Report: AI Attacks Push Organizations Toward Autonomous Cybersecurity Defense
Artificial intelligence is raising the stakes of cyber conflict as attackers use the technology to accelerate reconnaissance, uncover vulnerabilities, and launch attacks faster than many security teams can respond.
That widening speed gap is pushing organizations toward AI-powered systems capable of taking a more active role in cyber defense, according to Kai's 2026 State of Autonomous Defense Report. The survey of 500 CISOs worldwide found that 63% believe attackers currently hold the advantage, compared with just 18% who believe defenders are ahead.
Kai argues that the imbalance is being driven by speed.
Attackers are increasingly using automation to discover and exploit weaknesses, while many security teams still rely on manual processes to identify, prioritize, and remediate risks.
The Limits of Human-Led Security
The report highlights a growing challenge for security teams: The traditional approach of adding more people, tools, and processes is struggling to keep pace.
Kai found that 65% of CISOs say at least half of vulnerability and exposure management remains manual. Only 6% describe their approach as primarily machine-led.
That manual approach is creating operational pressure.
The report found that 60% of organizations take more than seven days to remediate a critical vulnerability, while 48% leave a quarter or more of known vulnerabilities open beyond 30 days.
The impact is also being felt by security teams themselves.
Seventy-eight percent of CISOs say vulnerability and exposure management contributes to security team burnout, with 17% describing it as a major contributor.
From Automation to Autonomous Action
The next phase of cybersecurity automation is moving beyond identifying problems and toward taking action.
Kai's report found that organizations are already using automation across parts of the security workflow. Fifty-five percent allow automated asset discovery and inventory, while 49% allow automated vulnerability prioritization.
More importantly, 32% of organizations already allow automated remediation actions without human approval.
That shift represents a major change in how security teams think about AI.
Instead of AI simply helping analysts review alerts, autonomous systems could increasingly identify risks, determine priorities and execute remediation steps.
Trust Remains the Biggest Barrier
Despite growing interest in autonomous defense, many organizations are still hesitant to hand more responsibility to AI systems.
Kai found that 52% of CISOs cite a lack of trust in automated decisions as the biggest barrier to greater automation. Governance and compliance concerns ranked second at 43%, while budget concerns ranked much lower at 21%.
The report suggests organizations are not necessarily waiting for more funding. They are waiting for confidence that AI systems can make decisions accurately, transparently and safely.
For security leaders, explainability will be critical.
Kai found that 52% of CISOs say auditability and explainability would increase their confidence in allowing machine-led remediation actions.
The Future Security Team Will Look Differen
The rise of autonomous defense does not mean removing humans from cybersecurity.
Instead, it could change where human expertise is applied.
Security professionals may spend less time manually investigating alerts and managing repetitive remediation tasks, and more time overseeing AI systems, managing risk and making strategic decisions.
Kai found that 45% of CISOs expect vulnerability and exposure management to become mostly or primarily machine-led within the next 12 to 18 months.
The broader shift reflects a wider trend across enterprise AI: Organizations are moving from using AI as an assistant toward deploying AI systems that can perform complex workflows.
The next cybersecurity advantage may not come from having more tools. It may come from having systems that can operate continuously at the speed of modern threats.
As Kai concludes in the report, "The next phase of enterprise defense will be defined less by whether organizations adopt automation and more by how quickly they can build the trust to let it act."
The full report is available here.