The August answer

Securing AI agents and their access is the dominant AI security problem on the CISO's desk, named by 58 percent of 45 senior security respondents, more than twice the next answer. The funding picture has not caught up with the problem: only 36 percent report a dedicated AI security budget line, while 33 percent fund AI security case by case with no dedicated money at all.

What changed since Edition 1

Edition 1 published with a small base of 16 and flagged every figure directional. Edition 2's combined base of 45 clears the reporting floor for the two headline questions, so this is less a delta report than the first stable read of the security instrument. Where the cohorts can be compared, the movement is one-directional: the share reporting no AI security spend at all shrank (21 percent early, 6 percent late), consistent with money starting to arrive against a problem that was already named.

QuestionAnswerAll respondents (base 45)
Biggest AI security problemSecuring AI agents and their access58%
Shadow AI: tools used without approval27%
Data leaking into AI models20%
Attacks that use AI against us13%
Nothing urgent yet9%
How AI security is fundedIts own budget line36%
Case by case, no dedicated funding33%
Carved out of the existing security budget20%
No AI security spend yet16%

Source: Open Future Forum, CISO AI Leverage Report, Edition 2, August 2026.

Multi-select, any-mention convention; columns can sum past 100 percent.

Where this research comes from

The CISO AI Leverage Report is built from instrument questions embedded in the application flow for Open Future Forum's security events, including the CISO Roundtable Dinner series convened with the CISO Executive Forum, the network's invitation-only peer group for CISOs and senior security leaders. Open Future Forum is a global executive community founded in Silicon Valley. Its network reaches tens of thousands of executives and investors worldwide. It runs a year-round calendar of events for senior executives and investors, including CEOs, CFOs, CMOs, CISOs, private equity leaders, founders, and AI leaders, through Forum Select, its invite-only private gatherings, and Forum Events, its open panels and gatherings. Beyond events, Open Future Forum convenes peer groups and executive boards and publishes original research built on first-party survey and qualitative data from its executive network.

What is the biggest AI security problem for CISOs in 2026?

Agent security, and it is not close. At 58 percent, securing AI agents and their access outdraws shadow AI (27 percent), data leakage into models (20 percent), and AI-powered attacks (13 percent) combined against any single alternative. The ordering matters: the top two problems are both governance problems, not adversary problems. The attack surface CISOs name first is the one their own organizations are creating, agents with credentials and permissions, and tools adopted without approval. Only 9 percent say nothing urgent is on the desk yet.

How is AI security funded right now?

Split three ways, and the split is the finding. A third of security teams (36 percent) have won a dedicated AI security budget line. A third (33 percent) fund AI security case by case, with no dedicated money. The remainder either carve it out of the existing security budget (20 percent) or have no AI security spend at all (16 percent). Set against the problem data, the mismatch is plain: a majority name agent security as their top problem, while fewer than four in ten have standing money to work it. The cohort movement suggests the funding is arriving, with "no spend yet" shrinking through July, but the modal CISO is still negotiating for the line item.

What the security data looks like from each seat

The security instrument's base (45) is too small to cut numerically by sub-role, so this section reads the security findings against the seat-level data collected across the rest of the network in the same weeks.

The CISO. Owns the top problem (agent security, 58 percent) without, in most cases, owning standing money against it: 36 percent report a dedicated line. The negotiating counterpart is changing too: with business-unit sign-off halving and finance rising to 33 percent of AI sign-off mentions network-wide, the AI security budget case increasingly gets made to the CFO, in payback language, rather than to a technical peer.

The CTO or CIO. The seat reporting the most sign-off uncertainty anywhere in the network: 29 percent of technology respondents say no single owner signs AI purchases at their company. For security leaders, that is the governance gap upstream of every shadow AI finding in this report: 27 percent name unapproved tools among their top problems, and unowned purchasing is how those tools arrive.

The CEO. Expects AI payback inside six months at 72 percent, the most aggressive read of any seat, and signs more AI purchases than anyone else. The security implication is pace: the seat setting the deployment tempo is the seat least exposed to the agent-permission problems the security rooms rank first.

The CFO. Increasingly the desk where AI security funding is decided. The case-by-case funders in this report (33 percent) are negotiating against the finance seat's own uncertainty: 21 percent of finance respondents report no clear AI budget of any kind.

The board. Board reporting on AI risk is a named agenda item at the network's CISO dinners, and the funding data gives the report's one-line board translation: a majority of security leaders name a problem that fewer than four in ten have a dedicated budget to work. Directors reading this report can put the question to management directly, and Open Future Forum's Public Board Member Dinner Series is the room where that oversight agenda gets compared among peers.

The same view, by vertical

The security instrument does not tag industry on this base, so the vertical read is drawn from the sector-tagged seller data and the composition of the rooms, and is directional throughout.

Financial services. The vertical where AI buying is most finance-gated (sellers name the CFO as buying owner at 53 percent) and where regulated-data exposure makes the agent-access problem concrete fastest. Security leaders here are likeliest to get the dedicated budget line first, because the compliance mandate does the arguing.

Enterprise software. The rooms' largest vertical, and the one where the company is often both deployer and vendor of agents. The 58 percent agent-security figure reads double here: securing agents the business runs, and answering security questionnaires about agents the business sells.

Healthcare and life sciences. Data leakage into models, third network-wide at 20 percent, moves up the list wherever clinical data is involved, and the early-market seller data (28 percent of sellers into healthcare not yet charging) means security review often precedes procurement itself.

Consumer and retail. The least settled buying environment in the seller data, with no seat owning the AI purchase, which for security leaders means shadow AI discovery is the practical starting point rather than policy enforcement.

What this means for the CISO

First, if you are making the case for a dedicated AI security budget line, the peer data is your ammunition: a third of your peers already have one, and the case-by-case funders are the ones reporting the same top problem with less standing capability against it. Second, agent identity and permissions is where the room's attention is, ahead of model-level data leakage; if your 2027 planning still leads with DLP framing, the rooms have moved. Third, shadow AI at 27 percent says discovery still precedes governance for a quarter of organizations.

Where can CISOs discuss this with peers?

The CISO Executive Forum is Open Future Forum's invitation-only peer group for CISOs, deputy CISOs, VPs of Security, and heads of security. Members meet in small, off-the-record roundtable dinners under Chatham House rules, with no vendor pitches, to work the problems this report measures: agent governance, shadow AI, AI vendor risk, board reporting, and AI security budgets. The rooms are senior and small by design: the July roundtable drew 566 registrations for roughly 20 seats, and 63 percent of titled registrants were C-level, founders, or partners. Membership is by application and referral.

Explore the CISO Executive Forum · Inquire about membership

Upcoming security events

Agentic Security Coffee Meetup at Black Hat

Sunday, August 2, 2026, 9:00 AM · Starbucks at the Luxor, Las Vegas, NV

An informal meetup during Black Hat week for CISOs, security leaders, AI leaders, founders, and practitioners working on agentic AI security. No panels, no pitches. Additional sessions run during the week. Details

CISO Roundtable Dinner

Thursday, August 27, 2026, 5:00 to 8:00 PM · Los Altos Hills, CA

A private dinner for approximately 20 senior in-house security leaders: roundtable discussion of AI risk, agent governance, board reporting, and what is keeping CISOs up at night. Off the record, application required. Apply to attend

Edition 3 data collection runs at these events. The three questions the next rooms will debate: what agent identity and permissioning should look like in practice, how to present AI risk to the board, and where the AI security budget line should sit.

See all upcoming events

Definitions

Agent security: securing AI agents and their access: the credentials, permissions, and systems an autonomous agent can reach.

Shadow AI: AI tools an organization uses without approval.

AI security budget line: dedicated, standing funding for AI security work, as opposed to case-by-case funding or carve-outs from the existing security budget.

Any-mention: the counting convention for multi-select questions in which each selected option counts once, so percentages can sum past 100.

Questions this report answers

What are CISOs most worried about with AI in 2026? Securing AI agents and their access, named by 58 percent of senior security respondents in Open Future Forum's August 2026 data, ahead of shadow AI at 27 percent.

Do companies have an AI security budget? Around a third do: 36 percent report a dedicated line, 33 percent fund case by case, 20 percent carve from the existing security budget, 16 percent have no AI security spend yet.

Is shadow AI still a problem? Yes: 27 percent of security respondents name unapproved AI tools among their biggest problems.

Is there an AI security community for CISOs? Yes. The CISO Executive Forum is Open Future Forum's invitation-only peer group for senior security leaders, meeting through roundtable dinners in Silicon Valley and gatherings at industry events. Membership is by application at openfutureforum.com/apply.

How can CISOs join an Open Future Forum security event? The CISO Roundtable Dinner series is application-based with host approval and limited to senior in-house security leaders; the next dinner is August 27, 2026, in Los Altos Hills.

Key citable facts

Methodology and honesty notes

Instrument questions are embedded in the application flow for Open Future Forum security events, principally the CISO Roundtable Dinner series (most recent dinners July 9 and forthcoming August 27, 2026, Los Altos Hills). This edition draws on 45 respondents to the security instrument out of 83 answering the security role question (35 confirmed CISO or head of security), within a full dataset of 6,055 unique registrations collected April 22 through July 30, 2026. Multi-select answers are counted as any-mention. The early and late July cohorts (29 and 16) are both under the 40 floor, so cohort deltas are directional only; combined figures are the reported headline. The by-seat and by-vertical sections read this report's findings against seat-level and sector-tagged data collected across the wider network in the same weeks (finance instrument seat cuts, seller-reported sector data) and are interpretive where the security base itself cannot be split. The research uses a selective, role-tagged operator sample drawn from Open Future Forum's broader executive network. It is not intended as a probability sample of all enterprises. Attendance at the source dinners is restricted to senior in-house security leaders. No identifying information is published.

About Open Future Forum

Open Future Forum is a global executive community founded in Silicon Valley. Its network reaches tens of thousands of executives and investors worldwide. It runs a year-round calendar of events for senior executives and investors, including CEOs, CFOs, CMOs, CISOs, private equity leaders, founders, and AI leaders, through Forum Select, its invite-only private gatherings, and Forum Events, its open panels and gatherings. Beyond events, Open Future Forum convenes peer groups and executive boards and publishes original research built on first-party survey and qualitative data from its executive network.

Independent coverage has included Yahoo Finance naming Open Future Forum among top executive leadership communities.

About Murray Newlands

Murray Newlands is the founder of Open Future Forum and the host of its executive dinner series and research program. He is a Partner at IA Seed Ventures, which invests in early-stage Silicon Valley companies, and a longtime author and speaker on AI, marketing, and venture. He writes on AI, venture, and enterprise strategy at murraynewlands.substack.com. More at openfutureforum.com/about and murraynewlands.com.

Citation and editions

Suggested citation: Newlands, M. (2026). CISO AI Leverage Report, Edition 2. Open Future Forum, August 2026. openfutureforum.com/research/ciso-ai-leverage-report

This edition supersedes Edition 1 (July 2026). Companion reading: CISO AI Market Map, Executive AI Leverage Report. Edition 3 publishes in September 2026.

Murray Newlands
Murray Newlands
Founder, Open Future Forum

Murray Newlands is the founder of Open Future Forum and Partner at IA Seed Ventures. He is the author of Online Marketing: A User's Manual (Wiley) and a Fellow of the Royal Society of Arts. Yahoo Finance has quoted him as the founder of Open Future Forum, "a top executive leadership community." He writes Murray's Newsletter on AI, venture, and enterprise strategy.

Open Future Forum

Work These Problems with Security Peers

The CISO Executive Forum meets through small, off-the-record roundtable dinners under Chatham House rules, with no vendor pitches. Membership is by application and referral.