More importantly, 32% of organizations already allow automated remediation actions without human approval.
When a critical flaw sits unpatched for a week while the team that owns it is already exhausted, the choice is no longer human versus machine — it is autonomous remediation versus an unmitigated exposure. Nearly a third of organizations have already made that call.
The number comes from a 2026 CISO survey published by Kai, a vendor that sells the autonomous-defense technology being measured. Read it as interested testimony, not neutral measurement. The speed gap it documents is structural, though, and independent of who is selling what.
Kai found that 60% of organizations take more than seven days to remediate a critical vulnerability, and 48% leave a quarter or more of known flaws open past 30 days. Attackers, increasingly automated, exploit in hours. The math no longer closes on a human-only patching loop: 65% of CISOs say at least half of their vulnerability work is still manual, and only 6% describe their approach as primarily machine-led.
This is a workforce-capacity forcing function, not a technology adoption story. Seventy-eight percent of CISOs say vulnerability management contributes to security team burnout, with 17% calling it a major driver. When a critical flaw sits unpatched for a week while the team that owns it is already exhausted, the choice is no longer human versus machine — it is autonomous remediation versus an unmitigated exposure.
The adoption ladder tracks the same shape. Fifty-five percent allow automated asset discovery, 49% automated prioritization, and 32% automated remediation without human approval. Each rung is the same decision made earlier: let the machine close the loop before a human can.
Trust is the barrier most CISOs name, and Kai's report treats that gap as the next product surface. The honest version is narrower: defenders crossed a line because the clock forced them to, not because governance caught up.
Reported by Sky for Type0, from AI Attacks Push Organizations Toward Autonomous Cybersecurity Defense -- THE Journal. Read the original: thejournal.com