Skip to main content
CybersecurityVulnerability Management

Sysadmins' AI Expectations Unmet as Adoption Lags

Sysadmin scrutinizes laptop screen in cluttered data center workstation.

“Sysadmins are comfortable using AI to analyze information, reduce noise and recommend actions, but they understand that an incorrect decision affecting production systems, vulnerabilities or access controls can have serious consequences,” said Gene Moody, field CTO at Action1.

Patch management, CPU/memory monitoring, and vulnerability prioritization: stark shortfalls

The Action1 2026 Survey Report: AI Impact on Sysadmins, published July 30 and based on a poll of more than 1,000 sysadmins worldwide, shows that expectations set in 2024 have not matched the operational reality in 2026. In nearly every category the field predicted wide automation — and did not get it.

  • Patch management optimization: 67% predicted full automation by 2026; only 16% report implementation today.
  • Server CPU and memory monitoring: 70% predicted automation; 20% implemented.
  • Vulnerability prioritization: 66% predicted automation; 17% implemented.
  • Incident detection and remediation: 67% predicted automation; 19% implemented.
  • Compliance analysis: 62% predicted automation; 28% implemented.
  • Log analysis: 83% predicted automation; 50% implemented.

Those mismatches frame a practical picture: optimistic forecasts for broad, hands-off automation have been scaled back by operators tasked with keeping production systems reliable.

Gene Moody and the emerging model of supervised AI

Action1’s field CTO framed the prevailing approach as selective and supervised rather than fully autonomous. “The emerging model is supervised AI, with experienced administrators retaining authority over high-impact decisions,” he said, summarizing the posture sysadmins report adopting as they gain firsthand experience with the technology’s limits.

That language echoes the pattern seen across the adoption numbers: tools that augment diagnosis or recommend actions are more acceptable than those authorized to act without human oversight.

Troubleshooting, mandates, and rising AI literacy

Not every metric moved backward. Nearly half of sysadmins — 47% — now say they use AI for troubleshooting, though “use” is primarily in the form of hypotheses and recommendations rather than autonomous fixes. The figure had been expected to reach 52% in 2024, so the gap is narrower for this lower-risk, investigative use case.

Mandates and familiarity, meanwhile, are climbing. Action1 reports that organizations requiring AI use more than doubled, from 15% in 2023 to 34% in 2026. Separately, 58% of sysadmins now say they understand how to integrate AI into workflows, up from 24% in 2023 — a jump that signals real investments in skills and process changes even as full automation remains elusive.

Privacy, accuracy and loss of control: the top barriers

Where adoption has stalled, concerns explain much of the hesitation. Action1’s respondents named privacy and accuracy as the leading worries at 74%, followed by loss of control at 58% and cost at 55%. Worries about job replacement were reported by 24% of sysadmins.

Those percentages align with the cautious posture Moody described: sysadmins are open to AI-generated analysis and noise reduction, but are reluctant to cede authority where mistakes could affect production, vulnerabilities, or access controls.

What this means for technologists, procurement leaders, and end users

  • Technologists and security teams will likely continue to adopt supervised AI for analysis and recommendations rather than full automation, using tools to reduce noise and form hypotheses while preserving human decision authority.
  • Procurement leaders will see the practical tension between rising mandates — 15% to 34% from 2023 to 2026 — and the slow uptake of high-risk automations; decisions about investments will weigh literacy gains (58% now feel able to integrate AI) against persistent concerns about privacy, accuracy, control and cost.
  • End users and customers can expect incremental improvements in troubleshooting and incident triage, but should not assume widespread autonomous remediation of patches, vulnerabilities or compliance tasks in short order.

Two years after sysadmins predicted a sweeping transformation, the record shows selective implementation and a strong human-in-the-loop posture. The Action1 numbers illustrate both a pivot and a pause: organizations are learning how to integrate AI, and mandates and familiarity are rising — yet the most consequential automations remain limited. The key question the survey leaves in plain sight is whether supervised AI, growing familiarity, and organizational mandates will close the gap between prediction and practice, or whether the caution reflected in these figures will harden into a long-term operating model.

Source: Action1 2026 Survey Report: AI Impact on Sysadmins (Infosecurity Magazine)