---
title: Enterprises Spend 17 Times More on AI Defense Than on Securing AI Itself
description: As cybersecurity spending nears $240 billion in 2026, enterprises spend about 17 times more using AI to defend than securing the AI agents they deploy.
author: Darie Nani (Editor-in-Chief)
date: 2026-08-12T19:31:59.520Z
updated: 2026-08-12T19:31:59.529Z
canonical: https://www.sovereignmagazine.com/article/ai-defense-spending-17x-securing-ai-2026
image: https://cdn.nanimediahouse.com/ai-security-spending-gap-145642.webp
categories: Science &amp; Tech
content_type: Analysis
region: Global
publication: Sovereign Magazine
schema_type: Article
---

Enterprises are spending roughly 17 times more on using artificial intelligence to defend themselves than on securing the AI systems they are rolling out. In 2025 companies put [about $49 billion into AI-amplified security](https://softwarestrategiesblog.com/2026/03/24/information-security-spending-2026/), the tools that use AI to detect threats and automate defense, and about $2.8 billion into protecting the AI models, data and pipelines they run themselves, according to Gartner. That imbalance is widening just as corporate security budgets head toward a record.

## Security Budgets Head Toward $240 Billion

CNBC reported this week that the spread of AI agents through corporate software, and a rise in attacks that target them, is set to drive a boom in cybersecurity spending. It cited Gartner’s forecast that worldwide information-security spending will [climb by roughly 12 to 13 percent in 2026, to about $240 billion](https://www.splunk.com/en_us/blog/learn/it-tech-spending.html). A separate reading of Gartner’s fourth-quarter 2025 forecast put the figure closer to $244 billion, up about 13 percent year over year; either way, security budgets are rising by roughly 12 to 13 percent, one of the steeper annual increases the category has seen.

## AI Defense Spending Dwarfs AI Security Spending

The 17-to-1 gap splits two different jobs. Using AI as a security tool is a maturing market of products that promise to make existing security teams faster and cheaper to run. Securing AI as a target is the newer, smaller category: protecting the models, training data and pipelines a company runs, and guarding against risks like prompt injection, data leakage and agent hijacking. The bigger the role AI plays in a company’s defenses, the wider that gap grows.

## Agents Spread Faster Than Security Plans Do

Gartner projects that 40 percent of enterprise applications will include a task-specific AI agent by the end of 2026. Against that pace of adoption, only about 6 percent of organizations report having an advanced strategy for securing AI agents. Most companies are deploying agents into core software well ahead of building the controls to govern what those agents can access, touch or act on.

## The Boom Leaves the Agents Themselves Thinly Covered

The imbalance leaves one category of enterprise software, the agents themselves, thinly covered by the money flowing into security. For a security buyer, the $240 billion figure describes a spending boom, not a solved problem: a large and growing share of enterprise software now runs on agents that most organizations are not yet equipped to secure to the same standard as the rest of their stack.

## FAQ

**Q: What is prompt injection?**
It is a way of attacking an AI system by hiding instructions in the text or data it reads, so the model follows an attacker’s commands instead of its user’s. It is one of the main risks the securing-AI category is meant to address.

**Q: What is agent hijacking?**
It is when an attacker takes over what an AI agent is able to do, using the agent’s own access to a company’s systems, data or tools to act in ways its owner never intended.

**Q: Does spending 17 times less on securing AI mean companies are dangerously exposed?**
Not on its own. Part of the gap reflects that AI-defense tools are a larger, more established market while securing AI is newer and cheaper per dollar. The risk is that agent adoption is outpacing the controls, which is why the smaller category is the one to watch.

**Q: Why are AI agents a bigger security risk than ordinary software?**
An agent can read data, make decisions and take actions across a company’s systems, so a compromised agent can do more damage than a static app, and it does so using legitimate access that is harder to spot.
