AI Surges to Second-Biggest Workplace Risk, SANS Report Finds
Event summary
- AI is now the second-biggest human risk in workplaces, trailing only social engineering, per SANS Institute's 2026 report.
- 75% of security awareness teams use AI to build and manage programs, with only 2.4% finding it ineffective.
- Most programs lack sufficient staff, with 3+ dedicated employees and 3–5 years needed to move past baseline compliance training.
- Global average salary for security awareness professionals reached $123,624 in 2026, up $7,000 from the prior year.
The big picture
The SANS report highlights a growing disconnect between AI adoption in workplaces and the ability of security teams to govern it. As AI tools proliferate, organizations face increasing risks from unauthorized use and unchecked AI agents. The report underscores the need for larger, more mature security awareness teams to build lasting security cultures, a challenge exacerbated by persistent staffing shortages despite rising salaries. This trend reflects broader industry struggles to balance rapid technological change with effective risk management.
What we're watching
- AI Governance
- How security teams will adapt to the rapid adoption of AI tools by employees, particularly in areas like generative AI and AI agents.
- Program Maturity
- Whether organizations can sustain long-term security culture building with current staffing levels and budgets.
- Salary Inflation
- The pace at which rising salaries for security awareness professionals will drive demand for specialized talent.
Related topics
