AI in Cybersecurity: what works, what doesn't, and what it costs (October 2026)

AI already helps with the tedious parts of cybersecurity: generating fuzz tests that have found real bugs, triaging reported phishing emails and explaining unfamiliar commands to analysts. It also helps attackers. In a 2024 study, fully automated AI phishing emails drew a 54% click rate, the same as emails written by human experts. AI cannot yet be trusted to detect vulnerabilities on its own or to run a security operations center without analysts, and staff cannot be expected to spot AI-written fraud by eye.

State of AI in Cybersecurity · October 2026

As of October 2026, AI in cybersecurity is ready for generating fuzz tests, still early for patching, phishing triage and analyst support, and not ready to detect vulnerabilities alone, run a security operations center, or stop AI-written phishing and deepfake fraud.

Ready now 1
  • Fuzz test generation for open source

Backed by trials or large deployments

Early 3
  • Finding and patching open-source bugs
  • Triaging reported phishing emails
  • Explaining commands and telemetry

Promising, limited outcome data

Not ready 5
  • Vulnerability detection without review
  • Autonomous security operations
  • Spotting AI phishing by eye
  • Trusting familiar faces on video
  • Unrestricted AI access to data

Evidence says avoid or add safeguards

What AI can reliably do in Cybersecurity today

  1. 1

    Proven Write fuzz tests that find new vulnerabilities in widely used open-source code.

    Evidence

    Google Security Blog, Nov 2024: AI-generated fuzz targets extended 272 C/C++ projects on OSS-Fuzz and found 26 new vulnerabilities, including OpenSSL CVE-2024-9143, which had likely existed for about two decades. Source ↗

  2. 2

    Early Find and patch vulnerabilities in open-source software, with humans reviewing the results.

    Evidence

    DARPA AI Cyber Challenge final, 8 Aug 2025: finalists found 54 of 63 synthetic vulnerabilities and patched 43, and found 18 real zero-days, patching 11. Average patch took about 45 minutes at about $152 per task. A competition, not production use. Source ↗

  3. 3

    Early Triage reported phishing emails faster and more accurately, with analysts reviewing the verdicts.

    Evidence

    Microsoft-authored randomized trial, Oct 2025: 167 security analysts; F1 up 77% and up to 6.5 times as many true positives found per analyst-minute under corpus ground truth. Run by the vendor. Source ↗

  4. 4

    Early Help analysts interpret unfamiliar commands and telemetry and word technical write-ups.

    Evidence

    Preprint under review, 2025: 10 months, 3,090 queries from 45 SOC analysts. Analysts used LLMs mainly for sensemaking, in one to three turns, not for final verdicts. A usage study, not an outcome trial. Source ↗

  5. 5

    Early Lower breach costs when security teams use AI and automation extensively.

    Evidence

    IBM Cost of a Data Breach 2025 (600 organizations): extensive use of security AI and automation was associated with $1.9 million lower average cost and breaches 80 days shorter. Correlational, not a controlled trial. Source ↗

Code and alerts come in, AI fuzzes, triages or drafts a fix, and an analyst confirms the result.

What it can't do, or where the risk is

  1. 1

    Can't Detect vulnerabilities in real code reliably on its own.

    Evidence

    PrimeVul (ICSE 2025): a 7B code model scored 68.26% F1 on an older benchmark but 3.09% on PrimeVul; GPT-3.5 and GPT-4 performed like random guessing under the strictest setting. Source ↗

  2. 2

    Can't Handle most security-operations tasks autonomously.

    Evidence

    ITBench (IBM and UIUC, arXiv Feb 2025): the best agents resolved 25.2% of CISO scenarios and 13.8% of SRE scenarios, out of 94 real-world scenarios. Source ↗

  3. 3

    Can't Rely on staff spotting AI-written phishing by eye.

    Evidence

    Heiding et al., arXiv Nov 2024: 101 participants; click rates were 12% for generic phishing, 54% for human-expert emails, 54% for fully AI-automated emails and 56% for AI with human review. Source ↗

  4. 4

    Can't Trust a video call because the faces and voices look familiar.

    Evidence

    AI Incident Database #634 (30 reports, incl. CNN and The Guardian): in Feb 2024 a finance employee at Arup made multiple transfers totaling about US$25 million (HK$200 million) after a video call with deepfaked executives. Source ↗

  5. 5

    Can't Be connected to sensitive data without AI-specific access controls.

    Evidence

    IBM Cost of a Data Breach 2025 (600 organizations): 13% reported breaches of AI models or applications; 97% of those lacked proper AI access controls; 8% did not know whether they had been compromised. Source ↗

AI-written phishing works as well as human experts, deepfaked video calls have cost companies millions, and vulnerability detectors still guess.

Where to start

Small business owner

Add call-back and second-approver steps for payments and bank-detail changes. Staff cannot reliably spot AI-written emails or deepfaked video calls.

Security team

Pilot AI on phishing-report triage and command explanations, with analysts keeping the final verdict. Track precision and time per alert before expanding.

Software or open-source maintainer

Try AI-assisted fuzzing on parsers and input handlers, and have a maintainer review every finding and patch before release.

Regulation & risk

Laws, rules and official guidance that commonly apply when AI is used in Cybersecurity.

NameApplies toOfficial sourceWhen it applies
EU NIS2 DirectiveEUdigital-strategy.ec.europa.euEssential and important entities: cybersecurity risk-management measures and notification of significant incidents
EU Cyber Resilience ActEUdigital-strategy.ec.europa.euMakers of products with digital elements: reporting obligations from 11 September 2026, main obligations from 11 December 2027
SEC cybersecurity disclosure rules (Form 8-K Item 1.05, Reg S-K Item 106)USsec.govPublic companies: report material incidents within four business days of deciding they are material; describe risk management annually
GDPR (Art. 32 security, Art. 33 breach notification)EU/EEAcommission.europa.euPersonal data is involved in an incident or is sent to an AI tool
NIST Cybersecurity Framework 2.0US (voluntary)nist.govOrganizing and measuring a security program; NIST has a draft guide on using AI for CSF analysis
EU AI Act (Art. 15 robustness and cybersecurity; Art. 50 transparency)EUdigital-strategy.ec.europa.euHigh-risk AI systems must be resilient to attacks; chatbots and synthetic content must be disclosed
SOC 2 (AICPA)Industryaicpa-cima.comA vendor claims SOC 2 for the security tool you buy
Computer Fraud and Abuse ActUSjustice.govScanning and testing tools, including AI-driven ones, used against systems you do not own or are not authorized to test

This list is a starting point for your own compliance review, not legal advice. Last reviewed 2026-10-03.

Cost & deployment reality

Verified starting prices for 1 of the tools below: $95 to $95 per month (median $95).

Breach costs frame the budget. IBM's 2025 study of 600 organizations put the global average breach at $4.44 million and the U.S. average at $10.22 million. Organizations using AI and automation extensively spent $1.9 million less and cut the breach lifecycle by 80 days against a 241-day global average; the comparison is correlational.

AI security products are usually metered or quoted. Microsoft Security Copilot bills provisioned capacity by the hour in security compute units, and Microsoft 365 E5 includes 400 units a month per 1,000 licenses, capped at 10,000. In DARPA's AI Cyber Challenge the finalists' systems averaged about $152 per task, a competition figure rather than product pricing.

AI-written attacks make awareness training alone insufficient. In one study fully automated phishing emails drew a 54% click rate, equal to human experts. Add call-back and second-approver checks for payments: Arup lost about US$25 million after a video call with deepfaked executives.

Secure the AI itself. OWASP says it is unclear whether fool-proof prevention exists for prompt injection, so it recommends least privilege, human approval for high-risk operations and regular adversarial testing. IBM found 97% of organizations with an AI-related breach lacked AI access controls. NIST has a draft quick-start guide on using AI for CSF analysis, open for comment until 15 October 2026.

Scenarios and tools for Cybersecurity

AI security copilots

Tool Pricing model Free tier Starting price Compliance claims Official site Last verified
Checkpoint genAI - AI Security Copilot Tool Not verified Not verified Not verified Not verified Online (redirects) (2026-09-28) 2026-10-01

LLM application security

Tool Pricing model Free tier Starting price Compliance claims Official site Last verified
ProtectAI - Secure LLM Applications Freemium Not verified Not verified Not verified Online (redirects) (2026-09-28) Not yet

Fraud & traffic scoring

Tool Pricing model Free tier Starting price Compliance claims Official site Last verified
ShieldLabs Freemium Yes: 5,000 identifications, one-time $95 / month Not verified Online (2026-09-24) 2026-10-01

Compliance automation

Tool Pricing model Free tier Starting price Compliance claims Official site Last verified
Secureframe: Automated Security and Compliance Software Not verified Not verified Not verified Not verified Online (2026-09-26) Not yet

SaaS governance

Tool Pricing model Free tier Starting price Compliance claims Official site Last verified
CloudEagle AI Freemium Not verified Not verified Not verified Online (2026-09-24) Not yet

Vendors & implementers

No vendors listed yet.

Submit your company →

Four ways to get this done

Editorial picks are ranked by verified facts. Sponsored slots are labeled and never affect the ranking. How to choose →

Use a tool yourself

Compare the tools listed on this page. See the tool list ↓

Hire an AI-native service

  • Secure.com

    Governed AI security teammates plus managed SecOps, exposure management and vCISO services over the tools you already run.

    Editorial listing · Not paidVisit secure.com ↗
  • Scan Ninja

    Managed vulnerability remediation and SOC 2 / CMMC readiness delivered by security experts on a tenant-isolated AI platform.

    Editorial listing · Not paidVisit scanninja.ai ↗
  • Bitscaled

    Managed IT, cybersecurity and cloud operations run through an in-house AI-native ERP control plane with accountable human operators.

    Editorial listing · Not paidVisit bitscaled.tech ↗
  • Treeline

    An outsourced IT, security and compliance team run on an AI-powered IT operating system.

    Editorial listing · Not paidVisit treeline.ai ↗

Recent changes: Cybersecurity tools

Last verified: 2026-10-03 · auto-checked 2026-09-28 · Reviewed by Toolsfine editorial

  1. Checkpoint genAI - AI Security Copilot Tool · pricing model · — → unknown ·
  2. ShieldLabs · pricing page URL · — → https://shieldlabs.ai/pricing ·
  3. ShieldLabs · starting price · — → 95 ·
  4. ShieldLabs · free tier · — → {"exists":true,"limits":"5,000 identi… ·
  5. ShieldLabs · pricing model · — → Freemium ·
  6. ShieldLabs · site status · — → Online ·
  7. CloudEagle AI · site status · — → Online ·
  8. Checkpoint genAI - AI Security Copilot Tool · official URL · — → https://www.checkpoint.com/ai/factory… ·
Full Cybersecurity directory →Click ranking →