TL;DR
Gallup’s May 2026 data says 65% of employees at organizations using AI report better personal productivity. Only 14% strongly agree AI has changed how work gets done. The 51 points in the title come from subtracting the second number from the first.
ISC2 found 65% of cybersecurity professionals surveyed are spending more time deciding whether to trust or act on AI recommendations, while 63% are spending more time checking the output.
AI can shorten the first part of the job without shortening the whole job. Review, ownership and human judgment can become the new delay.
People are reporting that AI makes them faster. The organizations around them seem to be changing much more slowly.
Gallup’s current workplace AI indicator puts numbers on that difference. Among employees at U.S. organizations that have implemented AI, 65% say it has had a positive effect on their productivity and efficiency. By comparison, 14% strongly agree AI has transformed how work gets done in their organization. That’s the 51-point spread I’m writing about: 65% minus 14%.
I’m doing that subtraction, not Gallup. The 51 points aren’t a formal Gallup metric, and the two questions use different response scales. So I wouldn’t treat 51 as some new productivity index. It’s a useful signal that the individual experience and the organizational experience may be moving at very different speeds.
Gallup’s Q2 numbers make that worth watching. Forty-seven percent of U.S. employees say their organization has integrated AI tools, up from 41% the previous quarter. Fifty-two percent say they use AI in their role at least occasionally, and 30% use it a few times a week or more.
People are using the tools. Now follow what happens to their work after the tool finishes.
Faster Worker, Same System
Take a security analyst using AI to cut a first-pass investigation from twenty minutes to five. Great. Then the recommendation waits for senior review. Maybe an application owner has to weigh in. Maybe somebody needs to approve a change or verify the evidence before anyone acts.
The analyst saved fifteen minutes. The incident may not have.
Security already knows this pattern. Add a lot more finding capacity without adding triage capacity and you don’t magically get fewer vulnerabilities. You can get a bigger queue. AI can create the same problem in ordinary workflows: more useful output arriving faster at the same people who were already responsible for checking it.
Gallup doesn’t measure that downstream effect. I’m making the connection. But Microsoft’s 2026 Work Trend Index gives us another reason to look there. Its global survey covered 20,000 AI users across 10 markets. Only 26% said leadership was clearly and consistently aligned on AI. Microsoft also found that organizational factors such as culture, manager support and talent practices accounted for 67% of the statistical association with reported AI impact, compared with 32% for individual factors such as mindset and behavior.
Microsoft is careful here, and we should be too. That’s an association, not proof of cause. But it points at something leaders can inspect inside their own companies. Someone can get very good at using AI while their work still passes through the same approvals, handoffs and decision rules it did two years ago.
The tool changed. The route didn’t.
Security Is Already Feeling It
ISC2 surveyed 856 cybersecurity professionals who use AI in their roles. Sixty-five percent said they were spending more time deciding when to trust or act on AI-generated recommendations. Sixty-three percent were spending more time reviewing or validating AI output.
That’s the part I care about.
AI can remove effort from one part of the job and put some of it back somewhere else. The work didn’t disappear. Some of it moved into deciding whether the answer is good enough to act on.
ISC2 also found that 48% were spending less time on tasks that don’t involve AI assistance. At the same time, half of respondents said human decision-makers bear final accountability when an AI-recommended action turns out to be wrong. Nearly a quarter said they’re often or very often expected to act on AI-generated security output without fully understanding how it was produced.
So the machine can produce the recommendation faster, while the person sitting behind it still owns the mistake.
That changes the job.
SANS saw something related in its July AI survey. AI use in cybersecurity rose from 50% to 78% in a year, yet only 27% of practitioners described their deployments as mature production. Seventy-six percent said security now has a governance role for enterprise AI. Sixty-three percent reported significant shortcomings in AI-assisted threat detection and response.
The tools arrived quickly. The rules for trusting them, checking them and deciding who owns the result are taking longer.
The Bottleneck Moved
Security teams have spent years automating the slow parts of the job. AI speeds up another chunk of it. But if the output still sits waiting for review, approval or someone willing to own the decision, you haven’t removed the delay. You’ve moved it.
An alert might be summarized in seconds and then wait an hour because nobody trusts the summary enough to close it. Or AI might rank a vulnerability instantly, only for the ticket to sit because the application owner isn’t clear. The machine has already finished. The work hasn’t.
That distinction matters because a lot of AI programs are still being measured at the tool. Seats. Usage. Prompts. Agents deployed.
Those numbers tell you whether people are using AI. They don’t tell you whether anything finishes sooner, let alone with accuracy.
If you want to know that, measure what happens after the output appears. How long until somebody checks it? How often does it get sent back? How often does a human reverse the recommendation? Most important, when does someone finally act?
If the first step went from twenty minutes to five and the final action still takes three hours, AI probably did what you asked it to do.
You found the next constraint.
Run Two Clocks
Pick one security workflow and run two clocks.
Stop the first when AI produces something a competent person considers useful. Stop the second when the organization actually does something with it.
The distance between those clocks is where I’d look next. Maybe the work is sitting with a reviewer. Maybe nobody knows who can approve it. Maybe the evidence isn’t strong enough yet. Whatever the reason, you can finally see where the time went.
Alert triage is an obvious place to try this because the start and finish are relatively easy to see. But the test works anywhere AI touches a workflow. Don’t ask only whether the analyst got faster. Ask whether the decision happened sooner and whether the result was still good.
I wouldn’t turn this into a staffing argument yet. Some tasks will genuinely require fewer human hours. Others may create more review because AI lets people produce plausible-looking work much faster than before. You have to measure the whole path before you know which one you have.
Gallup’s 51-point spread doesn’t prove organizations have failed to change. It tells us employees report a much bigger change in their own productivity than they report in how work gets done around them.
That difference is worth looking more deeply at.
If AI gives your analyst an answer in thirty seconds and your organization still needs three days to act on it, stop measuring the thirty seconds.
Follow the work downstream.
Resources
Gallup, Artificial Intelligence Indicator. May 2026 data: 65% positive self-reported productivity among employees at organizations that implemented AI, 14% strongly agree AI transformed how work gets done, plus survey methods and current adoption measures.
Gallup, Organizational AI Adoption Jumps Six Points, July 20, 2026. Reports organizational integration rising from 41% to 47% in Q2, 52% total workplace AI use and 30% frequent use.
Microsoft, 2026 Work Trend Index: Agents, Human Agency, and the Opportunity for Every Organization, May 5, 2026. Global survey of 20,000 AI users across 10 markets, including leadership alignment and the 67% vs. 32% organizational/individual association. Microsoft states the finding is associative, not causal.
ISC2, Rethinking AI’s Impact on Cybersecurity Roles, July 14, 2026. Survey of 856 cybersecurity professionals using AI, including changes in validation time, decision pressure and accountability.
SANS Institute, AI Use in Cybersecurity Jumped From 50% to 78% in a Year, July 13, 2026. Survey of 536 cybersecurity and IT practitioners plus a module of 57 senior security leaders, including maturity, governance and detection/response findings.
The queue and two-clock examples are my interpretation of the survey results. Gallup, Microsoft, ISC2 and SANS didn’t measure those exact workflow effects.

