AI is officially mainstream in security operations. According to Prophet Security's State of AI in Security Operations 2026 report (produced from ViB’s survey of 250+ cybersecurity pros), 40% of security teams now use AI daily. Another 56% are currently testing it out, and only 4% have no plans to adopt it.

For the teams already using AI, what is actually changing? Here are the ten biggest takeaways from the report.

1. Security teams are drowning in alerts

The average security team gets about 100 alerts every day, but larger companies often deal with close to 1,000. In fact, over a quarter of teams face more than 500 alerts daily.

Unfortunately, team sizes haven't kept up with the workload. While some massive organizations have over 100 analysts, many are running on skeleton crews of fewer than ten people. Because of this, it takes an average of 75 minutes to thoroughly investigate a single alert, and alerts often sit untouched for nearly an hour before anyone even looks at them.

When attackers can break out and start moving through a network in 29 minutes, a two-hour cycle from alert to answer stops being an efficiency problem and becomes a containment problem. Analysts are feeling the strain from high volume, slow alert triage, and constant noise.

2. Missed alerts lead to real damage

Because teams are so overwhelmed, about 28% of alerts are never investigated. This has very real consequences: 60% of respondents admitted that an alert they ignored or missed later turned into a serious issue, like a data breach or system downtime. For a third of those respondents, this happened three or more times last year.

And the problem is actually worse than the numbers show. Up to 40% of organizations have simply turned off certain security alerts because they didn't have the manpower to check them. Tuning away a rule that never produces an escalation is sound detection engineering. Switching one off because nobody has time to read what it produces narrows coverage exactly where the team cannot afford to look, which means the real alert load and the real exposure are both bigger than the reported numbers.

3. Hackers are using AI, too

More than half (56%) of security pros saw AI-driven attacks increase over the past year, especially in the finance and healthcare industries. The most common threats are AI-written phishing emails, deepfake audio and video scams, massive credential-stuffing attacks, and AI-generated malware.

4. AI is the top priority for security teams

For the first time, both securing AI systems and using AI for security are top priorities, beating out traditional concerns like cloud and data security. The drivers teams name are operational: faster response times (73%), better detection coverage (71%), doing more with the same team (56%), and less analyst burnout (37%).

5. AI is actually working

For teams using AI, it's delivering real results. Nearly three-quarters (72%) say AI has cut their investigation time by at least 25%, which works out to roughly 25 minutes back on every alert. Teams are also seeing better 24/7 coverage, fewer false alarms, and more time for analysts to focus on higher-level work.

6. Building your own AI is hard (and often fails)

Most AI users (72%) tried to build their own internal AI tools, and for a lot of teams the question of whether you can build an autonomous SOC in-house is still open. Building brought no speed advantage: teams that attempted a build reported investigation-time gains of 25% or more at the same rate as AI users overall (73% versus 72%). 

Durability is where they differed. Almost half (46%) of these DIY projects were eventually abandoned, never reached production, or were replaced by a commercial product.

7. Trust takes time, and AI isn't flying solo yet

Security teams generally trust AI, but with limits. While most say AI's conclusions match a human expert's opinion most of the time, 57% still require a human to review every single AI decision before closing an alert.

Because of this, AI mostly acts as an assistant. Most teams (44%) use it to recommend actions for humans to execute, and 30% let it handle low-risk automated remediation on its own. Not one respondent grants AI full, unsupervised autonomy.

8. Saved time goes toward threat hunting

When AI frees up time, teams use it to actively hunt for hidden threats. About half of the teams hunt regularly, and it pays off: 38% have found malicious activity that their automated tools missed. Teams that hunt weekly or more report a 49% hit rate, against 8% for teams that never hunt.

9. Roles are changing, but team sizes are holding

Despite fears of AI replacing humans, 57% of respondents expect their team size to stay the exact same, and 9% even expect it to grow. Instead of firing people, companies are shifting roles. As AI takes over basic triage, human analysts are moving into more advanced roles like incident response, threat hunting, and testing defenses.

10. Privacy is the biggest hurdle

The most-cited roadblock is regulatory: 44% of teams are worried about data privacy and how AI models are trained. Another 41% struggle with explainability, meaning they need to know why the AI reached the conclusion it did. Fortunately, these are questions you can answer by thoroughly evaluating the AI vendors you buy from rather than just waiting on the sidelines.

The Bottom Line

Almost everyone is moving toward AI in their security operations, mostly because the bad guys are already using it. The most successful teams follow a clear playbook: they use AI to investigate everything, validate its work systematically, slowly give it more autonomy as it earns trust, and use the time they save to actively hunt for threats.

How Prophet Security Works

Everything above describes one gap: the distance between the alerts a SOC receives and the ones it has time to investigate. Prophet Security, a leading agentic AI SOC platform recognized in Rising in Cyber 2026, an honor voted on by more than 150 CISOs and security leaders, built its platform to close it.

Prophet AI investigates every alert at every severity with senior-analyst depth, hunts for the threats that never produce an alert, and turns what it finds into new and tuned detections on the stack a team already runs.

It plans each investigation as it goes rather than matching alerts to a static playbook. It decides what to ask, queries the SIEM, EDR, identity, cloud, and email tools directly, pivots on what it finds, and reaches an evidence-backed determination, including returning "inconclusive" instead of guessing. Every question asked, every query run, and every piece of evidence retrieved is recorded, so an analyst can copy the query Prophet ran and execute it themselves.

That answers the two barriers the survey ranks highest. On explainability, every investigation is a complete audit trail rather than a score. On privacy, customer data never trains models, deployments are single-tenant, and the data plane can run inside the customer's own VPC.

Autonomy is granted per category of action. Response actions are scoped and permissioned by the customer, human approval is the default, and the range widens as the track record earns it, which is the same conservative progression the survey shows teams actually follow.

The freed capacity has somewhere to go. Prophet AI Threat Hunter runs expert-curated and scheduled hunts against a live profile of the organization and its coverage gaps, and Prophet AI Detection Engineer turns what investigations and hunts reveal into backtested, reviewable detections. At JB Poindexter, Prophet AI brought mean time to investigate under four minutes and avoided 1,469 analyst hours.

You can see Prophet AI in action and request a demo.

Found this article interesting? This article is a contributed piece from one of our valued partners. Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.