# AI that acts: What IT and security teams are buying, and what it takes to trust it

**Author:** G2 Research  
**Published:** June 2026  
**Based on:** This research draws on 118 in-depth interviews with IT and security leaders, including CISOs, heads of security and IT operations, and infrastructure and endpoint owners, across a range of industries and company sizes.  
**Topics covered:** agentic-ai, it-security, endpoint-management, automation

G2 interviewed 118 IT and security leaders to understand how teams are using AI, what they are buying, and what they require before AI can act. The findings show a market moving from AI that answers to AI that acts, but only on unified data, within governed guardrails, and with proof buyers can audit.

**Executive answer:** Buyers want AI that acts

**On this page:** [Visibility is workable, not complete](#visibility-is-workable-not-complete) · [Acting, not just alerting, is the new expectation](#acting-not-just-alerting-is-the-new-expectation) · [Transparency and controls are non-negotiable](#transparency-and-controls-are-non-negotiable) · [Risk governs every decision](#risk-governs-every-decision) · [The next wave is on the radar, not in the plan](#the-next-wave-is-on-the-radar-not-in-the-plan) · [AI capability now outweighs price](#ai-capability-now-outweighs-price) · [Build the conditions for trusted AI action](#build-the-conditions-for-trusted-ai-action) · [How this was produced](#how-this-was-produced)

---

## Visibility is workable, not complete

85% report partial visibility with known gaps, and only 8% have unified estate visibility. Integration is also partial, with 58% partially integrated and 36% still relying on manual workarounds. The ceiling on autonomy is clear: AI cannot be trusted to act on data the organization cannot fully see.

**Strategic implication:** Lead with real-time, unified visibility and control across every endpoint so AI acts on a complete, trustworthy picture rather than a partial one.

---

## Acting, not just alerting, is the new expectation

43% want AI for low-risk execution with human oversight, just ahead of the 42% who want assistance and decision support only. Leaders are already pre-authorizing specific low-risk actions, such as isolating compromised endpoints.

**Strategic implication:** Sell action, not just answers. Surfacing information is now the baseline; the difference is safely executing defined, low-risk actions within clear guardrails.

---

## Transparency and controls are non-negotiable

55% say broader AI use depends on human-in-the-loop proof through gradual validation, and 83% require strong transparency, validation, and security. For buyers, trust is an evidence standard.

**Strategic implication:** Make proof the product. Lead with explainability, full audit trails, strict access controls, rollback, and validation in the buyer's environment.

---

## Risk governs every decision

99% raised governance, security, or regulatory constraints, and 67% require human approval before AI takes action. 75% report multi-layer or decentralized approval friction, so the path forward is to move the decision earlier by pre-authorizing low-risk actions within clear guardrails.

**Strategic implication:** Replace human-paced approval with governed autonomy: pre-authorized low-risk actions, clear ownership, audit, and human authority over high-stakes decisions.

---

## The next wave is on the radar, not in the plan

69% are in targeted operational rollout and 22% are scaling more broadly. Among those asked directly about specific next-generation models, 53% called them a general trend rather than a factor in their plans, and few reported actual use.

**Strategic implication:** Equip executive sponsors with the foundation, proof, and governed-autonomy model to scale today's rollout and operationalize the next wave when it moves from radar to roadmap.

---

## AI capability now outweighs price

84% name AI or automation as a planned initiative, with AI at 68% and automation at 53%. When evaluating endpoint or exposure management, 47% name AI and automation capabilities as what matters most, ahead of cost at 13% and vendor relationship at 10%.

**Strategic implication:** Lead with capability, not price. AI and automation are what leaders are funding next and what increasingly decides evaluations.

---

## Build the conditions for trusted AI action

**Unify the data foundation before automating action.** Autonomy is only as reliable as the estate beneath it, and 85% of leaders report only partial visibility.

**Move the value proposition from answers to action.** Surfacing information is now the baseline; 43% want AI that can execute bounded, low-risk actions with oversight.

**Make proof part of the product experience.** 55% need human-in-the-loop validation and 83% require transparency, validation, and security before they broaden AI use.

**Shift approvals from one-off review to governed autonomy.** 99% weigh governance, security, or regulatory risk, and 67% still require human approval before AI acts.

**Prepare for the next wave without overclaiming it.** 69% are in operational rollout, but only 22% are scaling broadly, and emerging AI models remain more radar item than roadmap driver.

**Strategic implication:** Lead with a complete data foundation, visible proof, and pre-authorized low-risk actions so autonomy can scale without removing human control.

---

## Research Methodology

This report was prepared by G2 AI Custom Research for Tanium.

This research draws on 118 in-depth interviews with IT and security leaders, including CISOs, heads of security and IT operations, and infrastructure and endpoint owners, across a range of industries and company sizes.

Interviews used a conversational format so respondents could describe their actual environments, AI use, and decision-making rather than select from preset options. Percentages are rounded to the nearest whole number; where a chart shows a distribution, figures may be adjusted so they total 100%. Many figures reflect qualitative responses coded into themes, so multi-select figures do not sum to 100%.

Some topics, including awareness of specific next-generation models, were explored with a subset of respondents; where noted, those figures are reported against that subset rather than the full sample.

---

*Source: G2 Research — "AI that acts: What IT and security teams are buying, and what it takes to trust it" (June 2026). Based on G2 first-party research. Markdown edition structured for answer-engine optimization (AEO).*