Organisations that make extensive use of artificial intelligence in cybersecurity are able to remove cybercriminals from their infrastructure around 80 days faster on average following a successful security breach. This reduces the average cost of a cyberattack by approximately $1.9 million.
As many as 77% of companies say they already use AI to protect themselves against cyber threats, while 88% of cybersecurity teams are investing in AI agents. Despite the growing importance of the technology, 54% of organisations still identify a shortage of qualified specialists as one of the main barriers to implementation.
These are among the findings of the report Empowering Defenders: AI for Cybersecurity, prepared by the World Economic Forum in cooperation with KPMG.
AI is changing the rules of cyber defence
The development of artificial intelligence is transforming the way organisations protect their digital environments. AI can support virtually every stage of the cybersecurity cycle, from identifying threats and preventing incidents to detection, analysis, response and business recovery.
The growing number and complexity of cyberattacks mean that traditional security methods are increasingly proving insufficient. Cybercriminals use artificial intelligence to automate reconnaissance, identify vulnerabilities, prepare phishing campaigns and create or modify malware.
In response, organisations are also adopting AI-based solutions. These technologies allow them to analyse vast amounts of data more quickly, identify risks more effectively, detect unusual user and system behaviour, and automate some of the repetitive tasks previously performed by analysts.
AI can also help mitigate mounting staffing and operational pressures. Security teams are dealing with a growing number of alerts, increasingly complex IT environments and a shortage of qualified professionals. Automation can reduce workloads and allow employees to focus on activities that require expertise, experience and an understanding of the wider context.
“The paradox facing every CISO today is that AI simultaneously solves the problem of overloaded security teams while creating new risk vectors that did not exist just a year ago,” says Michał Kurek, Partner in Advisory and Head of Cybersecurity at KPMG in Poland and Central and Eastern Europe.
“Organisations that are already investing in the responsible implementation of AI are gaining a real advantage. They detect threats faster, respond to incidents more efficiently and make better use of the limited resources available to security teams,” he adds.
However, technology alone is not enough to create an effective protection system.
“The key to success is finding the right balance between automation and human judgement. Companies that can combine the capabilities of AI with expert experience and clearly defined control mechanisms are building resilience that can withstand the test of time,” Kurek says.
“It is this balance, rather than the scale of implementation alone, that now determines an organisation’s actual level of cybersecurity.”
Companies are investing in AI agents
Organisations are gradually moving beyond using AI solely as a tool supporting human analysts and are beginning to deploy AI agents capable of independently carrying out increasingly complex tasks.
According to the WEF and KPMG report, 88% of companies are already investing in AI agents. At the same time, 92% of technology leaders believe that the ability to manage such agents will become one of the most important cybersecurity skills over the next five years.
AI agents can analyse alerts, combine information from multiple systems, prioritise incidents and recommend corrective actions. More advanced solutions can also perform certain operations without direct human involvement.
However, as systems become more autonomous, the importance of an appropriate oversight model also increases.
Greater AI autonomy requires stronger controls
The degree of independence given to artificial intelligence should depend on the level of risk associated with the task being performed.
AI may act as a tool supporting human decision-making, provide recommendations that require approval or independently perform reversible operations under continuous supervision.
In selected cases, systems may operate more autonomously, but they should remain subject to control, monitoring and accountability mechanisms.
In high-risk areas, decisions that could have permanent consequences for an organisation, its customers or its infrastructure should remain under full human control.
This includes actions that could lead to the permanent deletion of data, the blocking of critical services, the disconnection of parts of an organisation’s infrastructure or decisions that could affect business continuity.
Organisations should also clearly define who is responsible for actions taken by AI agents, how those actions are documented and when a human operator should take control of the process.
Successful AI adoption depends on organisational readiness
Effective use of artificial intelligence in cybersecurity requires organisations to be properly prepared. The starting point should be to define the business objectives of the implementation and identify the problems that AI is expected to solve.
Companies must also assess the readiness of their processes, the quality of their data, their technology infrastructure and the skills of their employees.
Solutions should initially be tested through pilot projects and only then deployed on a wider scale.
Building trust in the technology is also important, while organisations must remain aware of its limitations. AI models can make mistakes, operate on incomplete data or generate recommendations that do not reflect the wider business context.
Excessive reliance on automated decisions may gradually weaken the skills of security teams and create a false sense of protection.
For this reason, organisations should develop contingency procedures and regularly test scenarios covering AI system errors or outages.
Skills shortages remain a major barrier
Although AI can reduce employee workloads and automate repetitive tasks, the shortage of qualified specialists remains one of the most serious challenges. According to the report, 54% of organisations identify this as a key barrier.
Implementing artificial intelligence requires not only technical expertise but also knowledge of risk management, data protection, regulatory compliance and the supervision of AI models and agents.
Employees must be able to assess the quality of system-generated recommendations, recognise the limitations of AI and take control in situations where automated action could lead to undesirable consequences.
AI can support compliance with NIS2 and DORA
Artificial intelligence is also becoming a tool that can help organisations meet increasingly demanding regulatory requirements, including those arising from the NIS2 Directive and the Digital Operational Resilience Act, or DORA.
Automating system monitoring, incident documentation and response procedures can improve efficiency without requiring a proportionate increase in operating costs.
AI can also support report preparation, the analysis of security gaps and the collection of information needed to demonstrate regulatory compliance.
Responsibility for compliance and decision-making, however, remains with the organisation. The use of AI does not release companies from the obligation to ensure proper oversight, risk controls and the security of the solutions they deploy.
About the report
The report Empowering Defenders: AI for Cybersecurity was prepared as part of the Cyber Frontiers initiative led by the World Economic Forum in cooperation with KPMG.
The publication examines the use of artificial intelligence throughout an organisation’s entire cybersecurity lifecycle.
It draws on case studies provided by World Economic Forum partners and insights from workshops involving representatives of more than 84 organisations across 15 sectors of the economy.





