The News
IANS and Artico Search have published the 2026 Security Budget Benchmark Report, drawing on responses from more than 500 security executives. The report finds that despite nearly flat overall budget growth (an average of 5% in 2026, with 45% of organizations reporting no increase at all), AI has become the dominant driver of net-new cybersecurity spending, with 69% of CISOs naming it their top investment priority. Critically, 81% of CISOs expect AI to create new security roles, while 69% do not expect it to reduce existing headcount, framing AI as a workforce augmentation story rather than a replacement one.
Analyst Take
The budget math tells a more complicated story
A 5% average budget increase sounds like progress until you account for inflation, expanding attack surfaces, and the compounding cost of AI-era threats. The headline number obscures a bifurcated market: well-capitalized organizations (venture-backed firms, large public companies with strong balance sheets) are funding AI security tooling aggressively, while the rest are treading water. For ITDMs at resource-constrained organizations, this creates a compounding disadvantage. Adversaries have access to the same AI tooling. The organizations that fail to make dedicated, tracked AI security investments will fall behind operationally, not just technologically.
The budget structure finding is worth pausing on. Organizations that track AI as a distinct budget line item reported increased AI funding at a rate of 70%, compared with just 31% for organizations where AI security spend is buried in IT or innovation budgets. This is not a coincidence. Visibility drives accountability, and accountability drives funding. CISOs who want to grow their AI security programs have a clear tactical move: get AI onto its own line in the budget, not folded into a general software category.
AI is not eating security jobs — it’s changing what those jobs look like
The workforce narrative in this report deserves more attention than it typically receives. The dominant fear in security circles (and in popular coverage) is that AI automation will eliminate analyst roles. This report pushes back hard. When 81% of CISOs expect AI to generate demand for new roles and skills, and 69% do not anticipate headcount reductions, the story becomes one of skill transformation rather than workforce contraction. The roles that emerge will likely center on judgment, context, and anomaly interpretation. These are exactly the capabilities that current AI systems handle poorly when dealing with incomplete or ambiguous information, as Artico’s Steve Martano noted directly.
For developers working in security-adjacent functions (DevSecOps, platform security, compliance automation), this shift creates real opportunity. The demand signal is pointing toward people who can configure, govern, and audit AI-assisted security workflows, not just people who can run manual investigations. That’s a meaningful career pivot, and organizations that invest in retraining now will be better positioned to retain talent than those waiting for the market to stabilize.
The procurement gap in government contexts
The IANS/Artico findings map interestingly onto the public sector, where AI security investment faces structural obstacles that commercial organizations don’t. According to ECI Research’s Google GovTech Survey, 31.8% of respondents identified FedRAMP and compliance approval friction for AI vendors as the single largest blocker preventing widespread AI adoption in developer workflows. That friction doesn’t disappear when a CISO decides AI is the top budget priority; it simply means the gap between intent and deployment widens. Government security leaders reading this report will recognize the ambition but should be clear-eyed that the path from budget allocation to operational AI security capability is considerably longer in regulated environments.
That procurement drag compounds an already difficult talent dynamic. ECI Research’s survey also found that 56.8% of respondents characterized developer frustration or burnout as having moderate impact on retention, with complaints common even when headcount stays steady. Security teams operating on constrained budgets, using tools selected by procurement vehicles rather than engineering preference, face a version of this problem acutely. The IANS finding that AI is expected to create new roles is optimistic; in government, realizing that optimism requires navigating procurement timelines that frequently run 7 to 12 months or longer for a single developer tool.
Looking Ahead
The 64% of CISOs expecting a budget increase in 2027 represents meaningful optimism, but that number should be read as a directional signal rather than a guarantee. The organizations best positioned to actually capture that increase are those building the governance infrastructure now: dedicated AI budget line items, clear policy frameworks for AI tool use, and workforce development programs that prepare analysts for judgment-intensive roles. The ones that treat 2026 as a holding pattern will find themselves behind when budgets do open up.
For the broader market, the software-versus-headcount convergence (35% software, 37% staff) is the structural trend to watch. If that ratio continues to shift toward software, it will reshape how security vendors price and package their products, how SIs structure security engagements, and how CISOs justify headcount to boards. Vendors who can demonstrate clear productivity multipliers per security analyst will have a material advantage in the next budget cycle. Those selling point solutions without a credible AI integration story will face increasing pressure to consolidate or be displaced.
Stay Ahead of Application Development Trends
Get weekly analyst insights, research notes, event coverage, and AppDevANGLE updates delivered directly to your inbox.
Subscribe for Weekly Insights
Join technology leaders, practitioners, and GTM teams following the trends shaping modern software delivery.
Looking for deeper research access?
Explore ECI Research reports, survey insights, and market analysis through the ECI Research Portal.
