For two years the AI security conversation was about tools nobody approved. Employees pasting customer data into a chat window, teams expensing a subscription, whole functions running on software the security team had never seen. That was shadow AI, and it was a discovery problem. You could not control what you could not find, so the work was finding it.
Something different is now on top of the pile, and the change happened fast enough to see inside a single month of our data.
The two problems are not the same shape
Shadow AI is unsanctioned software. The security question is "what is running here that we did not approve?" The controls that answer it are discovery controls: network and SaaS visibility, expense analysis, browser and endpoint telemetry, data loss prevention at the egress point. Once found, the response is binary. Block it, or bring it inside the perimeter and govern it.
Agent risk is sanctioned software. Nobody is hiding it. Somebody bought it, security may well have reviewed it, and it is running with credentials that were deliberately issued. The question is not "what is running?" It is "what is this thing allowed to touch, under whose identity, and who can take that away?"
That is an authorization problem, and authorization controls are a different stack: identity governance, scoped service accounts, short-lived credentials, permission review, and an inventory that maps each agent to an owner and a revocation path. Discovery tooling will tell you the agent exists. It will not tell you that the agent holds a token with standing access to a finance system because somebody granted it during a pilot and never narrowed it.
What the data shows about the handover
Our September CISO AI Leverage Report runs an instrument on senior security leaders at Open Future Forum security rooms. On the full base of 110, securing AI agents and their access is the biggest AI security problem for 67 percent. Data leaking into AI models is named by 29 percent, shadow AI by 25, and attacks that use AI against the company by 16.
The cohort comparison is where the movement shows. Splitting the base into the 54 who applied through July and the 56 who applied in August:
| Named problem | Through July | August |
|---|---|---|
| Securing AI agents and their access | 61% | 73% |
| Data leaking into AI models | 20% | 38% |
| Shadow AI | 28% | 23% |
| Attacks that use AI against us | 13% | 20% |
| Nothing urgent yet | 7% | 4% |
Two things are worth separating here. Shadow AI declining does not mean shadow AI is solved. It means it is being named first by fewer people, which is what happens when something moves from a crisis to a managed condition. The steep rise in data leakage is the more interesting number, because data leakage is the failure mode that connects the two problems. Whether the model receiving the data was approved or not is a governance question. The data has left either way.
Read as a group, agents and data leakage together are named by more than twice the share that names adversary attacks. Security leaders in these rooms are telling us their AI problem is currently a governance problem rather than an adversary problem.
What transfers and what does not
Transfers. Data loss prevention at the egress point still matters, because an agent moving data out looks similar to a person moving data out. Vendor review still matters. Logging still matters, though the useful log line changes from "who accessed this" to "which agent accessed this on whose behalf".
Does not transfer. Blocking. You cannot block a system the business has approved and is depending on, which removes the primary response that made shadow AI tractable. Discovery scanning is also of limited use, because the agent is not hiding.
New, and usually missing. An inventory that lists every agent in production with its credentials, its data scope, its human owner and its revocation path. Permission scoping at issue rather than at review. And a standing answer to the question of what happens when an agent acts wrongly and a customer is harmed.
The gap between the last item and current practice is the one I would watch. Discovery was a security team activity. Authorization is a joint activity with whoever operates the agent, and most companies have not built that working relationship.
The money has not moved
The uncomfortable finding is the funding. On the full base of 110, 37 percent of security teams hold a dedicated AI security budget line, 36 percent fund it case by case, 22 percent carve it from the existing security budget, and 11 percent have no AI security spend at all.
We call the distance between naming agent access as the top problem and holding a budget line for it the Security Funding Gap. It is 30 points on the full base and 32 in the August cohort. The line is growing, from 33 percent in the cohort through July to 41 percent in August, but the problem grew faster.
The gap is widest at the chair that owns the problem. Cut to security-seat respondents only, agent access is named at 69 percent while 24 percent hold a dedicated line and 48 percent fund case by case, a distance of 45 points on a base of 29. That base is small and directional, and I would not build a strategy on it. But it is consistent with what security leaders describe in the rooms: the CISO is often arguing for agent governance money one purchase at a time, against a problem they have already named as their largest.
What to do about it this quarter
Four things, in order of how quickly they can be done.
Inventory before policy. Write down every agent in production, its credentials, its data scope and its human owner. Most teams discover during this exercise that the count is higher than expected and that several agents have no named owner.
Scope at issue. New agents get least-privilege credentials with an expiry from the start. Retrofitting scope onto a running agent is a project. Issuing it correctly costs nothing.
Ask the AI leaders. The technology seat in our security rooms names agent access at 76 percent, higher than any other chair. Whatever the reporting line, that seat sees the exposure first and is worth consulting before the policy is written rather than after.
Move funding off case by case. A third of teams are funding the largest problem on their desk one argument at a time. The case for a line item is easier to make now, while the problem is rising, than it will be after an incident.
Limitations
The most important caveat is what this instrument does not touch. It records nothing about incidents, breaches or losses. It records what senior security leaders name as the largest AI problem on their desk and how that work is paid for, which is a measure of attention and funding rather than of harm.
The cohort comparison is one month against the previous period, on bases of 54 and 56. Two points of comparison make a direction, not a trend, and I would not extrapolate the line. The security-seat cut sits on 29 responses, below our 40-response floor, so the 45-point gap at that chair is indicative only. Respondents applied to AI-focused security sessions between March and August 2026, so they are ahead of the average team. Multiple answers were allowed throughout, which is why the shares exceed 100 percent.
Where security leaders compare notes
Open Future Forum runs CISO dinners and security roundtables where this is the standing subject, and the rooms approve roughly a quarter of applicants. The September CISO AI Leverage Report carries the full instrument with bases on every figure, and the event calendar is here.
Last updated: September 8, 2026
Frequently Asked Questions
Join a CISO Roundtable
Open Future Forum runs CISO dinners and security roundtables where agent governance is the standing subject. The rooms approve roughly a quarter of applicants.