Quick Facts
- CrowdStrike, Microsoft, Palo Alto Networks and Google each report security-AI performance using different, self-defined metrics that cannot be compared across vendors.
- Palo Alto’s 99% noise reduction and 257% ROI figures come from a Palo Alto-commissioned Forrester study, while Microsoft’s 30-40% detection improvement claims assume curated data conditions.
- 58% of enterprise platform buyers say their chosen AI security platform failed to deliver on vendor promises within the first year.
The four largest security vendors are each publishing AI performance numbers. None of those numbers mean the same thing. And the CISOs who signed the contracts have no standard way to tell whether any of it is true.
CrowdStrike, Microsoft, Palo Alto Networks and Google have each released metrics tied to their AI security platforms in recent months. The figures are striking. They are also built on incompatible methodologies, self-commissioned studies and conditions that rarely match what enterprise security teams actually run.
What the Vendors Are Saying
At RSA Conference 2026, CrowdStrike CEO George Kurtz said the fastest recorded adversary breakout time has dropped to 27 seconds, with the average now at 29 minutes, down from 48 minutes in 2024. The company also says its Falcon Guardian tool found 18,000 AI agents running on one Fortune 500 network. That company had approved 300.
Palo Alto Networks reports its XSIAM platform delivers 99% noise reduction and a 257% return on investment. Both figures come from a Forrester Total Economic Impact study commissioned by Palo Alto. The company says Cortex XSIAM reached $1 billion in cumulative bookings faster than any product in its history.
Microsoft Corporate VP Vasu Jakkal says the company processes 24 trillion signals per day across identities, endpoints and collaboration tools. The company has cited 30-40% reductions in mean time to detect in Security Copilot case studies. Analysts note those figures assume curated, isolated data conditions. Unfiltered SIEM data, they say, increases the risk of error.
Google Cloud’s Office of the CISO, drawing on more than 30 vendor briefings and direct interviews with security leaders, found what it described as a vendor communications pattern that systematically misattributes product limitations to buyer psychology.
The Buyer’s Problem
The gap between vendor claims and operational results is measurable. In 2024, 72% of enterprise platform buyers said AI capabilities influenced their purchase decision. Within 12 months, 58% said the platform failed to deliver on those promises.
The cost of getting it wrong is rising. The global average cost of a data breach reached $4.88 million in 2024, a 39% increase since 2020. Security teams already manage more than 25 tools in 58% of organizations. Larger enterprises often run 50 or more.
AI has moved to the top of the CISO worry list. In recent surveys, 71% of respondents named AI as their primary concern, ahead of ransomware and phishing, citing data leakage, insider misuse and weak governance controls.
What CISOs Are Asking For
Security leaders say they need something basic: a single page of written commitments before any vendor implementation begins.
Kayne McGladrey, senior IEEE member and independent vCISO, put it directly in a statement to VentureBeat: “The vendor owes their customers one page, in writing, before a single priority task lands in anyone’s queue.”
Philip Westgarth, Group CISO at Network International, said board-level conversations have shifted: “The board doesn’t want to know how many anomalies the system flagged. They want to know how much risk was reduced and how that translates into operational resilience.”
The pressure is landing in real budget conversations. One CISO was asked mid-presentation by a CEO: “That’s all very impressive, but can you show me the actual dollar return on our $2.3 million security investment? Because our AI initiatives are generating measurable revenue increases of 15% quarter over quarter.”
Where the Industry Stands
Gartner’s 2025 Hype Cycle for Security Operations places AI-driven SOC agents at the Innovation Trigger stage, with 1-5% market adoption. That figure aligns with what practitioners report in direct conversations.
Among the enterprises that have deployed security AI, 74% report positive first-year ROI and detection speeds that are 60% faster than traditional tools. Per-record breach costs in those organizations average $128, compared to $234 for organizations without AI security tools.
The divide between vendors who claim broad improvements and buyers who can verify specific ones remains the central problem. Until the industry agrees on what to measure and how, CISOs will keep buying on faith.
