top of page

KPMG AI Cybersecurity Survey Finds Maturity Makes Companies More Cautious, Not Less

46 minutes ago
12 min read

KPMG found a 50-point gap in active cyber defense between early AI experimenters and organizations already reporting returns. The KPMG AI cybersecurity survey shows that confidence does not eliminate concern. It gives companies enough operational experience to identify more risks, fund stronger controls, and let AI perform more consequential security work.

Only 8% of organizations at the experimentation stage reported deploying AI-assisted cyber defense. That share reached 58% among organizations with established returns. Early adopters were also more likely to stop at monitoring, without changing security operations.

This is not a simple story about businesses becoming comfortable with AI. It is a story about comfort changing what companies expect AI to do. Mature adopters are moving beyond watching threats, while accepting that deeper automation creates greater exposure and accountability.

The findings come from KPMG’s quarterly Global AI Pulse study, which surveyed 2,131 senior leaders across 20 countries. The resulting maturity gap matters for security vendors, enterprise buyers, boards, and employees whose workflows increasingly depend on AI agents.

The KPMG AI cybersecurity survey reveals an operational divide

The defining gap is not whether companies acknowledge AI risk, but whether that concern has changed daily security operations.

KPMG surveyed executives responsible for organizational strategy and operations between July 23 and August 26, 2026. Eligible organizations generally reported at least $50 million in annual revenue. Higher thresholds applied in several large markets.

The researchers compared 268 organizations in the experimentation stage with 208 organizations reporting established returns. That comparison produced the clearest cybersecurity finding in the Global AI Pulse.

Among experimenters, 26% monitored AI-related threats without making operational changes. That figure fell to 4% among established adopters. Meanwhile, active AI-assisted defense rose from 8% to 58%.

The contrast suggests that early-stage programs often treat security as an observation task. Teams collect alerts, update policies, and study possible misuse. They hesitate to let AI directly influence detection, investigation, or response.

Established adopters have crossed that boundary. Their AI programs have produced enough evidence, infrastructure, and internal trust to support more active security roles. That does not mean an autonomous model controls the entire response process.

AI-assisted cyber defense can cover several narrower functions. A system might prioritize alerts, connect related events, summarize investigations, identify unusual activity, or recommend containment steps. Human approval can remain mandatory for high-impact actions.

The percentages do not identify which functions each respondent automated. They still show a substantial shift from observation toward intervention. That shift changes the consequences of errors.

A monitoring system can overwhelm analysts with false positives. An operational system might block an account, isolate a device, change access, or redirect an investigation. Each action requires clearer authorization, testing, and review.

The study also found that 86% of respondents were adapting their cybersecurity operating models for AI-accelerated threats. Most reported changes to cyber governance or threat detection, according to the report.

That broad response supports the original news analysis, but the maturity comparison provides the more important signal. Nearly every company can say it is responding. Far fewer can show that the response has reached operations.

An operating model defines who makes decisions, which systems carry them out, and how the organization reviews outcomes. Changing that model requires more than purchasing an AI feature from a security vendor.

Teams need usable data, defined escalation paths, evaluation criteria, and records that explain automated decisions. They also need a way to reverse harmful actions without losing evidence.

Those requirements explain why operational adoption trails general interest. Businesses can test AI quickly. They cannot safely delegate security decisions at the same speed.

AI cybersecurity maturity raises spending and concern together

Mature AI users spend more on security because experience exposes dependencies that experimentation can keep hidden.

Seventy-one percent of established adopters included cyber and data security among their AI budget priorities. Only 36% of experimenters said the same.

The mature group also expressed greater concern. Half described cybersecurity as a barrier to their AI strategy, compared with 34% of experimenters. Greater use therefore correlated with both more investment and more perceived friction.

At first glance, those results appear contradictory. Organizations deploy more AI-assisted defense, yet they become more likely to call cybersecurity an obstacle.

The contradiction fades when AI moves into real workflows. A pilot can operate with limited data and narrow permissions. A production system often connects to identity platforms, document stores, cloud services, customer records, and internal applications.

Every added connection expands what an error or attacker can reach. A model does not need complete administrative control to cause damage. Access to sensitive context, executable tools, or trusted communications can be enough.

This creates a tradeoff between capability and exposure. Useful AI needs information and authority. Security teams must restrict both without making the system ineffective.

Established adopters encounter that tension repeatedly. They learn which permissions models request, how outputs influence employees, and where vendor dependencies appear. Experimenters can postpone many of those questions because their deployments remain contained.

The finding also challenges a familiar adoption narrative. Organizational comfort does not make security concerns disappear. It moves those concerns from hypothetical risk registers into budgets, architecture, and executive decisions.

That distinction matters to enterprise buyers. A company evaluating AI security products should not interpret a long list of controls as evidence of organizational resistance. Controls can indicate that the company has reached more consequential uses.

The reverse is also true. An organization reporting few obstacles might have a simple, isolated deployment. Low concern does not automatically indicate stronger security.

KPMG’s maturity categories describe an AI journey, not a security certification. Established returns mean respondents reported meaningful outcomes and growth opportunities. The label does not prove that their defenses outperform independent benchmarks.

Still, the association is useful. Companies reporting returns were much more likely to fund cyber controls, diversify providers, formalize accountability, and deploy active defenses.

The pattern also fits the wider threat environment. The World Economic Forum reported that 87% of surveyed leaders saw AI-related vulnerabilities rising during the previous year. Its AI cyber outlook also found uneven access to expertise and defensive technology.

More than half of those respondents cited limited skills and knowledge as an obstacle to AI-driven cybersecurity. Smaller organizations were more likely to report insufficient resilience than larger organizations.

That context adds an important qualification. The KPMG respondents came from sizable organizations, including many with resources to build formal management layers. Their path cannot be assumed for every business.

A mature multinational can distribute costs across security, legal, data, and engineering teams. A smaller company might receive AI capabilities through an existing vendor without comparable evaluation resources.

The adoption gap could therefore become a resilience gap. Well-resourced companies can use AI to accelerate defense while developing controls around it. Others may gain the same automated features without equal visibility into their behavior.

Active defense turns AI risk into a capability tradeoff

The central question is no longer whether AI belongs in cybersecurity, but how much authority defenders can grant without creating another attack path.

Security teams face a difficult asymmetry. Attackers can use automation without following procurement rules, audit requirements, or change controls. Defenders must move quickly while protecting production systems and evidence.

AI can help analysts process high alert volumes and connect weak signals across systems. It can also generate inconsistent conclusions, inherit poisoned context, or take an unsafe action through an integrated tool.

The risk grows with agentic AI, meaning systems that plan and perform multistep tasks with partial autonomy. These systems can search, reason, call software tools, and adjust their approach based on results.

KPMG found that 38% of respondents were developing or implementing multiagent systems. Significant employee adoption of AI agents reached 34%, up from 25% in the first quarter.

That growth places more pressure on identity and access management. An agent must operate under a defined identity, with permissions appropriate to its task. Shared credentials and broad tokens weaken accountability.

Security teams must also distinguish between protecting AI and using AI for protection. Those goals overlap, but they are not identical.

Using AI for cybersecurity means applying models to threat detection, vulnerability analysis, alert triage, or response. Cybersecurity for AI means protecting models, data, applications, interfaces, and agent tools from manipulation or theft.

A third category covers malicious AI use. Attackers can apply models to reconnaissance, impersonation, exploitation support, or social engineering. Organizations must prepare for all three categories without treating them as one problem.

This wider framing has appeared in public guidance for several years. The AI risk framework from NIST asks organizations to govern, map, measure, and manage AI risk across the system lifecycle.

NIST has also developed a preliminary Cyber AI Profile that connects cybersecurity outcomes with AI-specific opportunities and risks. That work reflects the same convergence visible in KPMG’s survey.

The practical challenge is authorization. An AI system that summarizes an alert carries one risk level. A system that disables a user or modifies firewall rules carries another.

Companies need explicit limits for each step. They must define which decisions remain advisory, which require approval, and which can execute automatically under narrow conditions.

They also need evaluation data that reflects actual operations. A model tested against clean historical examples might fail during a noisy incident. Attackers may intentionally craft inputs that exploit its assumptions.

Human review remains important, but it cannot become an empty checkbox. Reviewers need enough context, time, and authority to challenge the recommendation. Otherwise, automation bias turns nominal oversight into routine approval.

The mature adoption pattern suggests companies are building this confidence incrementally. Monitoring comes first because it offers information without direct intervention. Active defense follows when organizations trust their data, controls, and response process.

However, comfort can introduce complacency. A model that performed well during previous incidents might behave differently after an update. A provider can change system behavior without altering the customer’s workflow.

That is why operational AI needs continuous testing. Teams should track false positives, reversed actions, missed threats, escalation frequency, and analyst disagreement. Performance must be measured after deployment, not only before approval.

The same evidence should inform purchasing decisions. Buyers need to know whether a vendor’s AI produces recommendations, executes actions, or delegates tasks to other agents. Those distinctions shape risk more than an “AI-powered” label.

Harness layers move governance closer to the model

KPMG’s strongest adopters are building control systems around AI, but the survey shows that many organizations still lack complete coverage.

Fifty-five percent of respondents operated a formal AI harness layer. KPMG defines this as the controls and tools between AI models and business use cases.

The layer can govern what models access, which actions they perform, and how outputs reach employees or systems. It can also provide monitoring, evaluation, audit trails, and cost tracking.

Among organizations reporting established returns, 86% had a formal cross-functional or enterprise-wide layer. The figure was 31% among experimenters.

Security and identity controls appeared in 43% of respondents’ layers. Data access controls also reached 43%, while 41% monitored AI outputs.

Those figures mean most respondents did not report each individual capability. A company can have a formal management layer while lacking important functions inside it.

Human review appeared in 34% of layers. Evaluation and testing reached 33%, policy enforcement reached 30%, and audit trails appeared in 28%.

Model routing was least common at 23%. Routing selects which model handles a task and can help organizations manage sensitivity, performance, availability, and cost.

KPMG summarized the imbalance as companies building a gate before a switchboard. Many organizations can restrict access, but fewer can dynamically direct work across models and providers.

That weakness matters for resilience. A company might have strong access controls around one provider while lacking a tested alternative. If that provider changes terms, availability, behavior, or geographic coverage, operations can stall.

Established adopters appeared more prepared for that problem. Only 6% relied primarily on one global model provider, compared with 19% of experimenters.

Another 8% of established adopters relied on a small number of providers, compared with 29% of experimenters. The mature group was also more likely to value switching between models.

Provider diversity does not automatically reduce risk. Multiple integrations expand the systems that teams must evaluate and monitor. Different models can produce inconsistent outputs or require different controls.

The benefit comes from reducing concentrated dependency. A tested alternative gives organizations options during an outage, policy change, regulatory conflict, or serious model failure.

This is where cybersecurity, sovereignty, and continuity meet. Model sovereignty concerns who controls critical models, where they operate, and whether access can be relied upon.

Seventy-two percent of respondents applied formal sovereignty criteria to at least some decisions or maintained an enterprise-wide strategy. Only 8% said sovereignty concerns slowed deployment.

That result suggests most companies view sovereignty as a design constraint, not a reason to stop using AI. They are trying to preserve switching options and control data placement while continuing adoption.

Accountability is the other part of the management layer. KPMG found that 53% assigned responsibility for AI-informed decisions at the C-suite level or above.

A named executive held responsibility at 35% of organizations. Another 18% placed it with the CEO or executive committee.

Executive ownership can resolve conflicts between speed, cost, and risk. It can also make failures easier to investigate because someone has authority over the entire operating model.

However, an executive title does not guarantee effective control. Accountability requires decision records, reliable telemetry, escalation rights, and technical staff who can explain system behavior.

KPMG captured the point clearly: “Accountability is what turns controls into decisions someone can be asked to explain.” That is especially relevant when agents operate across departmental boundaries.

A security team cannot govern what it cannot identify. Organizations need inventories of models, agents, integrations, data sources, owners, and permissions. Those records must stay current as employees add tools.

The documentation burden is substantial. Teams often store policies, evaluations, incident notes, and architecture decisions in separate systems. A searchable knowledge base can help reviewers connect those materials during an assessment.

The goal is not documentation for its own sake. Teams need evidence that lets them answer who approved a system, what changed, and why an automated action occurred.

The survey shows correlation, not proof of safer AI

Mature adopters report more controls and active defenses, but self-reported maturity cannot establish that those organizations suffer fewer incidents.

The KPMG AI cybersecurity survey offers a detailed view of management practices. It does not provide independently tested security outcomes.

Respondents classified their organizations’ AI journey and described their own controls, spending, and priorities. The study did not publish breach rates for each maturity group.

It also did not compare false-positive rates, containment speed, financial losses, or recovery time. Those measures would help determine whether AI-assisted defense improves resilience.

The maturity relationship can support several explanations. Experience may lead companies to build better controls. Stronger organizations may also adopt AI faster because they already possess larger budgets and better security teams.

A third factor can influence both sides. Companies with valuable data, regulated operations, or complex infrastructure may invest heavily in AI and cybersecurity at the same time.

That means readers should avoid treating the 58% adoption figure as proof that active AI defense produced established returns. The survey identifies an association, not a causal result.

Its sample also limits generalization. Participating organizations met significant revenue thresholds, and the U.S. tracking sample focused on companies with at least $1 billion in revenue.

Smaller businesses often depend more heavily on packaged software and managed providers. They may have less influence over model selection, evaluation methods, or incident telemetry.

The report’s categories are broad as well. “AI-assisted cyber defense” can describe systems with very different autonomy, accuracy, and operational impact.

One respondent might use a model to summarize cases. Another might allow automated containment. Placing both under one category can hide meaningful differences.

The report also says 89% of organizations see measurable value from AI, while only 12% consistently compare that value with cost across the enterprise. That gap should temper confident claims about returns.

Reported value can include productivity, cost savings, revenue growth, or improved decisions. It does not necessarily mean a program has produced a complete financial return.

The same caution applies to cybersecurity outcomes. Faster alert analysis can save analyst time without reducing incident impact. An automated action can shorten containment while increasing disruption elsewhere.

Boards should therefore ask for outcome measures tied to specific use cases. Useful indicators include investigation time, confirmed detection quality, action reversals, missed incidents, and service recovery.

They should also examine whether performance differs across teams and environments. A model that succeeds in a well-instrumented cloud workload might struggle with legacy infrastructure.

Employee behavior is another uncertainty. KPMG found significant agent adoption at 34% of organizations. Adoption does not reveal whether employees used approved agents, followed data rules, or understood automated outputs.

Shadow AI can expand even while formal governance improves. Employees might use external tools because approved systems are slow, limited, or difficult to access.

The survey’s quarterly cadence offers direction rather than proof of a sudden change. KPMG explicitly cautions that quarter-to-quarter movements should be read as trends, not dramatic steps.

That makes the report valuable as a management signal. It shows where experienced organizations are allocating attention. It should not be presented as a security effectiveness benchmark.

Three signals will show whether active AI defense delivers

The next test is whether companies can convert reported comfort into measurable security outcomes without hiding new failures behind automation.

The first signal is operational evidence. Enterprises should begin reporting whether AI changes detection quality, investigation speed, containment time, or incident impact.

These measures will strengthen KPMG’s maturity argument if active users show better outcomes after accounting for company size and security spending. Frequent reversals or missed incidents would weaken it.

The second signal is broader implementation of complete management layers. Security and identity controls lead today, while testing, auditability, human review, and routing remain less common.

Progress requires more than raising the overall 55% adoption rate. Organizations need complementary controls that cover model selection, permissions, outputs, actions, and recovery.

The third signal is accountability under pressure. A named executive matters most when a model behaves incorrectly, a provider changes, or an agent exposes sensitive data.

Incident reports should show whether organizations can reconstruct the decision path. They should identify the model, context, permissions, approvals, and controls involved.

Regulatory guidance and industry standards will shape those disclosures. Vendors will also face pressure to explain how their agents use identity, preserve logs, and support customer testing.

For enterprise buyers, the immediate task is to separate capability claims from operating evidence. Ask where AI can act, which decisions require approval, and how quickly an action can be reversed.

Security leaders should also compare monitoring-only deployments with active defenses. The goal is not maximum autonomy. It is the right authority for each task, supported by testing and clear ownership.

Knowledge workers have a role in that process. They should understand which agents can access their documents, messages, and applications. They should know how to challenge an unsafe recommendation.

The KPMG AI cybersecurity survey suggests that experience changes the security conversation. Mature adopters do not treat risk as a reason to retreat. They treat it as a reason to build stronger operating systems.

That conclusion remains provisional until better outcome data arrives. Over the next several quarters, watch for independently measured detection gains, fuller control layers, and transparent incident reviews.

Organizations should begin with a concrete question: which AI system can take an action today, and can the business explain that action afterward? If the answer is unclear, confidence has moved faster than control.

Give every agent the context to do better work

Connect your agents to the knowledge, decisions, and history already organized in remio.

remio currently supports Windows 10+ (x64) and Macs with Apple silicon.

Your AI Partner at Work
Get more done with remio

Plan. Create. Deliver.
All in one place.

bottom of page