SecurityBrief US - Technology news for CISOs & cybersecurity decision-makers
United States
Security chiefs more worried than staff over AI governance

Security chiefs more worried than staff over AI governance

Wed, 12th Aug 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

Rapid7 has published global research showing that executive security leaders are more concerned than frontline practitioners about AI governance in cybersecurity operations. Executives were 1.6 times more likely to report high concern about how AI vendors handle security data.

The findings suggest a shift in the debate around AI in security teams. Adoption is now widespread, and governance is becoming a more prominent issue for senior decision-makers.

The study, conducted by Omdia, surveyed 500 security professionals across North America, EMEA and Asia-Pacific. Respondents came from organisations with 100 employees to more than 20,000, across sectors including manufacturing, technology, finance, business services and retail.

Operational use of AI appears well established among the organisations surveyed. Nearly all respondents said AI was having a positive impact on security operations, while 98% of those already using it said it was helping to reduce alert fatigue.

This suggests many security operations centres have moved beyond early trials to routine deployment. The survey also found that 92% of respondents believe human oversight remains essential, indicating that organisations still want analysts involved in judgement and decision-making even as AI takes on more repetitive tasks.

Another finding concerned outsourced security services. Some 86% of respondents said managed detection and response providers that integrate AI have an advantage over more traditional services.

Governance focus

The research points to a gap between those running security tools day to day and those responsible for broader risk and accountability. Practitioners reported confidence in AI's operational role, while executive leaders expressed greater concern about how vendors manage sensitive security information.

That concern reflects wider expectations of AI systems in security environments. Respondents highlighted transparency in AI decision-making, visibility into model performance and data privacy protections among the issues they expect providers to address.

For boards and senior security leaders, these questions are increasingly tied to governance rather than simple product performance. As AI becomes more deeply embedded in security workflows, scrutiny is shifting from whether it works to how it is controlled, monitored and explained.

Rapid7 said the findings show AI is now part of mainstream security operations rather than a developing add-on. The focus, it argues, is shifting towards responsible deployment and clearer accountability around vendor practices.

The survey sample helps explain that emphasis. Executive security leaders such as CSOs and CISOs made up 41% of respondents, while 40% came from security and security operations management. Engineers, architects, threat hunters and incident responders accounted for smaller shares.

That profile helps explain why the results reflect both operational and strategic views of AI use. Security managers and analysts may judge AI by whether it eases workloads and improves workflow efficiency, while executives are more likely to focus on data handling, risk exposure and governance standards.

Human role

The findings also suggest that enthusiasm for AI in the security operations centre has limits. Although respondents reported strong benefits, the overwhelming support for human oversight indicates that organisations do not view AI as a replacement for security staff.

Instead, the survey presents AI as a support tool for automating repetitive tasks, reducing alert volumes and helping analysts work through investigations more effectively. In that context, trust in the technology appears to depend not only on outcomes but also on whether people remain accountable for final decisions.

That distinction matters as security vendors market AI more aggressively in operational settings. Buyers appear willing to adopt the technology, but they are also demanding clearer answers on what data is being used, how systems reach conclusions and where responsibility sits when problems arise.

For providers of managed detection and response services, the survey suggests AI integration has become a competitive factor in customer expectations. At the same time, the emphasis on transparency and privacy means the market may reward providers that can explain their use of AI rather than simply advertise it.

Dejan Decklich, Chief Product and Technology Officer at Rapid7, described the change in emphasis. "The conversation has changed," Decklich said. "Security teams are no longer asking whether AI belongs in the SOC; they're asking how to govern it responsibly. Organisations want AI that helps analysts move faster and work more effectively, but they also expect transparency, accountability, and human expertise to remain central to security operations."

Omdia said the next phase of AI use in security is likely to depend on trust rather than basic acceptance. "Our research shows organisations have largely accepted AI as part of modern security operations," said Dave Gruber, Principal Analyst at Omdia. "The next phase of adoption will be defined by trust. Security leaders increasingly want solutions that combine AI-driven efficiency with transparency, governance, and human expertise."