AI in Cybersecurity: what works, what doesn't, and what it costs (October 2026)
AI already helps with the tedious parts of cybersecurity: generating fuzz tests that have found real bugs, triaging reported phishing emails and explaining unfamiliar commands to analysts. It also helps attackers. In a 2024 study, fully automated AI phishing emails drew a 54% click rate, the same as emails written by human experts. AI cannot yet be trusted to detect vulnerabilities on its own or to run a security operations center without analysts, and staff cannot be expected to spot AI-written fraud by eye.
State of AI in Cybersecurity · October 2026
As of October 2026, AI in cybersecurity is ready for generating fuzz tests, still early for patching, phishing triage and analyst support, and not ready to detect vulnerabilities alone, run a security operations center, or stop AI-written phishing and deepfake fraud.
- Fuzz test generation for open source
Backed by trials or large deployments
- Finding and patching open-source bugs
- Triaging reported phishing emails
- Explaining commands and telemetry
Promising, limited outcome data
- Vulnerability detection without review
- Autonomous security operations
- Spotting AI phishing by eye
- Trusting familiar faces on video
- Unrestricted AI access to data
Evidence says avoid or add safeguards
What AI can reliably do in Cybersecurity today
- 1
Proven Write fuzz tests that find new vulnerabilities in widely used open-source code.
Evidence
Google Security Blog, Nov 2024: AI-generated fuzz targets extended 272 C/C++ projects on OSS-Fuzz and found 26 new vulnerabilities, including OpenSSL CVE-2024-9143, which had likely existed for about two decades. Source ↗
- 2
Early Find and patch vulnerabilities in open-source software, with humans reviewing the results.
Evidence
DARPA AI Cyber Challenge final, 8 Aug 2025: finalists found 54 of 63 synthetic vulnerabilities and patched 43, and found 18 real zero-days, patching 11. Average patch took about 45 minutes at about $152 per task. A competition, not production use. Source ↗
- 3
Early Triage reported phishing emails faster and more accurately, with analysts reviewing the verdicts.
Evidence
Microsoft-authored randomized trial, Oct 2025: 167 security analysts; F1 up 77% and up to 6.5 times as many true positives found per analyst-minute under corpus ground truth. Run by the vendor. Source ↗
- 4
Early Help analysts interpret unfamiliar commands and telemetry and word technical write-ups.
Evidence
Preprint under review, 2025: 10 months, 3,090 queries from 45 SOC analysts. Analysts used LLMs mainly for sensemaking, in one to three turns, not for final verdicts. A usage study, not an outcome trial. Source ↗
- 5
Early Lower breach costs when security teams use AI and automation extensively.
Evidence
IBM Cost of a Data Breach 2025 (600 organizations): extensive use of security AI and automation was associated with $1.9 million lower average cost and breaches 80 days shorter. Correlational, not a controlled trial. Source ↗
What it can't do, or where the risk is
- 1
Can't Detect vulnerabilities in real code reliably on its own.
Evidence
PrimeVul (ICSE 2025): a 7B code model scored 68.26% F1 on an older benchmark but 3.09% on PrimeVul; GPT-3.5 and GPT-4 performed like random guessing under the strictest setting. Source ↗
- 2
Can't Handle most security-operations tasks autonomously.
Evidence
ITBench (IBM and UIUC, arXiv Feb 2025): the best agents resolved 25.2% of CISO scenarios and 13.8% of SRE scenarios, out of 94 real-world scenarios. Source ↗
- 3
Can't Rely on staff spotting AI-written phishing by eye.
Evidence
Heiding et al., arXiv Nov 2024: 101 participants; click rates were 12% for generic phishing, 54% for human-expert emails, 54% for fully AI-automated emails and 56% for AI with human review. Source ↗
- 4
Can't Trust a video call because the faces and voices look familiar.
Evidence
AI Incident Database #634 (30 reports, incl. CNN and The Guardian): in Feb 2024 a finance employee at Arup made multiple transfers totaling about US$25 million (HK$200 million) after a video call with deepfaked executives. Source ↗
- 5
Can't Be connected to sensitive data without AI-specific access controls.
Evidence
IBM Cost of a Data Breach 2025 (600 organizations): 13% reported breaches of AI models or applications; 97% of those lacked proper AI access controls; 8% did not know whether they had been compromised. Source ↗
Where to start
Small business owner
Add call-back and second-approver steps for payments and bank-detail changes. Staff cannot reliably spot AI-written emails or deepfaked video calls.
Security team
Pilot AI on phishing-report triage and command explanations, with analysts keeping the final verdict. Track precision and time per alert before expanding.
Software or open-source maintainer
Try AI-assisted fuzzing on parsers and input handlers, and have a maintainer review every finding and patch before release.
Regulation & risk
Laws, rules and official guidance that commonly apply when AI is used in Cybersecurity.
| Name | Applies to | Official source | When it applies |
|---|---|---|---|
| EU NIS2 Directive | EU | digital-strategy.ec.europa.eu | Essential and important entities: cybersecurity risk-management measures and notification of significant incidents |
| EU Cyber Resilience Act | EU | digital-strategy.ec.europa.eu | Makers of products with digital elements: reporting obligations from 11 September 2026, main obligations from 11 December 2027 |
| SEC cybersecurity disclosure rules (Form 8-K Item 1.05, Reg S-K Item 106) | US | sec.gov | Public companies: report material incidents within four business days of deciding they are material; describe risk management annually |
| GDPR (Art. 32 security, Art. 33 breach notification) | EU/EEA | commission.europa.eu | Personal data is involved in an incident or is sent to an AI tool |
| NIST Cybersecurity Framework 2.0 | US (voluntary) | nist.gov | Organizing and measuring a security program; NIST has a draft guide on using AI for CSF analysis |
| EU AI Act (Art. 15 robustness and cybersecurity; Art. 50 transparency) | EU | digital-strategy.ec.europa.eu | High-risk AI systems must be resilient to attacks; chatbots and synthetic content must be disclosed |
| SOC 2 (AICPA) | Industry | aicpa-cima.com | A vendor claims SOC 2 for the security tool you buy |
| Computer Fraud and Abuse Act | US | justice.gov | Scanning and testing tools, including AI-driven ones, used against systems you do not own or are not authorized to test |
This list is a starting point for your own compliance review, not legal advice. Last reviewed 2026-10-03.
Cost & deployment reality
Verified starting prices for 1 of the tools below: $95 to $95 per month (median $95).
Breach costs frame the budget. IBM's 2025 study of 600 organizations put the global average breach at $4.44 million and the U.S. average at $10.22 million. Organizations using AI and automation extensively spent $1.9 million less and cut the breach lifecycle by 80 days against a 241-day global average; the comparison is correlational.
AI security products are usually metered or quoted. Microsoft Security Copilot bills provisioned capacity by the hour in security compute units, and Microsoft 365 E5 includes 400 units a month per 1,000 licenses, capped at 10,000. In DARPA's AI Cyber Challenge the finalists' systems averaged about $152 per task, a competition figure rather than product pricing.
AI-written attacks make awareness training alone insufficient. In one study fully automated phishing emails drew a 54% click rate, equal to human experts. Add call-back and second-approver checks for payments: Arup lost about US$25 million after a video call with deepfaked executives.
Secure the AI itself. OWASP says it is unclear whether fool-proof prevention exists for prompt injection, so it recommends least privilege, human approval for high-risk operations and regular adversarial testing. IBM found 97% of organizations with an AI-related breach lacked AI access controls. NIST has a draft quick-start guide on using AI for CSF analysis, open for comment until 15 October 2026.
Scenarios and tools for Cybersecurity
AI security copilots
| Tool | Pricing model | Free tier | Starting price | Compliance claims | Official site | Last verified |
|---|---|---|---|---|---|---|
| | Not verified | Not verified | Not verified | Not verified | Online (redirects) (2026-09-28) | 2026-10-01 |
LLM application security
| Tool | Pricing model | Free tier | Starting price | Compliance claims | Official site | Last verified |
|---|---|---|---|---|---|---|
| | Freemium | Not verified | Not verified | Not verified | Online (redirects) (2026-09-28) | Not yet |
Fraud & traffic scoring
| Tool | Pricing model | Free tier | Starting price | Compliance claims | Official site | Last verified |
|---|---|---|---|---|---|---|
| | Freemium | Yes: 5,000 identifications, one-time | $95 / month | Not verified | Online (2026-09-24) | 2026-10-01 |
Compliance automation
| Tool | Pricing model | Free tier | Starting price | Compliance claims | Official site | Last verified |
|---|---|---|---|---|---|---|
| | Not verified | Not verified | Not verified | Not verified | Online (2026-09-26) | Not yet |
SaaS governance
| Tool | Pricing model | Free tier | Starting price | Compliance claims | Official site | Last verified |
|---|---|---|---|---|---|---|
| | Freemium | Not verified | Not verified | Not verified | Online (2026-09-24) | Not yet |
Vendors & implementers
No vendors listed yet.
Four ways to get this done
Editorial picks are ranked by verified facts. Sponsored slots are labeled and never affect the ranking. How to choose →
Use a tool yourself
Compare the tools listed on this page. See the tool list ↓
Hire an AI-native service
- Editorial listing · Not paidVisit secure.com ↗
Governed AI security teammates plus managed SecOps, exposure management and vCISO services over the tools you already run.
- Editorial listing · Not paidVisit scanninja.ai ↗
Managed vulnerability remediation and SOC 2 / CMMC readiness delivered by security experts on a tenant-isolated AI platform.
- Editorial listing · Not paidVisit bitscaled.tech ↗
Managed IT, cybersecurity and cloud operations run through an in-house AI-native ERP control plane with accountable human operators.
- Editorial listing · Not paidVisit treeline.ai ↗
An outsourced IT, security and compliance team run on an AI-powered IT operating system.
Recent changes: Cybersecurity tools
Last verified: 2026-10-03 · auto-checked 2026-09-28 · Reviewed by Toolsfine editorial
- Checkpoint genAI - AI Security Copilot Tool · pricing model · — → unknown ·
- ShieldLabs · pricing page URL · — → https://shieldlabs.ai/pricing ·
- ShieldLabs · starting price · — → 95 ·
- ShieldLabs · free tier · — → {"exists":true,"limits":"5,000 identi… ·
- ShieldLabs · pricing model · — → Freemium ·
- ShieldLabs · site status · — → Online ·
- CloudEagle AI · site status · — → Online ·
- Checkpoint genAI - AI Security Copilot Tool · official URL · — → https://www.checkpoint.com/ai/factory… ·