When the Weakest Link Started Using AI: What the 2026 SANS Report Tells Security Leaders
Sep 8, 2026 | Industry Insight
Every year, SANS publishes its Security Awareness & Culture Report, and every year it tells us roughly the same story - social engineering is still the top human risk, programs mature slowly, and time (not budget) is the biggest constraint on getting anything done. The 2026 edition (the 11th) confirms all of that. But it also contains one number that should get every CISO's attention: AI has jumped from the fourth-highest human risk to the second-highest, in just two years.
Social engineering still holds the top spot and probably will for a while. Phishing, smishing, and vishing simply can't be solved with technology alone (see SecureSky’s blogs https://blog.securesky.com/your-attackers-hired-ai.-have-you and https://blog.securesky.com/cybercrime-has-a-subscription-plan-and-it-is-targeting-you to see how AI is helping malicious actors in the social engineering arena).
AI's rapid climb up the human risk list isn't a fluke. It reflects something security teams are living through right now. Employees are adopting AI faster than any policy, training program, or governance framework can keep pace with.
It's Not One Risk. It's Three.
One of the more useful reframes in this year's report is that "AI risk" isn't a single thing to train on. SANS breaks it into three distinct categories, each with a different threat model and a different audience:
-
Generative AI (GenAI). The tools most employees already use — ChatGPT, Copilot, Gemini, Claude. The risk here isn't the technology itself; it's what people do with it. Pasting sensitive data into public tools, trusting unreviewed output as if it came from a subject-matter expert, and using personal accounts because sanctioned enterprise versions either don't exist yet or are too locked down to be useful.
-
Vibe coding. Using GenAI to write software by describing what you want in plain language rather than writing code. It's a productivity story until you realize employees with zero development background are now shipping code into production environments with no idea whether it's secure — and often no one in security even knows it happened.
-
Agentic AI. Bots and scripts that use GenAI to take actions on someone's behalf, with no human reviewing each step. This is the one that should worry security teams most, not because the AI is malicious, but because the more autonomy an agent has and the more sensitive the systems it touches, the faster a small mistake compounds into a large one.
The report's framing for agentic AI in particular is worth borrowing - treat AI agents the way you'd treat a new hire. You already have policies for who can touch sensitive data and how. Agentic AI doesn't need a brand-new governance framework. It needs your existing rules for people, extended to include bots that act like people.
Why Annual Training Can't Keep Up
Here's the uncomfortable part. Most security awareness programs are still built around an annual cadence. A training module deployed once a year, refreshed with new content, checked off a compliance list. That model was already struggling against phishing, which evolves month to month. Against AI, it doesn't stand a chance. A developer experimenting with vibe coding faces a completely different risk profile than a finance employee dropping customer data into a chatbot, and both differ again from an executive whose AI agent is making decisions without anyone watching. One module can't address all three, and by the time it's built, the specific risks it covers may have already shifted.
This is exactly the gap that continuous, human-risk-aware monitoring exists to close. Annual training tells you what people were taught. It doesn't tell you what's actually happening in your environment. Which unauthorized AI tools are in use, which employees are pasting sensitive data where it shouldn't go, or which "shadow AI" workflows have quietly become part of how work gets done. That visibility has to come from your detection stack, not your LMS.
What This Means for Your Program
A few practical takeaways, whether you're building out a security awareness function or evaluating whether your detection and response coverage extends to this risk:
-
Extend existing policies to AI rather than starting from scratch. Data classification, acceptable use, and access rules already exist. The work is applying them to GenAI, vibe-coded code, and AI agents specifically, not reinventing governance.
-
Assume shadow AI is already happening. Employees are not waiting for an approved tool. The report notes this pattern is spreading faster than shadow IT ever did, in part because the barrier to trying a new AI tool is close to zero.
-
Build visibility into where AI activity actually touches your environment. Logins from AI tools, unusual data flows, new agent-driven processes - the same way you'd want visibility into any other identity or endpoint behavior. This is squarely where a Microsoft-stack-centered detection program (Sentinel, Defender XDR, Entra ID) already has the telemetry. The gap is usually knowing what to look for.
-
Don't treat human-based AI risk as a training problem alone. SANS makes the point that AI risk moves too fast for a training calendar to track. Training builds awareness of the categories of risk. Detection and response is what catches the specific instance.
Social engineering earned its position at the top of the list the hard way, over a decade of data. AI earned its climb to second place in two years. That trajectory alone is worth paying attention to. Not as a reason to panic, but as a reason to make sure your program, and your detection coverage, are built for a risk that won't sit still long enough for an annual update to catch it.
This post draws on findings from the SANS 2026 Security Awareness & Culture Report: https://www.sans.org/mlp/ssa-security-awareness-report
If you're assessing how AI-related human risk shows up in your environment, or whether your current detection coverage would catch it, SecureSky's team can help you find out. Please contact us at:
+1 833.473.2759 (+1 833.4SecSky)
