Skip to content

Security1 publisher2 min readPublished

Three quarters of security teams are funding AI without a budget line for it

An IANS and Artico survey puts AI at about 3 percent of the average security budget, and 24 percent of organizations have given it a line of its own. Bugcrowd's CEO says the rest comes out of what was already bought.

The Watch · Security desk

Illustration accompanying Three quarters of security teams are funding AI without a budget line for it

What happened

  • An IANS and Artico survey of security leaders found AI investment has become a priority for 69 percent of organizations, with 24 percent giving it a dedicated security budget line.
  • AI now takes about 3 percent of the average security budget, most of it going to AI-enabled security tools and software, while overall cybersecurity budgets are barely growing.
  • Organizations that raised AI security spending by more than 10 percent this year expect another double-digit increase in the next budget cycle, according to the survey.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • constraint A flat total means the next double-digit AI increase has to be taken from tools already deployed, so each new agentic capability arrives with an unbudgeted subtraction somewhere in the stack.
  • decision With 76 percent of organizations holding no dedicated AI line, a board approving AI security work is approving a trade it cannot see priced, because the offsetting cut sits inside another line item.
  • exposure Swapping scheduled penetration testing for continuous validation changes who finds what: the coverage a retainer bought is gone the month the contract is not renewed, whatever the tooling promises.
  • contradiction Gerry's reallocation claim and the report's note that IT, data, and innovation functions pay for part of the AI spend point different ways, and the unbroken-out share decides how much of the 3 percent came out of controls.

The money moves in two directions at once. Penetration testing and point-in-time testing lose budget, while continuous validation and monitoring of what employees do with AI tools gain it, according to Dave Gerry, CEO of Bugcrowd, quoted in the ReversingLabs writeup of the survey [7]. "It's mostly reallocation. Very few CISOs are walking into a board meeting and getting a bigger number," Gerry said [5].

"Shadow AI is the new shadow IT. The total stays flat, the line items look nothing like last year's," he said [6].

Sixty-nine percent of organizations call AI investment a security priority and 24 percent have given it a dedicated budget line, so at least 45 points of that majority are paying for AI out of budgets built for something else [1][2][18]. The remaining 76 percent fold it into broader security, IT, data, or innovation budgets [17][2].

Agentic deployments are the clearest case. "Very few teams have a dedicated agentic AI line item. It's mostly being carved out of existing SOC tooling and automation budgets, which means something else got quietly deprioritized to pay for it," Gerry said [11].

The 3 percent covers more than displaced spending [3]. Some AI-related spending sits outside security entirely, funded through IT, data, or innovation functions, the report notes [15]. The report does not break out how much of the total that covers, or which tools lost funding to pay for the rest [21].

The biggest increases Gerry named are application security and offensive validation, as the gap widens between the vulnerabilities teams find and the ones they fix [8]. "Discovery isn't the constraint anymore. Teams can find far more than they can fix, so money is moving toward triage and prioritization, the work that turns findings into decisions," he said [9]. Identity is the other line he expects to grow, tied to the access-control failures behind many AI agent failures [10].

The workforce numbers point the same way as the budget ones. Ninety-one percent of CISOs expect AI to raise the productivity of their existing teams over the next year, and 81 percent expect to need new roles and skills [13][14].

Organizations that raised AI security spending by more than 10 percent this year expect another double-digit increase in the next budget cycle [12]. With the total flat, that increase has to come out of other line items [19]. ReversingLabs adds that AI compute cycles are now on the radar for many buyers [16].

What to watch

  • Whether the next IANS and Artico cycle shows the 24 percent dedicated-line share rising. A rise would mean AI spend has stopped displacing existing controls.
  • Renewal decisions on penetration testing retainers and point-in-time testing contracts. Those renewals will name the defunded controls before any survey does.
  • Whether AI compute and token costs appear as their own budget line rather than inside tooling spend.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories