AI is giving security leaders a way to do more with the teams they already have, and new IANS research shows the priority is automating routine work and reskilling staff rather than cutting headcount. At the same time, vendors are layering AI features into existing products and raising prices, which is reshaping how CISO budgets are built and where the money actually goes.
What the research found about AI and security teams
The research points to a clear pattern: most CISOs do not plan to shrink their teams because of AI. Instead, the goal is to use AI so current staff can cover more ground, with routine work automated, entry-level and junior employees reskilled to make more thoughtful decisions, and senior practitioners given more time for the complex problems that require judgment and experience.
That shift shows up in how security operations centers (SOCs) are being organized. Tier-one SOC tasks and some tier-two work are being automated first. As data gathering and initial analysis move to AI, the people who remain in those seats are expected to step into more strategic work faster than the traditional career ladder allowed.
Where the budget is actually going
Three budget pressures are showing up at the same time:
- Vendor price increases. Every major security vendor they work with has rolled out paid AI add-ons inside existing contracts, and in many organizations, most of the new budget is going straight to absorbing those increases rather than expanding the program.
- CISOs are evaluating smaller, fast-growing vendors because mainstream tools are not yet solving their problems, then waiting to see which get acquired or prove stable before bringing them in.
- Because vendors uncertain, more security teams build internal tools, including with vibe coding, for gaps that commercial products leave.
Alongside those pressures, a fourth trend is giving CISOs a way to fund long-deferred work. The business is willing to spend on AI, and security leaders are using that appetite to pull resources into areas the business has historically underfunded, such as identity, SOC modernization, and vulnerability management.
How AI is changing the work security teams do
The practical wins CISOs point to are concrete. Teams are finally getting through backlogs of alerts, third-party questionnaires, and internal documentation that never had enough human hours attached to it. AI is making it easier to prioritize, summarize, and pull trends out of large datasets.
There is a side effect. Once teams can see all the problems hiding in their data, they have to find time and budget to fix the backlogs of alerts, third-party questionnaires, and internal documentation that AI now surfaces. Visibility is expanding faster than capacity, which is why the CISO conversation has moved from whether to adopt AI to how to keep team size steady, invest in reskilling, and move junior staff up the decision-making curve.
Hiring, reskilling, and the entry-level pipeline
Most CISOs say they are not planning layoffs: the stated plan is to keep team size steady and redirect reskilling budgets so existing staff can operate in AI-augmented workflows. Junior staff are being moved into higher-judgment tasks earlier in their tenure, and senior staff are being reassigned from routine review work to threat modelling, vendor oversight and cross-functional risk projects.
The harder question is what happens five years out. When CISOs were asked at the end of 2025 where future senior leaders would come from if entry-level tasks are automated, the common answer was that the market would deal with it later. That answer is already shifting. Security leaders are now openly questioning how to build a future talent pipeline when so much of the early-career work is being outsourced to AI.
Tools keep changing.
What stays the same even as AI moves in
AI is changing the speed and shape of the work, but the underlying problems have not moved. Phishing and social engineering remain the easiest way into a network, and they are now AI-enabled. Permissions, secrets management, and data classification are still messy in most organizations, and they still drive a large share of incidents. The threats are familiar; the volume and the polish are different.
FAQ
Are CISOs cutting security jobs because of AI?
No. The IANS research finds that most CISOs do not plan to shrink their teams. The focus is on using AI to automate routine tasks, reskill staff, and free senior practitioners for more complex work.
What is driving CISO budget changes right now?
Vendors are adding AI features and raising prices, so much of the new budget is going to keeping up with the existing stack. CISOs are also evaluating smaller AI-focused vendors and, in some cases, building tools in-house to fill gaps.
How is AI changing entry-level cybersecurity roles?
Tier-one SOC work and other early-career tasks are being automated first, which is pushing organizations to reskill junior staff faster and raising the question of where future senior security leaders will come from if the traditional pipeline is automated away.
This article summarizes reporting from darkreading.com.

