According to a recent study published by GrandView Research, global investment in AI in cybersecurity is set to reach $93.75 billion by 2030. The use of AI in cybersecurity is growing as organizations look for new ways to detect threats, analyze data, and manage third-party risk. According to PwC’s 2026 AI Business Predictions, companies are moving toward more disciplined, enterprise-wide AI strategies, with AI agents playing a larger role in complex workflows. While AI can help security teams work faster and more efficiently, it also creates new risks that require strong governance, oversight, and continuous monitoring.
What accounts for the growing use of AI in cybersecurity? There are several factors at play.
First, AI technology has matured tremendously in recent years. What was once limited to rule-based technology can now accurately detect anomalous user behavior with speed and precision. Second, data is being generated en masse, with over 402.74 million terabytes created each day, which is impossible to sort through using manual methods. IBM’s 2026 X-Force Threat Intelligence Index reported a 44% year-over-year increase in attacks that began with the exploitation of public-facing applications, while active ransomware groups increased 49%. At the same time, the cybersecurity industry continues to face a global workforce shortage, with NIST citing a gap of 4.7 million cybersecurity professionals. As a result, many organizations are turning to AI-enabled cybersecurity tools to help teams work more efficiently, prioritize threats, and respond faster. Humans are unable to sufficiently secure an enterprise-level attack surface alone.
These factors work together to make AI an essential element in defending against third-party attacks.
What is Artificial Intelligence (AI) in Cybersecurity?
AI in cybersecurity has a wide variety of applications today. As attack surfaces continue to expand and the need to analyze massive amounts of data increases, organizations have recognized the value of AI to quickly and accurately identify and respond to cybersecurity threats. These AI and machine learning models become more effective and accurate as they train on data with the goal of making better decisions over time.
For example, organizations might use AI to generate a knowledge graph that can identify suspicious IP addresses connected to your network, or which users have been infected by a particular malware tool, and what path the malware took to infect those users. Or they might use chatbots, natural language processing systems that draw on a knowledge base of information to help security teams further research security issues.
Like most newly adopted technologies, however, AI systems are also used by attackers to launch more sophisticated attacks. For example, cybercriminals exploit the ChatGPT model by training it with social media posts to mimic the tone and voice of an author and convince users to give them payment information and other sensitive data. With these types of AI-powered solutions, they can launch these attacks on a far wider scale than ever before.
How Security Teams Are Using AI in Cybersecurity
Security teams are using AI to investigate, identify, report, and further research any cybersecurity risks and potential security issues facing organizations today. According to Fortinet’s 2026 Skills Gap Report, “84% say AI-enhanced security tools are helping IT and security teams be more effective and efficient, up from 80% last year.
These AI-based cybersecurity systems are used in:
- Threat detection. AI-based systems use machine-learning techniques to analyze network traffic and user behavior to identify emerging threats. For example, if a user attempts to access assets in your computer systems that they don’t have access to, the AI-powered systems alert your security team of a possible insider threat.
- Direct incident response. The ability to analyze large amounts of data means that AI-based systems can detect and prioritize incidents, proactively responding to both known and unknown threats. They can also trace incidents back to their origin, resulting in more effective security measures.
- Endpoint protection. Traditional threat detection relies on signatures or known user behavior. AI-based endpoint protection includes machine-learning algorithms that detect anomalous behavior after establishing a baseline, usually in real-time.
- Breach risk prediction. AI technology can take inventory of all of your organization’s IT assets and the different users who have various access and permissions to those assets. It can then use that information to predict the most likely method of attack and the potential entry point so that your organization can best defend itself.
- Network security. Analyzing network activity for unusual activity, such as unusually large data transmitted over the network, could be an indicator of potential DDoS attacks. It can also quickly spot and patch vulnerabilities in the network infrastructure to mitigate against emerging threats such as zero-day vulnerabilities.
- Third-party risk monitoring. AI can help security teams analyze vendor risk signals, identify changes in a supplier’s cyber posture, and prioritize third-party risks that need immediate attention. For example, if a vendor’s attack surface suddenly expands or a new vulnerability is detected in their environment, AI-powered tools can flag it in real time, giving your team the visibility needed to act before that risk reaches your organization.
The Risks of Using AI in Cybersecurity
With the advantages of generative AI come a number of risks for security teams, from both the process of the AI systems and cybercriminals who leverage the technology for their own malicious purposes.
These risks include:
- Inaccurate results and/or false positives. AI technologies are based on datasets, so their accuracy is dependent on the amount of data they use in their training. Acquiring and investing in such massive datasets often requires more time and resources than many organizations have available. While training AI models on smaller datasets may be more cost-effective, they also render inaccurate results.
- Data leakage. All data entered into ChatGPT is stored and used to continue to train its model. With access to sensitive data, these highly distributed LLM models are at constant risk of data leakage. Between May 2022 and June 2023, more than 100,000 ChatGPT accounts were compromised by information-stealing malware.
- Prompt injection. Text from the AI model can be structured for malicious purposes, including writing commands in an email text prompting it to forward to an attacker or writing injection-style text in a place where AI models can easily access the data.
- Phishing attacks. Cybercriminals can leverage generative AI tools such as ChatGPT to write convincing phishing emails, using social media as training data to mimic the tone and voice of the author. This lures users into giving sensitive data such as customer credentials and payment information. This leaked information can also lead to data breaches.
- Hallucinations. AI systems can generate answers even with a relatively low confidence level. This results in inaccurate, biased, and false results. For example, if you ask a model to identify five examples of vulnerabilities in your system but only 3 exist, it may make up two to satisfy the request.
Best Practices for the Use of AI in Cybersecurity
To mitigate these risks, organizations can put a number of best practices in place.
1. Implement a company-wide strategy for AI
Since AI delivers both benefits and risks to your security team, your organization should develop a policy for how it plans to integrate AI technology into its security architecture and processes.
Before doing so, however, you’ll need to determine:
- Your security objectives. Are you looking to improve your threat detection, identify third-party risk, or detect unknown vulnerabilities?
- Your business goals. How can AI help us align with our business goals? For example, can it assist in spotting emerging trends, enhance the security of your customer interactions, or identify potential security issues before they become critical?
- Your organization’s current AI skillset. Does your team currently have the necessary AI skills to meet these objectives, or will it require hiring additional staff?
- Your measurement for success. After implementing AI, do you expect a decrease in the time your security team spends on patching vulnerabilities? An improvement in your security posture?
Your AI governance policies. Which tools, vendors, AI agents, and use cases are approved, and what data should never be entered into AI systems?
2. Provide access to high-quality and accurate data
Since AI works by recognizing patterns in data, its models are only as good as the data it is given. Biased and outdated data can generate inaccurate results. AI tools may rely on training data, connected data sources, web access, or uploaded documents, depending on how they are configured. However, organizations should still verify AI outputs against trusted, up-to-date sources before using them to make cybersecurity decisions.
3. Consider ethical, privacy, and security implications
Data privacy and security are key concerns when it comes to AI. The technology can be used to monitor and track user behavior, violating their privacy. To guard against this, organizations should implement data anonymization techniques and create transparent guidelines to ensure that users have control over the collection of their data. To protect user security, organizations should conduct ongoing monitoring of the AI systems for suspicious activity and regular security assessments, including verifying that the AI systems are configured correctly. This is critical since attackers can leverage vulnerabilities in the system and use them to change AI algorithms, impacting their ability to deliver effective cybersecurity.
4. Continually test and update AI models
Since the models are trained with data and data changes over time, it’s important to keep your AI models updated with new data to ensure their accuracy. Otherwise, you’ll experience “model drift,” where AI models move away from their original performance levels over time. Continuous testing also identifies any model limitations that you may need to address. For example, it can help ensure that the AI model recognizes the latest threats so that your organization can mitigate cyber threats effectively.
How Panorays Utilizes AI for Third-Party Risk Management
According to the Identity Theft Resource Center’s 2025 Data Breach Report, U.S. data compromises reached another record high in 2025, underscoring the continued need for stronger visibility into vendor and supply chain risk.
As attack surfaces expand, it becomes increasingly challenging for your organization to gain visibility of its supply chain and understand the risks exposed to your organization from new technologies such as artificial intelligence. Panorays delivers this visibility by combining automated and contextualized security questionnaires with external attack surface assessments to gain a 360-degree rating of your supplier’s risk, including identifying third-, fourth-, and N-th party suppliers who are using AI, which assets are vulnerable to exploitation, and the likelihood of any given supplier being breached through that vulnerability.
Not only can Panorays identify these risks, but its AI capabilities benefit third-party risk managers with AI-assisted responses to security questionnaires based on users’ previous answers, reducing friction for third parties and enabling quicker and more accurate answers.
Panorays also uses AI to parse new data to stay on top of the latest data breaches so that your organization can mitigate risks proactively, rather than responding to any security incident once it’s too late.
Want to learn more about how you can leverage AI systems in your third-party risk management program? Get a demo today.
AI in Cybersecurity FAQs
-
Examples of AI in cybersecurity include:
- Predictive breach detection. By detailing the number of users, devices, and applications with different levels of access to your system, AI and machine learning models can predict where and how the next security breach will occur in your organization.
- Threat detection. Detecting emerging threats through pattern recognition and identifying new tools for launching malware attacks and malicious user behavior that indicate a possible insider threat.
- Endpoint protection. AI-based endpoint protection uses training models to continuously establish a baseline for normal behavior. It then uses that baseline to monitor and respond to any behavior that acts outside of that baseline.
- Direct incident response. AI models can assist in identifying, prioritizing, and proactively responding to emerging and existing security threats in your infrastructure. For example, it can identify a threat to a specific compromised device within your organization and isolate it to prevent a data breach.
-
AI is used in cybersecurity for several purposes. First, it is used to analyze large amounts of data and to discover anomalous user behavior or traffic that could pose a threat to your organization. For example, it is used in network security to monitor and analyze traffic patterns and detect when anomalous traffic patterns indicate a possible DDoS attack. Second, its ability to analyze large amounts of data is used to help make better security decisions. For example, it can predict where a future data breach might occur and respond proactively to defend against it. Third, it can help monitor and identify vulnerabilities in your organization’s supply chain by identifying which third parties are using AI and whether they are meeting the proper compliance regulations to mitigate risk from those technologies.
As AI capabilities expand, they will continue to contribute to the improved cybersecurity of organizations even as cybercriminals leverage them for their malicious purposes.
-
AI helps organizations stay on top of compliance by continuously monitoring for changes in vendor posture, flagging potential violations, and generating the documentation security teams need to demonstrate due diligence. Rather than relying on periodic manual reviews, AI-powered tools can track regulatory changes, assess whether vendors meet required standards, and alert teams when something shifts. This is particularly valuable as frameworks like GDPR, DORA, and NIS2 place increasing expectations on how organizations manage third-party and supply chain risk.
-
ROI from AI in cybersecurity shows up in several ways: reduced Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR), fewer successful breaches, lower incident response costs, and improved team efficiency. Organizations should also factor in the cost of alert fatigue reduction when AI filters noise and prioritizes real threats; security teams spend less time chasing false positives and more time on work that matters. Tracking these metrics before and after AI implementation gives you a clearer picture of the value delivered.
-
No, and organizations that treat it as a replacement rather than a tool will find themselves exposed. AI excels at processing large volumes of data, identifying patterns, and automating repetitive tasks. But it lacks the contextual judgment, creativity, and accountability that human professionals bring to complex security decisions. The most effective security programs use AI to augment their teams handling the volume and speed of threat data so that human analysts can focus on investigation, strategy, and response.
-
Start with transparency: how does the vendor explain how their AI makes decisions, and how do they handle false positives? Look for vendors with strong data governance practices, clear policies on how your data is used for training, and a track record of accurate, reliable outputs. Integration with your existing security stack matters, as does the vendor’s ability to keep their models updated as the threat landscape evolves. For third-party risk specifically, look for vendors that combine AI with real attack surface data rather than relying solely on self-reported questionnaire responses.
-
Your direct vendors aren’t the only risk in your supply chain; their vendors carry risk too. AI helps by automatically mapping supplier relationships beyond your direct third parties, identifying subcontractors and secondary suppliers that could introduce exposure into your environment. It can then continuously monitor those relationships for changes in risk posture, flag vulnerabilities, and assess the likelihood of a breach propagating through the chain. Without AI, this level of visibility across a complex supplier ecosystem is practically impossible to maintain manually.
-
AI is only as good as the data it’s trained on. Biased, outdated, or incomplete datasets produce unreliable results. Hallucinations remain a real risk, where models generate confident but inaccurate outputs that could lead to poor security decisions. AI systems can also be targeted by attackers directly, through prompt injection, adversarial inputs, or exploitation of model vulnerabilities. And while AI can process data at scale, it still struggles with the kind of nuanced, contextual judgment that experienced human analysts bring to complex investigations. Strong governance, continuous testing, and human oversight are essential to managing these limitations.
-
During an active incident, speed is everything. AI helps by rapidly analyzing incoming data to identify the scope and origin of the attack, isolating affected systems to contain the damage, and surfacing relevant context to help analysts make faster decisions. While human judgment remains essential for complex response decisions, AI handles the volume and velocity of data that would overwhelm a manual process, reducing the time between detection and containment, and limiting the overall impact of the attack.
-
Insider threats are particularly difficult to detect because the activity often looks legitimate on the surface. AI addresses this by establishing a behavioral baseline for each user and flagging deviations, unusual access times, attempts to reach restricted files, large data transfers, or sudden changes in activity patterns. Rather than relying on static rules that insiders can work around, AI models adapt continuously as behavior evolves, making it harder for malicious or compromised insiders to go undetected for extended periods.