For two years the AI security conversation was about tools nobody approved. Employees pasting customer data into a chat window, teams expensing a subscription, whole functions running on software the security team had never seen. That was shadow AI, and it was a discovery problem. You could not control what you could not find, so the work was finding it.

Something different is now on top of the pile, and the change happened fast enough to see inside a single month of our data.

The two problems are not the same shape

Shadow AI is unsanctioned software. The security question is "what is running here that we did not approve?" The controls that answer it are discovery controls: network and SaaS visibility, expense analysis, browser and endpoint telemetry, data loss prevention at the egress point. Once found, the response is binary. Block it, or bring it inside the perimeter and govern it.

Agent risk is sanctioned software. Nobody is hiding it. Somebody bought it, security may well have reviewed it, and it is running with credentials that were deliberately issued. The question is not "what is running?" It is "what is this thing allowed to touch, under whose identity, and who can take that away?"

That is an authorization problem, and authorization controls are a different stack: identity governance, scoped service accounts, short-lived credentials, permission review, and an inventory that maps each agent to an owner and a revocation path. Discovery tooling will tell you the agent exists. It will not tell you that the agent holds a token with standing access to a finance system because somebody granted it during a pilot and never narrowed it.

What the data shows about the handover

Our September CISO AI Leverage Report runs an instrument on senior security leaders at Open Future Forum security rooms. On the full base of 110, securing AI agents and their access is the biggest AI security problem for 67 percent. Data leaking into AI models is named by 29 percent, shadow AI by 25, and attacks that use AI against the company by 16.

The cohort comparison is where the movement shows. Splitting the base into the 54 who applied through July and the 56 who applied in August:

Named problemThrough JulyAugust
Securing AI agents and their access61%73%
Data leaking into AI models20%38%
Shadow AI28%23%
Attacks that use AI against us13%20%
Nothing urgent yet7%4%

Two things are worth separating here. Shadow AI declining does not mean shadow AI is solved. It means it is being named first by fewer people, which is what happens when something moves from a crisis to a managed condition. The steep rise in data leakage is the more interesting number, because data leakage is the failure mode that connects the two problems. Whether the model receiving the data was approved or not is a governance question. The data has left either way.

Read as a group, agents and data leakage together are named by more than twice the share that names adversary attacks. Security leaders in these rooms are telling us their AI problem is currently a governance problem rather than an adversary problem.

What transfers and what does not

Transfers. Data loss prevention at the egress point still matters, because an agent moving data out looks similar to a person moving data out. Vendor review still matters. Logging still matters, though the useful log line changes from "who accessed this" to "which agent accessed this on whose behalf".

Does not transfer. Blocking. You cannot block a system the business has approved and is depending on, which removes the primary response that made shadow AI tractable. Discovery scanning is also of limited use, because the agent is not hiding.

New, and usually missing. An inventory that lists every agent in production with its credentials, its data scope, its human owner and its revocation path. Permission scoping at issue rather than at review. And a standing answer to the question of what happens when an agent acts wrongly and a customer is harmed.

The gap between the last item and current practice is the one I would watch. Discovery was a security team activity. Authorization is a joint activity with whoever operates the agent, and most companies have not built that working relationship.

The money has not moved

The uncomfortable finding is the funding. On the full base of 110, 37 percent of security teams hold a dedicated AI security budget line, 36 percent fund it case by case, 22 percent carve it from the existing security budget, and 11 percent have no AI security spend at all.

We call the distance between naming agent access as the top problem and holding a budget line for it the Security Funding Gap. It is 30 points on the full base and 32 in the August cohort. The line is growing, from 33 percent in the cohort through July to 41 percent in August, but the problem grew faster.

The gap is widest at the chair that owns the problem. Cut to security-seat respondents only, agent access is named at 69 percent while 24 percent hold a dedicated line and 48 percent fund case by case, a distance of 45 points on a base of 29. That base is small and directional, and I would not build a strategy on it. But it is consistent with what security leaders describe in the rooms: the CISO is often arguing for agent governance money one purchase at a time, against a problem they have already named as their largest.

What to do about it this quarter

Four things, in order of how quickly they can be done.

Inventory before policy. Write down every agent in production, its credentials, its data scope and its human owner. Most teams discover during this exercise that the count is higher than expected and that several agents have no named owner.

Scope at issue. New agents get least-privilege credentials with an expiry from the start. Retrofitting scope onto a running agent is a project. Issuing it correctly costs nothing.

Ask the AI leaders. The technology seat in our security rooms names agent access at 76 percent, higher than any other chair. Whatever the reporting line, that seat sees the exposure first and is worth consulting before the policy is written rather than after.

Move funding off case by case. A third of teams are funding the largest problem on their desk one argument at a time. The case for a line item is easier to make now, while the problem is rising, than it will be after an incident.

Limitations

The most important caveat is what this instrument does not touch. It records nothing about incidents, breaches or losses. It records what senior security leaders name as the largest AI problem on their desk and how that work is paid for, which is a measure of attention and funding rather than of harm.

The cohort comparison is one month against the previous period, on bases of 54 and 56. Two points of comparison make a direction, not a trend, and I would not extrapolate the line. The security-seat cut sits on 29 responses, below our 40-response floor, so the 45-point gap at that chair is indicative only. Respondents applied to AI-focused security sessions between March and August 2026, so they are ahead of the average team. Multiple answers were allowed throughout, which is why the shares exceed 100 percent.

Where security leaders compare notes

Open Future Forum runs CISO dinners and security roundtables where this is the standing subject, and the rooms approve roughly a quarter of applicants. The September CISO AI Leverage Report carries the full instrument with bases on every figure, and the event calendar is here.

Last updated: September 8, 2026

Murray Newlands
Murray Newlands
Founder, Open Future Forum

Murray Newlands has been building executive communities in Silicon Valley since 2019. Open Future Forum hosts private dinners and events for C-suite leaders and board directors navigating the AI era, grounded in a give-first philosophy.

Frequently Asked Questions

Is shadow AI still a security problem in 2026?
Yes, but it is no longer the problem most named first. In our September data 25 percent name shadow AI on the full base of 110, and its share fell from 28 to 23 percent between the July and August cohorts while agent access rose from 61 to 73.
What is the difference between shadow AI and AI agent risk?
Shadow AI is unsanctioned software, which makes it a discovery problem with blocking as the response. Agent risk concerns approved systems holding issued credentials, which makes it an authorization problem where blocking is not available.
Do shadow AI controls work on AI agents?
Partly. Egress data loss prevention, vendor review and logging carry across. Discovery scanning and blocking largely do not, because the agent is neither hidden nor removable.
Do companies have AI security budgets in 2026?
37 percent of security teams hold a dedicated AI security budget line, 36 percent fund case by case, 22 percent carve it from the existing security budget, and 11 percent have no AI security spend, on a base of 110.
Which seat sees agent risk most clearly?
The technology seat in our security rooms names agent access at 76 percent, the highest of any chair, ahead of the security seat itself at 69 percent.
CISO Roundtable Dinner

Join a CISO Roundtable

Open Future Forum runs CISO dinners and security roundtables where agent governance is the standing subject. The rooms approve roughly a quarter of applicants.