Why AI Won’t Solve Cybersecurity’s Talent Shortage

▼ Summary
– Demand for new cybersecurity specialist roles has more than doubled, with AI governance, engineering, and risk positions being created as AI automates routine tasks.
– Only 38% of organizations provide comprehensive AI security training, and nearly one in four have no AI governance plans.
– Regulations like NIS2, DORA, and SEC are driving organizations to restructure teams, create specialist positions, and prioritize certifications.
– Experienced cybersecurity professionals remain the hardest to recruit, and poorly defined career paths hinder hiring and retention.
– Technical capability now outweighs work experience as the top hiring criterion, while time and budget constraints limit training and widen skills gaps.
Organizations are fundamentally rethinking how they hire and structure cybersecurity teams, moving away from traditional credentials and toward workforce frameworks and verified skills. The shift comes as artificial intelligence reshapes security roles and new regulations create specialized hiring demands. According to the SANS 2026 Cybersecurity Workforce Survey, demand for specialists in emerging roles more than doubled over the past year, while hiring for existing cybersecurity skills also saw a notable uptick.
AI is transforming security work by reducing manual analysis and automating routine tasks. This automation has created a fresh wave of demand for roles centered on AI governance, engineering, and risk management. Survey data shows 54% of organizations now have AI security policies, yet only 38% offer comprehensive AI security training. Nearly one in four companies still lack any formal AI governance plans.
The impact on team composition is significant. Nearly three-quarters of respondents reported that AI has influenced their team structure. The most common adjustments involved workflow automation and less manual analysis, with relatively few organizations reporting workforce reductions. Employers are actively adding AI-focused cybersecurity roles, such as AI security engineers, AI governance analysts, and AI/ML security specialists. Despite this, experienced cybersecurity professionals remain the hardest positions to fill.
Compliance is expanding demand for specialists, as new regulations reshape hiring priorities. Companies are increasingly adopting workforce frameworks like NICE and the European Cybersecurity Skills Framework to standardize roles and skills. Regulations such as NIS2, DORA, DoD 8140, SEC, and CMMC are driving demand for specialist roles, particularly in critical infrastructure, financial services, and defense contracting.
“Organizations are building entirely new specialist positions, restructuring teams around regulatory requirements, and facing real enforcement consequences if they don’t,” said James Lyne, CEO of SANS Institute. Certifications are also gaining importance for hiring, audits, client requirements, and career development as companies seek to demonstrate cybersecurity proficiency.
Experienced professionals remain difficult to recruit, especially in senior leadership and cybersecurity management roles, including CISOs. These positions account for most hiring decisions and take the longest to fill. Organizations also cited poorly defined cybersecurity career paths as a major retention challenge, with relatively few offering clear progression pathways.
Skills gaps are outpacing staffing shortages as employers prioritize technical capabilities over work experience. AI, new regulations, and evolving threats are changing the skills required across security teams. Time and budget constraints remain the biggest barriers to closing these gaps, limiting training and professional development. Companies linked those gaps to delayed projects, slower incident response, increased burnout, and difficulty adopting new technologies. Notably, technical capability ranked ahead of work experience as the most important hiring criterion, with demonstrated skills taking clear priority.
(Source: Help Net Security)


