
After years sitting across the table from enterprise security leaders, I've stopped hearing the question I used to hear constantly: does AI belong in security operations? They now ask how to deploy it without breaking what already works.
Our latest benchmark data shows that shift. Ninety-seven percent of organizations are either using AI (58%) or evaluating it (39%). So the story isn't adoption versus rejection. It's the split between companies that have put AI to work and the ones stuck in an evaluation loop with no exit.
I've watched enterprises stand up AI review boards over the past year, and often the executive sponsoring the purchase can't describe how their own review process works. One prospect turned down a free trial because saying yes would trigger convening that board, and nobody wanted to start the clock. A lot of teams are stuck in that state: not opposed to AI, just frozen in front of it.
Evaluation isn't neutral, though. While one company builds a business case and compares vendors, the company down the street is cutting manual work and scaling coverage without adding headcount. Every month evaluating widens that gap.
And these teams aren't evaluating from a position of calm. The average organization fields 342 alarms a day, with at least a third of them false. For enterprises it climbs far past 421, with false-alarm rates near 44%. This is self-reported; what we see with customer environments is far higher, around 80-90% false. Ask operators what they'd hand off first and they name the same two chores: triaging alarms and sending routine notifications. Yet 62% still don't run automated real-time device monitoring. Nobody is deferring AI while humming along efficiently. They're deferring it while drowning.
I see what that does to a shift. Operators wade through noise until they slip into autopilot, and autopilot is where the one incident that matters gets missed or answered 10 minutes late. Add the swivel-chair problem, toggling between the VMS, access control, an intel feed, and a chat window to stitch together one event, and you've built a system that punishes attention.
The most common thing I hear from buyers is, "We need to get our house in order first." I understand the instinct. It's also a trap. You're never fully ready. Pick one persistent problem, point AI at it, check the outcome, iterate.
Here's what that looks like. A customer came to us with 2,500 incidents a day and a target under 100. We didn't flip a switch. First we found the big-offender faulty doors and got them fixed. Then we built rules around a tiered door-priority structure. Still short, so we dug into the leftover volume and found most of it came from doors with no cameras and alarms nobody could verify. Were they going to dispatch a guard hundreds of times for events they couldn't see? Probably not. So they used pre-determined rules around their access control to automatically resolve alarms that weren’t real. And when they did that, with AI resolving more than 40% of that, operators now see fewer than 100.
Implementation tends to surface problems that ignoring them has buried for years. One customer with 1,100+ monitored doors found roughly 14% of their weekly incident volume, close to 1,900 incidents, were created by misconfigured rules in their hardware. At another site, a GSOC analysis found 67% of door-forced and door-held alarms were false, most traceable to a handful of doors with bad hardware or configuration.
Neither of those numbers came from a person combing through logs. They came from AI sitting across the full history of every door, every rule, every setting, and surfacing the pattern that a human reviewing incidents one at a time would never catch. That's the actual role AI plays in getting a program like this under control: not answering the alarm, but showing you where the noise is really coming from so you can fix the cause instead of triaging the symptom. It's the same move as the 2,500-incident customer above, point AI at the volume, let it tell you what's broken, then go fix it.
The concerns buyers raise about AI deserve straight answers. Data privacy is the big one, and it's solvable. It's why we host AI models inside the customer's cloud instance, so nothing leaves to a third party. The fear of AI replacing people deserves honesty too: the point is to improve the human’s work experience by getting operators off mundane work, not out the door. Humans are still very much needed in any physical security process to actually respond to what is real.
What I won't indulge is the tired line that, "AI doesn't work." The technology moved past that. Trust is the limit now, not capability, and the benchmark shows it: 75% of mature programs already use AI, against 43% of less mature ones.
Most organizations already believe AI matters, so the next phase is about who moves from pilot to production first. The companies that pull ahead won't spend more on AI, they'll spend less time evaluating it and more time putting it to work.

Ryan Schonfeld is the Co-Founder & CEO of HiveWatch.



Weekly insights from the people shaping the future of technology.
Insights from leading voices in technology
Latest video podcasts
Quick takes
Insightful articles on tech trends




Whether you’re a reader, contributor, or tech enthusiast, we’d love to hear from you. Use the form below to send us a message — we’ll get back to you as soon as we can.