The Mandate to Scale
Over the past year, the expectations placed on security and fraud teams have changed. Boards and executive teams are asking them to use AI to hunt threats faster, investigate more deeply, and keep up with a threat landscape that moves faster than most budget and planning cycles.
Cisco found that 85% of surveyed major enterprise customers were experimenting with, piloting, or deploying agentic AI, while only 5% had reached broad production.
Use of AI in cybersecurity is already high and rising. In CSC’s 2026 CISO survey, 57% of respondents said they use AI-based monitoring and enforcement tools, up from 50% the previous year, while 44% use AI for threat detection and fraud prevention, up from 36%.
However, inside most security and fraud teams, the day-to-day work still looks familiar.
Malware samples still get triaged by hand, one analyst at a time. Breach data still gets compared against known-compromised records through hours of manual searching. Investigations involving phones, messaging platforms, or external applications often require someone to work directly from a physical device. These workflows take time, and much of that time goes toward repetitive work rather than the decisions that require experience and judgment.
Teams are already finding ways to keep moving. Replica Cyber’s Exception Economy research found that every surveyed organization had granted at least one security exception in the previous year. Nearly half had also moved high-stakes work forward on the corporate network despite reservations.
Those decisions usually come from the pressure to just keep business moving. The work still needs to get done, even when the environment, approval process, or available tooling was designed for a different kind of task.
Security teams are worrying under that pressure at a challenging time. Alert volumes remain overwhelming, burnout is widespread, and AI governance has become another major responsibility for security leadership. Splunk found that 96% of surveyed CISOs now have responsibility for AI governance and risk management. The same Splunk research found that 98% cited high alert volumes as a stressor, while nearly two-thirds reported moderate to significant team burnout.
Of course, there is real demand for AI-powered security operations. Teams can already see where agents could take on repetitive work, accelerate investigations, and give analysts more time for decisions that require experience and judgment. Getting there requires more than access to a model via a security exception.
These workflows need controlled environments, clear permissions, reliable audit trails, and a safe way to work with sensitive data, untrusted content, external systems, and potentially risky actions. They also need approval processes that match the speed at which teams are being asked to operate.
Security and fraud leaders are being asked to scale before the systems around them are ready to scale with them.
Sources:
- Cisco, research on enterprise adoption of agentic AI
- CSC, CISO Outlook 2026
- Splunk, The CISO Report 2026
- Replica Cyber, The Exception Economy

