The Way Security Teams Research Tools Just Changed. The Data Is Striking.

A new report from G2 landed this week with a number that should stop security teams in their tracks.
51% of B2B software buyers now start their research with an AI chatbot — not Google, not a peer recommendation, not a review site. An AI chatbot. Seven months ago that figure was 29%. That's a near-doubling in less than a year, and there's no sign it's slowing down. If you work in security and you're responsible for evaluating or recommending tools, this shift is already affecting how your team researches. The question worth asking is whether the way you're using AI for that research is actually making you more accurate — or just more confident in potentially wrong answers.
Why security buyers face a different problem
Software buying decisions are rarely low-stakes. But security tool decisions carry a particular kind of weight. Choose the wrong project management tool and you waste money and a few months of friction. Choose the wrong EDR for a FedRAMP-regulated environment and you fail an audit. Choose the wrong SIEM without accounting for your analyst-to-alert ratio and you're drowning in noise within 90 days. The specificity of those requirements matters enormously. And that's where AI-assisted research starts to show its limits.
AI chatbots are genuinely good at certain things: giving you a shortlist of well-known tools in a category, explaining what a technology does, summarising how two products differ at a surface level. What they're not good at — yet — is knowing that you have 3,000 AWS endpoints, no dedicated security engineer, a FedRAMP Authorized requirement, and a 60-day evaluation window. The gap between "here are the top five SOAR platforms" and "here are the two SOAR platforms worth evaluating given your specific situation" is where most AI-assisted research falls short.
G2's data makes this tension concrete: 69% of buyers ended up choosing a different product than they originally planned based on AI guidance. That's not necessarily bad — being redirected toward a better fit is the whole point. But it raises a question every security team should sit with: redirected toward what, exactly? And validated against which requirements?
The generic shortlist problem
Here's how most AI-assisted security research actually plays out. A security architect is tasked with evaluating identity and access management tools. They open ChatGPT and ask for the top IAM platforms for mid-market companies. They get a list: Okta, Microsoft Entra, Ping Identity, CyberArk, JumpCloud. The list is reasonable. It's also completely context-free. It doesn't know whether they're a Microsoft shop or AWS-native. It doesn't know whether they need SCIM provisioning, PAM capabilities, or just SSO with MFA. It doesn't know their compliance framework, their budget, or whether they have the engineering bandwidth to configure a complex deployment. The result is a shortlist that feels authoritative — 83% of buyers in the G2 report said they felt more confident in their final decision after AI-assisted research — but may be built on criteria that have nothing to do with the buyer's actual situation. Confidence and accuracy are not the same thing. In security, that distinction matters.
Where AI-assisted research is genuinely valuable for security teams
To be clear: the shift to AI-first research isn't a problem to be solved. It's a capability to be used well. And there are places where it's genuinely moving the needle for security buyers. Discovery is one of them. One in three buyers in the G2 report purchased from a company they had never heard of before. In security, where new tooling categories emerge constantly and interesting challengers appear well before they have enterprise marketing budgets, this matters. A security team that only evaluates the tools their existing contacts recommend is going to miss a lot. AI-assisted discovery — asking what's interesting in a category, what new approaches have emerged, what the challengers to an incumbent look like — is a legitimate alpha source, provided you validate what you find. Speed is another. Four out of five buyers said AI helped accelerate their purchasing decision. For security teams operating under resource pressure, getting to a credible shortlist faster is real value. The risk is mistaking speed for accuracy — getting to the wrong answer faster is not progress.
What good AI-assisted security research actually looks like
The buyers getting genuine value from AI-assisted research are using it at the right stages. They're using it for initial category orientation and discovery. They're then moving to requirements-grounded evaluation — which means specifying their actual constraints (stack, compliance framework, team capacity, deployment model) before applying AI to the shortlist. And they're treating AI output as a starting point, not a verdict. The problem isn't using AI to research security tools. The problem is treating a generic AI recommendation as a brief. A brief has your requirements in it. A generic AI answer doesn't.
The broader signal
There's something bigger in this data beyond the buying behaviour shift. The G2 report calls it the Answer Economy — the idea that the unit of value in search is no longer a list of links but a direct answer. For security buyers, that means the quality of information available to you before you ever talk to anyone is improving rapidly. The research layer is getting better. What hasn't kept pace is the evaluation layer — the structured process of taking that initial research and validating it against what your organisation actually needs. That's the gap worth closing. The 51% figure isn't a warning. It's a description of where your peers already are. The question is whether the AI-assisted research they're doing — and that you're doing — is grounded in the specifics that make a security tool decision right or wrong for your environment. Generic answers are getting easier to come by. Defensible decisions still take more than that.
Picari helps security teams go from brief to defensible shortlist — requirements grounded, independent of any company on the list.
Not sure where to start?
Brief your scenario and we'll show you which vendors fit, in under 2 minutes.