Survey Finds Rapid Uptick in AI Use for Cybersecurity While Governance Lags | Cybernomics
researchTuesday, July 28, 2026

Survey Finds Rapid Uptick in AI Use for Cybersecurity While Governance Lags

The Journal of Accountancy reports that a global survey found a sharp increase in organizations actively using AI in their cybersecurity strategies, but governance practices have not matured at the same pace as deployment. This gap highlights emergent operational and risk-management challenges.

What the source says

According to the Journal of Accountancy, a global survey shows a marked rise in organizations using AI in their cybersecurity strategies, yet governance structures and maturity have not kept pace with the deployment of these technologies.

Why this matters to CPA firms

Firms are both users and advisors in this space: they may be deploying AI tools to protect client data and firm systems while also counseling clients on cybersecurity posture. The dissonance between rapid AI adoption and lagging governance raises concerns about false confidence in automated defenses, model-risk management, and accountability for incidents. Firms must evaluate whether AI-driven controls are subject to sufficient oversight, testing, and human review.

Operational, staffing, and regulatory considerations

Operationally, adopting AI in cybersecurity will require new or retooled roles-security engineers, AI governance leads, and compliance specialists-to manage model updates, monitor performance, and handle incidents. Human labor will be needed for policy development, vendor oversight, and ongoing validation of AI systems. From a professional-judgment and risk perspective, firms should incorporate AI governance into their risk assessments and client advisories, documenting oversight and testing to demonstrate due care. Economically, investments in governance and skilled personnel will be necessary to reduce liability and protect client data; conversely, failure to mature governance can increase breach risk and potential regulatory scrutiny or client-loss exposure.

AIcybersecurityriskgovernance

Original Source

Journal of Accountancy

Read Original