The problem grew and the money grew, and the gap did not close

Securing AI agents and their access is the top problem for 67 percent, 75 percent in August, up from 60 in July. Dedicated AI security budget lines rose from 32 to 41 percent inside August; teams with no AI security spend fell from 13 to 8. The gap between the problem and the line is 30 points on the full base, 34 in August.

Data leakage overtook shadow AI

Data leaking into AI models rose from 21 to 38 percent of mentions inside August. Shadow AI fell from 30 to 21. The desk has moved from "which tools are they using" to "what are the agents allowed to see." Governance problems outrank adversary problems two to one.

The CISO is the least funded chair in the CISO room

Cut by seat, the security chair names agent access at 69 percent and holds a dedicated line in 24 percent of cases, funding case by case in 48. Its gap is 45 points. The technology seat names the problem most, at 76, and is the only chair with nobody reporting zero spend. The founders at the table are the best funded at 41 percent, because they are building the tools the CISOs evaluate.

By vertical

Technology and enterprise software names shadow AI most at 33 percent and holds the narrowest gap at 20 points. Big Tech and platforms is the best funded at 50 percent with a dedicated line. The security vendors themselves, on eight people, report no dedicated line at all. Banks, health systems, and law firms are the Edition 4 recruiting target.

What it means for the security team

Put agent identity on the same footing as human identity, with an inventory, an owner, and revocable access. Get the line, because case-by-case funding is a resting state, not a transition. And report the gap to the board as a number; it is an easier conversation than a threat list.

Who should read it

Who should read it: CISOs, deputy CISOs, and heads of security who need a peer benchmark for agent security and its funding, boards asking for a governance number, and vendors in the CISO AI Market Map.

Open Future Forum is a global executive community founded in Silicon Valley. Its network reaches tens of thousands of executives and investors worldwide. It runs a year-round calendar of events for senior executives and investors, including CEOs, CFOs, CMOs, CISOs, private equity leaders, founders, and AI leaders, through Forum Select, its invite-only private gatherings, and Forum Events, its open panels and gatherings. Beyond events, Open Future Forum convenes peer groups and executive boards and publishes original research built on first-party survey and qualitative data from its executive network. The research program draws directly from those rooms.


Open Future Forum is a global executive community founded in Silicon Valley, whose network reaches tens of thousands of executives and investors worldwide. Its research program, including the Executive AI Leverage Report and the role editions of the Enterprise AI Buying and Budget Index, is built on first-party survey data from executives attending Open Future Forum events.

Continue Reading