Nearly three-quarters of organizations haven't practiced responding to an AI-related security breach, even as they deploy artificial intelligence more widely across their security operations, according to ISACA's 2026 State of Cyber report. The research found that 71% of organizations have conducted no AI incident response drills. Just 3% maintain mature, formal protocols for AI-specific incidents, while 30% haven't started planning their response at all. These exercises would prepare teams for scenarios like confidential information leaked through AI platforms, AI-powered phishing and fraud campaigns, and unauthorized use of generative AI by staff or insiders.

Adoption is racing ahead of preparation, the report shows. Some 37% of organizations now use AI to automate threat detection and response, up eight percentage points from 2025, while 35% deploy it for routine security operations and 29% for endpoint security. Security professionals are driving that expansion, with 54% saying they or their team helped develop, onboard, or roll out AI solutions. Some 60% have helped shape AI policies within their organization. Among European IT and cybersecurity professionals surveyed, 38% reported their organization experienced more cyberattacks than a year earlier, and 54% anticipate an incident within the next 12 months. Social engineering was the most frequently reported attack method, cited by 46%, and ISACA noted it's increasingly powered by AI. The cybersecurity workforce is feeling the pressure: 72% said their job is more stressful than five years ago, with the more complicated threat environment the primary driver, while 56% reported their teams are understaffed and 55% underfunded.

"Organizations can effectively use AI for preventing and detecting cyber threats. However, its governance should be non-negotiable," said Chris Dimitriadis, ISACA's global chief strategy officer. The report warns that AI allows attackers to operate "at the speed of intent," automating attacks that once took days or weeks. Dimitriadis explained governance is needed both to keep employees' use of AI safe and to shield businesses from AI-generated threats, pointing to CMMI's AI Maturity Model as a benchmark. Beyond the threat landscape, 57% of respondents blamed unrealistic expectations and excessive workload for stress, while 35% said staff weren't sufficiently trained or skilled. A fifth of companies take no action on burnout, though among those that do, 55% offer flexible hours and 46% encourage staff to take breaks and vacation.

The report concludes that budgets are too often "sunk into crisis response" instead of the workforce and training needed to prevent attacks. Dimitriadis added that better funding and a clear plan for improving cyber resilience should be a C-suite priority. The research signals that as organizations rush to harness AI's defensive capabilities, they're simultaneously exposing themselves to a new category of risk they haven't rehearsed managing, leaving security teams stretched thin while facing both traditional and AI-enabled threats at accelerating speed. The gap between AI deployment and incident readiness suggests that governance frameworks and formal response protocols need to catch up before the next breach forces organizations to learn on the fly. Leadership teams may find themselves choosing between funding innovation and funding the guardrails that make innovation sustainable.