campbell helps professional services firms adopt generative AI safely, with practical governance and controls.