Securing AI agents and their access is now the top AI security problem for CISOs. In Open Future Forum's first-party research, 62 percent of security leaders name it first, ahead of data leakage at 31 percent and shadow AI at 23 percent. Most are handling it without dedicated money: 69 percent lack an AI security budget line.

Why agents became the top security problem

Agents changed the shape of the problem. A chatbot leaks data; an agent takes actions: it holds credentials, calls tools, touches production systems and does so at machine speed and scale. Security leaders can reason about that concretely, which is why the concern shows up consistently across separate samples: in the CISO AI Market Map's broader buyer data, 55 percent of respondents flagged securing AI agents and their access as the biggest AI security problem, the largest single answer by a wide margin and the same top concern the security-leader sample put at 62 percent.

A chatbot leaks data. An agent takes actions: it holds credentials, calls tools and touches production systems at machine speed.

Agent identity and access: the working agenda

The practical agenda emerging in CISO rooms treats agents as a new identity class. That means scoped permissions rather than inherited human credentials, distinct non-human identities per agent, audit trails for every action, data access boundaries enforced at the tool layer, and revocation paths that work at agent speed. The distinction between human and agent credentials is becoming the organizing question: an agent operating under a person's login inherits everything that person can do, which is exactly the failure mode security teams are moving to eliminate. Vendor coverage for this is mapped in the market map's identity, access and non-human identity category, one of eight security categories across 63 vendors.

Who pays for agent security

The money has not caught up with the concern. Among security leaders in the CISO AI Leverage Report sample, 69 percent lack a dedicated AI security budget line. In the broader market map data, only about a third of buyers have a dedicated AI security budget line; the rest split between case-by-case purchases, carve-outs from existing security budgets, and no AI security spend at all. Meanwhile the agentic AI security market is forecast to grow from 1.65 billion dollars in 2026 to 13.52 billion by 2032, while security budgets grew only 4 percent in 2025, the slowest rate in five years, and security's share of IT spend slipped from 11.9 to 10.9 percent. That divergence is the defining CISO budget story of 2026.

The seat gap: agents arrive without the CISO

Agents are entering companies through purchases the CISO never sees. Zero of 92 AI founders surveyed named security or the CISO as their buyer; founders target CIOs and CTOs (43 percent) and business units (38 percent), while CEOs sign off on 47 percent of AI purchases. The result is a governance problem by construction: the executive accountable for agent risk is not in the transaction that creates it. The CISOs handling this well are inserting lightweight review into procurement rather than trying to slow the purchases down.

Governance and board reporting

Boards are asking about AI risk in general terms; CISOs are learning to answer in agent terms. The reporting pattern that works: how many agents run in production, what identities and permissions they hold, what data they can reach, what happened in the last incident or test, and what the dedicated budget is. Given that 89 percent of security teams report being stretched thin or understaffed, the honest version of that report also names what is not covered. Governance frameworks are settling around the same primitives as the technical agenda: identity, permission scope, auditability and revocation.

Where CISOs compare notes

These findings come from invitation-screened security dinners and registration instruments across Open Future Forum events, published in the CISO AI Leverage Report and CISO AI Market Map. The same conversations continue off the record inside the CISO Executive Forum, whose roundtable dinners center on AI security, data governance and responsible AI. If you hold the security seat, the next edition's answers are being argued out over those dinners right now.

Last updated: August 12, 2026

Murray Newlands
Murray Newlands
Founder, Open Future Forum

Murray Newlands has been building executive communities in Silicon Valley since 2019. Open Future Forum hosts private dinners and events for C-suite leaders and board directors navigating the AI era, grounded in a give-first philosophy.

Frequently Asked Questions

What is the biggest AI security problem for CISOs?
Securing AI agents and their access. In Open Future Forum's research, 62 percent of security leaders name it their top AI security problem, ahead of data leakage at 31 percent and shadow AI at 23 percent. Agents hold credentials and take actions, which makes them a different risk class than chatbots.
Do companies have AI security budgets?
Mostly not yet. 69 percent of security leaders lack a dedicated AI security budget line. In broader buyer data, only about a third have a dedicated line; the rest fund case by case, carve from existing security budgets, or have no AI security spend at all.
How should companies govern AI agents?
Treat agents as a distinct identity class: scoped permissions instead of inherited human credentials, a non-human identity per agent, audit trails for every action, enforced data boundaries and fast revocation. Report to the board in those terms: agents in production, permissions held, data reachable, incidents and budget.
Why do AI agents reach companies without security review?
Because the CISO is rarely in the transaction. Zero of 92 AI founders surveyed named security as their buyer; they sell to CIOs, CTOs and business units, and CEOs sign off on 47 percent of AI purchases. Lightweight security review inside procurement closes the gap better than blocking purchases.
CISO Research

Read the Research, Then Join the Room

The CISO AI Leverage Report and CISO AI Market Map are built on first-party data from security leaders at Open Future Forum events.