While there are indications that security leaders are being asked to secure AI adoption without added funding, greater clarity on the need for AI protections could lead to increased budget next year, GuidePoint Security’s Gary Brickhouse tells CRN.
CISOs looking for a boost in budget to help secure the surging adoption of AI around their organizations could begin to see a much-needed spending increase starting next year, according to GuidePoint Security’s Gary Brickhouse.
The reality is that while many organizations may not yet be providing more funding to protect AI usage—which itself is supposed to reduce costs in many cases—clarity on the massive need for AI security could be coming, said Brickhouse, CISO at Herndon, Va.-based GuidePoint, No. 32 on CRN’s Solution Provider 500 for 2026.
[Related: Cyderes CEO: ‘Not One’ CISO Has Disclosed Getting More Budget To Secure AI]
In some cases, executives may first want to get a handle on how their business can use the new AI tools, along with gaining a better sense of the return on investment the technologies can deliver, he told CRN.
Thus, for now, many security teams are focused on allocating budget for preventing the most catastrophic outcomes, as their organizations work through the broader questions around the use of AI, Brickhouse said.
“I think as that solidifies, that’s where you’re going to see the security start to firm up around [AI],” he said.
At present, to use a football analogy, security practitioners are playing more of a prevent defense that is designed mainly to stop major harm, Brickhouse said.
As a security team in this type of scenario, “I don’t have all the controls in place. I’m just trying to stop the really bad thing from happening,” he said.
“But as the organization gets better clarity on how they’re going to use AI, then security can come alongside of it and tighten in around that,” Brickhouse said. “And I think that’s where you’ll see that budget increase—in more of a 2027 [time frame].”
Indications that many organizations are not seeing the expected AI security budget increases have surfaced in conversations over recent months with many CISOs, according to Chris Schueler, CEO of Kansas City, Mo.-based Cyderes, a major MSSP and No. 124 on CRN’s Solution Provider 500 for 2026.
In an interview for the latest episode of CRN’s Security or Else! video series, Schueler discussed the challenges around funding of AI security and why it may translate to massive cyber risk for many organizations.
“In the last three months, the one question I ask every single CISO [is], ‘What budget have you gotten to secure AI?’” he said. “Not one CISO—not one—has told me they’ve gotten any incremental budget to secure AI. Not one. That to me is the biggest, scariest thing that I’ve ever seen.”
Many CISOs and other cybersecurity leaders are therefore being asked to somehow fund the added protections that are required from existing budget allocations, Schueler said.
The message seems to be “take your same budget and your same controls, and either fund it because you see the risk—fund it with your existing budget—or just put blinders on and be a voice in the room to say, ‘It’s only a matter of time,’” he said. “That’s going to be a problem.”
Without a doubt, a key part of the challenge is that many executives are still in the midst of assessing the business case for AI adoption, according to GuidePoint’s Brickhouse.
“I think CEOs are going to start asking harder questions about ROI before they start asking about security,” he said. “They’re still trying to figure out, ‘Is this a sustainable model? Can we do this?’”
Yet, in all likelihood, “there’s going to be a reconciliation of some sort heading into ’27,” Brickhouse said.





