Listen to this Post

A new global study from Kai reveals that cybersecurity has entered a machine-speed era where human-driven security operations are struggling to keep pace with AI-powered attackers.
Artificial intelligence is fundamentally reshaping the cybersecurity battlefield, and according to Kai’s 2026 State of Autonomous Defense Report, most security executives now believe attackers have seized the advantage. The report, based on a survey of 500 Chief Information Security Officers (CISOs) from enterprises generating at least $500 million in annual revenue, paints a picture of an industry transitioning from manual operations toward autonomous cyber defense while wrestling with trust, governance, and operational challenges.
Attackers Are Winning the AI Race
One of the report’s most striking findings is that 63% of CISOs believe cybercriminals currently hold the AI advantage, while only 18% believe defenders are ahead. Although 89% of organizations consider themselves at least somewhat prepared for AI-driven attacks, only 28% describe their readiness as strong, highlighting a significant confidence gap.
Kai argues that adversaries have been quicker to operationalize AI for reconnaissance, vulnerability discovery, and exploitation, while many enterprises still rely heavily on human analysts for defensive decision-making.
Manual Security Operations Are Becoming a Bottleneck
Despite years of investment in cybersecurity tools, vulnerability management remains largely manual.
According to the survey:
- 65% of organizations still perform at least half of vulnerability management manually.
- Only 6% describe their operations as primarily machine-led.
- 60% require more than seven days to remediate a critical vulnerability.
- 48% leave at least one-quarter of known vulnerabilities unpatched for more than 30 days.
As attackers increasingly exploit vulnerabilities within days—or even hours—these remediation timelines create growing windows of opportunity for cybercriminals.
Security Team Burnout Is Becoming a Security Risk
The operational burden extends beyond technology.
The report found that 78% of CISOs believe vulnerability and exposure management contributes to burnout among security teams, suggesting that staffing challenges are no longer simply an HR issue but a direct cybersecurity concern. Fatigued analysts inevitably increase the likelihood of missed vulnerabilities, delayed remediation, and operational errors.
Automation Is Moving Beyond Detection
While organizations remain cautious, automation is steadily progressing from analysis toward action.
The survey reveals that organizations already allow automated systems to perform several critical security functions without human approval:
- Asset discovery (55%)
- Vulnerability prioritization (49%)
- Response workflow escalation (44%)
- Remediation validation (40%)
- Automated remediation (32%)
However, full automation remains uncommon, with 57% of organizations reporting that less than half of remediation workflows are machine-led. Human oversight continues to dominate production environments.
Trust—Not Budget. Is Slowing AI Adoption
Interestingly, financial constraints are no longer viewed as the primary obstacle.
Instead, organizations cite:
- Lack of trust in automated decisions (52%)
- Governance and compliance concerns (43%)
- Skills shortages (38%)
- Integration complexity (38%)
Only 21% identified budget limitations as the biggest barrier to expanding automation.
The findings suggest that explainability, accountability, and governance frameworks will become decisive factors in determining how quickly autonomous cybersecurity is adopted.
Autonomous Defense Is Becoming the Next Operating Model
Despite current hesitation, CISOs overwhelmingly expect automation to become central to cybersecurity operations.
Kai reports that:
- 45% expect vulnerability management to become mostly or primarily machine-led within the next 12 to 18 months.
- Human-driven ticketing and remediation workflows are expected to lose effectiveness first as attackers continue accelerating their operations.
- Most organizations plan to finance AI security initiatives through existing IT transformation budgets rather than creating separate innovation funds.
The report concludes that future competitive advantage will depend less on detecting threats and more on enabling trusted autonomous response.
Industry Context
The report also highlights the unprecedented scale facing defenders.
According to Kai:
- More than 48,000 new CVEs were published during 2025—an average of 132 vulnerabilities every day.
- The FBI recorded over $20 billion in reported cybercrime losses during 2025, a 26% increase year-over-year.
- NIST has shifted the National Vulnerability Database toward prioritizing only selected vulnerabilities because the volume has exceeded what its previous operating model could process.
These developments reinforce the growing mismatch between machine-speed attackers and human-speed defensive operations.
UnderCode Analysis
Kai’s findings reflect a broader transformation already visible across enterprise cybersecurity.
The cybersecurity industry appears to be entering a period similar to the evolution of cloud computing a decade ago: organizations initially hesitate due to governance and trust concerns, but competitive pressure gradually makes adoption unavoidable.
Over the next several years, organizations that continue relying primarily on manual vulnerability management are likely to experience increasing remediation backlogs as vulnerability disclosure volumes continue growing. Meanwhile, enterprises that successfully implement explainable and governed autonomous remediation platforms may significantly reduce attacker dwell time while easing analyst workload.
Rather than replacing security professionals, autonomous defense is more likely to shift human expertise toward governance, validation, threat hunting, and strategic decision-making while allowing AI agents to handle repetitive operational tasks.
The report suggests that the defining challenge of the next generation of cybersecurity will not be whether organizations adopt AI—but whether they develop enough confidence to allow it to take action at machine speed.
Source: Kai – 2026 State of Autonomous Defense Report. Survey of 500 CISOs conducted by Wakefield Research between June 15–29, 2026.
Fact Checker
✔ Verified: Kai’s 2026 State of Autonomous Defense Report surveyed 500 CISOs from private-sector organizations generating at least $500 million in annual revenue, providing the basis for all survey findings in the report.
✔ Verified: 63% of CISOs believe AI-powered attackers currently have the advantage over defenders, while only 18% believe defenders hold the advantage.
✔ Verified: 65% of respondents said at least half of their vulnerability and exposure management activities are still performed manually.
✔ Verified: 60% reported taking more than seven days to remediate a critical vulnerability, and 48% leave at least one-quarter of known vulnerabilities unpatched for more than 30 days.
✔ Verified: 52% identified a lack of trust in automated decisions as the biggest obstacle to expanding autonomous security operations, ranking higher than budget concerns (21%).
✔ Verified: 45% expect vulnerability and exposure management to become mostly or primarily machine-led within the next 12–18 months.
Prediction
🟢 (+1) Positive: Organizations that successfully deploy explainable AI with strong governance are likely to reduce remediation times significantly over the next few years.
🟢 (+1) Positive: Autonomous vulnerability remediation is expected to become a standard capability among large enterprises rather than an experimental feature.
🟢 (+1) Positive: Security analysts will increasingly transition from manually applying patches to supervising, validating, and optimizing AI-driven security operations.
🟢 (+1) Positive: Vendors that provide transparent decision-making, auditability, and accountability for autonomous actions are likely to gain a competitive advantage as enterprise adoption accelerates.
🟢 (+1) Positive: Enterprises that combine autonomous remediation with human oversight are likely to respond faster to emerging threats while reducing analyst burnout.




