What Was Found When Security Leaders Were Asked About Actual AI Adoption
Most AI security tools are hype. Security leaders know it. That does not mean we are writing AI off.The better questions are where it helps, what is holding adoption back, and what a tool has to prove before it earns a place on the team.
I have sat in the CISO seat long enough to be skeptical of new tooling. I also cannot picture any CISO watching this shift from the sidelines. So at Surf we asked. In the summer of 2026, we surveyed 51 senior security and IT leaders from our professional network. Roughly three in four were director-level or above. 57% held C-suite or executive roles.
The picture was clear. Leaders are not dismissing AI, and they are not taking claims at face value. 51% described AI in security as "mostly hype with some real promise." 18% said it is already delivering real value.
Why Aren’t Big Promises Landing
We asked which vendor promises leaders are tired of hearing. Two topped the list: "zero false positives" and "autonomous remediation."
"Zero false positives" fails because every operator knows no tool is perfect. Claiming otherwise costs you credibility in the first meeting. What matters is how rare false positives are, how fast we spot them, and how easily the team corrects them.
"Autonomous remediation" raises a different concern. When a tool acts on its own, the cost of being wrong goes up. I want to know the blast radius, why the tool chose that action, and where a human can step in. Being open to automation is not the same as handing over control.
So what earns trust? 33% want a proven track record in environments like theirs. 31% said unclear ROI is their biggest barrier to adoption. Working is not enough. The tool also has to make business sense.
Finding the Issue Isn’t the Fix
The next opportunity for AI is less about finding more issues and more about the work that follows. A third of leaders said manual coordination to fix issues is their greatest operational pain. That matches my experience. A tool flags the problem. The team still has to understand the context, find the right owner, and coordinate the response. Detection was never the bottleneck.
The same appetite shows up in compliance. Nearly a third said evidence collection is the task they would most happily hand to AI. Both answers point to the unglamorous side of security: repetitive, time-consuming work that pulls good people away from higher-value priorities.
AI Won’t Shrink Your Team
There is plenty of concern about AI taking jobs. That is not what these leaders expect. Only 6% said AI means hiring fewer people. 53% expect to redeploy staff toward higher-value work.
Teams are not being replaced. How they spend their time is changing. Leaders want AI as the clean-up crew, taking repetitive work off the plate so people can focus on judgment, strategy, and experience.
That does not mean a lighter workload. 53% expect their teams to cover more ground in the years ahead.
Where do they want help first? 33% said identity and access hygiene, with the rest pointing to areas like cloud posture and remediation. Leaders expect AI to have a big impact on application security soon, but the work they want to hand off first is far less flashy. Know what you have. Know who has access. Know what needs cleaning up.
The Risk Depends on Where You Sit
Concerns about AI vary by role. Most CISO-level leaders are focused on external threats: new attack surfaces and smarter AI-driven attacks. Practitioners are looking inward, worried about relying too heavily on automation and letting it replace human judgment.
Both groups are right. They are seeing different sides of the same problem. Leaders are watching how AI changes the threat landscape. Practitioners are watching what happens when AI becomes part of the daily workflow.
That gives us two things to plan for. We need to understand how AI changes the threats coming at us. We also need clear limits on how our own teams use it. What can a tool do on its own? When does a person review its work? If we only watch the threat outside, we miss the risk the people closest to these tools are pointing to.
Let AI Earn the Next Assignment
Security leaders are not looking to be impressed. We want proof that AI makes our teams more effective without creating a new set of problems.
That starts with giving AI work it can prove itself on. If a tool handles repetitive tasks reliably, explains its decisions, and shows measurable value, we will trust it with more.
There is still plenty to figure out. But the survey makes one thing clear. Leaders are not writing AI off, and they are not handing it control blindly. They are deciding where it takes work off the plate, where people stay involved, and what it has to prove first.
AI will not earn more responsibility by promising to solve bigger problems. It will earn it by handling the work in front of it.

