Ask a security team what has changed most in the last two years, and most will say the same thing: AI now sits on both sides of the fight. Attackers use it to write convincing phishing emails and clone voices. Defenders use it to spot a breach in hours instead of months. Any Artificial Intelligence statistics worth reading in 2026 need to capture both halves of that picture, not just the marketing-friendly half.

This guide pulls together the numbers that matter for UK and Irish organisations specifically: how much AI is saving defenders, how exposed businesses are to AI-driven fraud, and where the gap between AI adoption and AI security readiness is widest. Below, you’ll find data on market growth, breach costs, the UK’s own Cyber Security Breaches Survey, the skills gap facing security teams, and the tactics attackers are using right now.

Global AI in Cyber Security Market Growth and Adoption

Artificial Intelligence Statistics, Global AI

Spending on AI-driven security tools has grown every year since 2020, and the pace is not slowing. For any business weighing up whether AI belongs in its security budget, the market figures below are among the first Artificial Intelligence statistics worth knowing, and give a useful sense of scale before we get into cost and risk data further down.

Market Size and Forecasts

Estimates vary depending on which analyst firm you ask, largely because “AI in cyber security” gets defined differently across reports. Grand View Research puts the global market at $25.35 billion in 2024, rising to $35.91 billion in 2025, and forecasts it will reach $93.75 billion by 2030, a compound annual growth rate of 24.4%. Other analysts, including MarketsandMarkets and The Business Research Company, publish narrower or wider figures depending on scope, but the direction is consistent: strong double-digit growth through the rest of the decade. Antivirus software and endpoint protection vendors are among those folding AI detection into standard products, which is part of why the antivirus software category has changed so much in the past three years.

Adoption by Sector

Adoption is not even, and these are some of the Artificial Intelligence statistics that vary most by sector in this guide. Finance, insurance and large technology firms lead the way, largely because they have the budget and the in-house data science skills to deploy AI security tools properly. Smaller organisations are adopting more slowly, often through vendor products rather than building anything in-house, which matches what we cover in our guide to why cyber security matters for smaller teams with limited resources.

Faster Detection, Lower Costs: The Efficiency Case for AI

Artificial Intelligence statistics about cost savings all come back to one thing: speed. The faster a breach is spotted and contained, the less it costs, and this is where AI’s advantage over manual monitoring is clearest in the data.

Breach Costs, With and Without AI

IBM’s 2025 Cost of a Data Breach Report found the global average cost of a breach fell to $4.44 million, down 9% from $4.88 million in 2024 and a return to 2023 levels. The drop was driven largely by faster containment at organisations using AI-powered defences. Firms that used AI and automation extensively across prevention, detection and response saved $1.9 million per breach compared with those using none, and identified and contained incidents roughly 80 days faster on average.

Where the Savings Come From

The savings are not just about faster alerts. IBM’s data shows that having a tested incident response plan saves an average of $2.66 million per breach, and combining that with AI-driven detection and a zero trust architecture stacks the savings further. The catch is that these gains only appear when AI tools are properly governed. Unsanctioned or “shadow” AI, meaning AI tools staff adopt without IT’s knowledge, added $670,000 to the average breach cost and took ten days longer to contain than breaches without it. One in five organisations in IBM’s study reported a breach linked to shadow AI, which makes AI governance as important as AI adoption itself.

The UK and Ireland Picture: A Different Story to the US Data

Most of the AI cyber security statistics in circulation come from US-led reports, which is a problem if you’re trying to make the case to a UK board or a client in Dublin. Artificial Intelligence statistics drawn only from US sources miss this part of the picture entirely, since UK and Irish organisations face their own regulatory backdrop and, as the data below shows, their own gap between AI enthusiasm and AI security readiness.

The UK Cyber Security Breaches Survey 2025/2026

The Department for Science, Innovation and Technology published its Cyber Security Breaches Survey 2025/2026 in April 2026, based on responses from over 2,100 UK businesses and more than 1,000 charities. It found that 43% of businesses and 28% of charities experienced a breach or attack in the past 12 months, broadly flat on the previous year.

The survey’s new AI section found that around a third of businesses (31%) and a quarter of charities (25%) are using AI, adopting it or actively considering it. Of that group, only 24% of businesses and 27% of charities said they had cyber security practices in place to manage the risks AI introduces, meaning adoption is running well ahead of governance for most UK organisations.

NCSC Guidance and the AI Cyber Security Code of Practice

The National Cyber Security Centre, working with DSIT, published the Code of Practice for the Cyber Security of AI at the start of 2025. It sets baseline security requirements across the lifecycle of an AI system, from design through to decommissioning, and was adopted as a global standard by the European Telecommunications Standards Institute in May 2025, with 18 countries endorsing it.

The NCSC’s 2025 Annual Review also confirmed the first full operational year of its Laboratory for AI Security Research, set up to study how AI changes both attack and defence. In a March 2026 warning, the NCSC noted that frontier AI models can now be used to probe parts of a network for the cost of a takeaway meal, which is a useful line for explaining to non-technical stakeholders why the barrier to entry for attackers has dropped so far. Organisations building or buying AI systems should treat the NCSC’s guidance on securing AI as the baseline reference, rather than a nice-to-have.

Ireland’s Regulatory Position

Irish organisations sit under the same EU frameworks that increasingly shape UK guidance by extension, including the EU AI Act’s phased obligations for high-risk AI systems and NIS2’s incident reporting requirements for essential and important entities. Ireland’s National Cyber Security Centre has echoed the UK’s line that AI security needs to be built in from the design stage, not added after deployment, particularly for organisations in finance and healthcare where Dublin’s tech and fintech sector has driven rapid AI adoption.

The Financial Impact: Breach Costs and Cyber Insurance

Artificial Intelligence Statistics, The Financial Impact

Board-level conversations about AI security tend to move fast once the finance team gets involved, because the numbers above translate directly into premiums, provisioning, and audit findings.

Reduced Breach Costs at Scale

For a mid-sized UK organisation, the $1.9 million average saving from extensive AI use in security operations is not an abstract number. It’s one of the Artificial Intelligence statistics boards act on fastest, since it is close to the entire annual security budget for many mid-market firms, which is why insurers and auditors are starting to ask pointed questions about AI governance during renewal and due diligence conversations.

Insurance and the AI Governance Gap

Cyber insurers are increasingly treating AI governance as a rating factor rather than an afterthought. Analysis following the UK’s 2025/2026 breaches survey noted that insurers are beginning to price the gap between AI adoption and AI security readiness, with some risk teams describing fragmented AI governance and untested incident scenarios as a growing concern at renewal time. Separately, research from insurer QBE found that 95% of UK businesses were using AI or looking into it, while 80% believed cyber threats were rising, a combination that underwriters are watching closely.

Building the Business Case

When making the case for AI security investment internally, the strongest argument is rarely the technology itself. It’s the combination of faster containment, lower average breach costs, and the fact that insurers are starting to reward organisations that can demonstrate proper AI governance rather than simply AI adoption.

The Human Factor: Skills Gaps and Analyst Burnout

None of the above matters if there’s nobody with the right skills to run it. This is the part of the AI security conversation that gets the least attention, despite being the one most security leaders raise first when asked what keeps them up at night.

The Widening Skills Gap

Some of the most overlooked Artificial Intelligence statistics in this area come from the workforce side. ISC2’s 2025 Cybersecurity Workforce Study, based on responses from over 16,000 professionals worldwide, found that 59% of respondents reported critical or significant skills gaps on their teams, up sharply from 44% the year before.

For the first time, ISC2 chose not to publish a single global workforce shortage figure, arguing that the gap in specific capabilities, particularly around AI and cloud security, now matters more than raw headcount. The consequences are measurable: 88% of organisations experienced at least one significant security incident linked to a skills shortage in the past year, and 69% experienced more than one.

AI as Both Pressure and Relief

AI is a mixed blessing for stretched teams. It is reshaping entry-level analyst work, with Gartner projecting that more than half of Tier 1 security operations centre tasks will be handled by AI by 2028, which could ease some of the burnout ISC2’s respondents describe. At the same time, teams are expected to learn new AI-specific skills, such as validating AI-generated alerts and auditing AI systems themselves, on top of existing workloads. Whether that trade-off nets out as relief or extra pressure seems to depend heavily on whether organisations invest in training before rolling AI tools out, rather than after.

Closing the Gap

Practical steps for UK organisations include treating AI literacy as core training rather than an optional extra, being realistic about what entry-level hires can be expected to know on day one, and being honest with boards about the gap between the skills teams have and the skills AI tools require to run safely. Our guide to key cybersecurity definitions is a useful starting point for teams building internal training around newer AI-specific terminology.

The Dark Side: How Attackers Are Using AI

Every gain on the defender’s side of these Artificial Intelligence statistics has an equivalent on the attacker’s side. This section covers where AI is currently doing the most damage, and where UK organisations are most exposed.

AI-Generated Phishing

Testing cited by the Cloud Security Alliance in early 2026, drawing on Microsoft’s 2025 Digital Defense Report, found that AI-generated phishing emails achieved a 54% click-through rate compared with 12% for manually written messages in the same test set. Separate research reported that over 80% of phishing emails now contain AI-generated elements, a sharp rise through the second half of 2025.

Volume has grown alongside sophistication: industry tracking recorded more than 850,000 phishing attacks in the final quarter of 2025 alone. These figures make clear why generic “spot the bad grammar” advice no longer works, and why understanding the different types of hackers and their methods now needs to include AI-assisted actors as a distinct category.

Deepfakes and Voice Cloning

The UK has become a specific target for this kind of fraud, and it produces some of the sharpest year-on-year swings among the Artificial Intelligence statistics in this guide. Sumsub’s 2025-2026 Identity Fraud Report recorded a 94% year-on-year rise in deepfake attempts in the UK, with deepfakes involved in around 11% of first-party fraud schemes globally.

The same report found that “sophisticated fraud”, meaning multi-step, AI-assisted attacks rather than simple one-off scams, grew from 10% to 28% of all identity fraud cases year-on-year, a 180% increase in share. For businesses, the practical risk is usually voice cloning used in invoice fraud or executive impersonation calls, rather than the video deepfakes that get most of the media attention.

What This Means for Defenders

The common thread across both phishing and deepfake data is that traditional staff awareness training, built around spotting obvious tells, needs an update. AI-generated attacks are, by design, built to pass the tests that older training relied on.

If one thing stands out among the Artificial Intelligence statistics in this piece, it’s this: adoption is running ahead of governance, in the UK and everywhere else, and that gap runs through nearly every figure above. If your organisation is already using AI in any part of its security stack, the priority is closing that gap, not adding more tools on top of it. Have you seen AI change the kinds of attacks your organisation faces, for better or worse? Share what you’ve experienced in the comments below; we read and reply to them.

Frequently Asked Questions

These are the questions that come up most often when UK teams try to turn the data above into a business case or a board briefing. Each answer points back to a specific, sourced figure rather than a general impression.

What are the most useful Artificial Intelligence statistics for a UK business case?

The clearest figure is IBM’s finding that organisations using AI and automation extensively in security operations saved $1.9 million per breach and detected incidents 80 days faster than those that didn’t. It directly links AI investment to a measurable financial outcome, which is usually what boards want to see before approving spend.

How much faster can AI detect a cyber attack?

IBM’s 2025 data found organisations using AI extensively identified and contained breaches around 80 days faster on average than those with no AI or automation in place, though the exact figure varies by sector and by how the AI is deployed.

Does using AI increase a business’s own risk of being attacked?

It can, if it’s adopted without governance. IBM found that unsanctioned “shadow AI” added $670,000 to the average breach cost and took longer to contain. The risk sits less with AI itself and more with deploying it without visibility, access controls or a clear owner.

What percentage of UK businesses use AI for cyber security?

These are among the Artificial Intelligence statistics most worth repeating to a UK board: the UK’s 2025/2026 Cyber Security Breaches Survey found that around a third of businesses are using AI, adopting it or considering it, but only 24% of that group have cyber security practices in place to manage the associated risk.

Will AI replace cybersecurity analysts?

Not entirely, based on current data. Gartner projects that more than half of Tier 1 SOC tasks will be handled by AI by 2028, which changes entry-level roles significantly, but ISC2’s research still points to a widening gap in higher-level skills such as incident response and cloud security that AI tools cannot currently close.