Security finding
In this sample, identity and access dominate the AI security agenda. Agent access leads the CISO instrument, 37 percent of applicable AI Leaders respondents use shared service accounts, and the dedicated-budget share is half the share naming the problem.
What October adds
The combined security base is 151. Agent access ranks first at 68 percent and the dedicated-line share is 34 percent, a difference of 34 points. The Microsoft data comes from a separate population and is not merged with the CISO instrument; it shows how production agents authenticate to enterprise data.
Where this research comes from
Three CISO Roundtable Dinner exports carry the same security problem and funding questions. The AI Leaders access-method question comes from Enterprise AI at Microsoft and is reported separately. Respondents are deduplicated by email for each question.
Security priorities
Agent access leads at 68 percent. Data leakage and shadow AI form a second tier at 29 and 28 percent. AI-enabled attacks sit at 19 percent. Seven percent report nothing urgent (base 151, any mention).
Respondents select agent access more than three times as often as AI-enabled attacks, which are named by 19 percent.
Funding approaches
Thirty-four percent report a dedicated line, 35 percent fund case by case, 26 percent carve the work out of the existing security budget and 11 percent report no AI security spend. Dedicated funding and case-by-case approval are almost equally common, while an existing-budget carve-out is also material.
The credential evidence
Among respondents for whom agent access is applicable, 49 percent use per-agent credentials, 37 percent shared service accounts, 8 percent delegated user identity and 6 percent credential-free or brokered access (base 49). Shared accounts make attribution, least-privilege enforcement and incident reconstruction harder.
October security evidence
Security priorities

AI security problems
| Answer | Count | Share |
|---|---|---|
| Securing AI agents and their access | 103 | 68% |
| Data leaking into AI models | 44 | 29% |
| Shadow AI | 42 | 28% |
| AI-enabled attacks | 29 | 19% |
| Nothing urgent yet | 10 | 7% |
Base 151; any mention, so shares can sum above 100 percent.
Agent access appears in 103 of 151 answers. Data leakage and shadow AI are close at 44 and 42 responses, while AI-enabled attacks appear in 29. The ranking puts non-human access at the center of how organizations govern agent data and actions.
Funding approaches

AI security funding
| Answer | Count | Share |
|---|---|---|
| Case by case | 53 | 35% |
| Dedicated AI security line | 52 | 34% |
| Existing security budget | 40 | 26% |
| No AI security spend | 16 | 11% |
Base 151; any mention, so shares can sum above 100 percent.
The dedicated-line share is 34 percent, half the 68 percent naming agent access. Case-by-case funding is slightly more common at 35 percent, and 26 percent carve money from an existing security budget. The difference between the problem and dedicated funding is 34 points.
| Respondent seat | Base | Dedicated line | Case by case | Existing budget | No spend |
|---|---|---|---|---|---|
| Security | 23 | 13% | 57% | 39% | 4% |
| Technology | 18 | 44% | 33% | 28% | 0% |
| CEO or founder | 56 | 36% | 29% | 23% | 16% |
| Other or unclassified | 46 | 39% | 33% | 28% | 9% |
Rows shown cover 143 of 151 respondents; omitted title categories total 8. Classification uses title keywords; security and technology rows are directional; any mention.
The title-classified cut shows a marked difference in funding models. Fifty-seven percent of security respondents report case-by-case funding, compared with 33 percent of technology respondents and 29 percent of CEO or founder respondents. The security and technology bases are directional. A dedicated line, case-by-case approval and an existing-budget carve-out do not provide the same planning certainty.
Priorities by respondent role
| Respondent seat | Base | Agent access | Data leakage | Shadow AI | AI-enabled attacks |
|---|---|---|---|---|---|
| Security | 23 | 78% | 35% | 35% | 22% |
| Technology | 18 | 72% | 39% | 17% | 22% |
| CEO or founder | 56 | 63% | 27% | 30% | 14% |
| Other or unclassified | 46 | 65% | 24% | 26% | 22% |
Rows shown cover 143 of 151 respondents; omitted title categories total 8. Classification uses title keywords; technology and security rows are directional; any mention.
The security seat names agent access in 78 percent of answers, compared with 72 percent of technology respondents and 63 percent of CEO or founder respondents. These are title-classified cuts, and the security and technology bases are directional. The concern nevertheless appears beyond the CISO role.
Credential evidence from production

Agent access method, all respondents
| Answer | Count | Share |
|---|---|---|
| Per-agent credentials | 24 | 34% |
| Shared service accounts | 18 | 25% |
| Delegated user identity | 4 | 6% |
| Credential-free or brokered access | 3 | 4% |
| Not applicable yet | 22 | 31% |
Base 71.
Agent access method, applicable respondents
| Answer | Count | Share |
|---|---|---|
| Per-agent credentials | 24 | 49% |
| Shared service accounts | 18 | 37% |
| Delegated user identity | 4 | 8% |
| Credential-free or brokered access | 3 | 6% |
Base 49.
Among the 49 applicable responses, per-agent credentials account for 49 percent and shared service accounts for 37 percent. Delegated identity and brokered access together reach 14 percent. The access-method and security-priority questions come from different populations; together, they identify a stated concern and an operating practice worth auditing.
External context
IBM's 2026 Cost of a Data Breach Report calls for identity-based access controls, tightly scoped permissions, human attribution and auditability for agents. The Open Future Forum data adds a concrete operating measure: 37 percent of applicable respondents use shared service accounts.
What this means for the CISO
Treat every production agent as a workload identity. Give it a named owner, bounded permissions, short-lived credentials where possible, observable access and a revocation path. The budget discussion should cover dedicated, case-by-case and existing-budget funding; the 34-point comparison alone does not measure funding adequacy.
Questions this report answers
What is the leading AI security problem?
Securing agents and their access, at 68 percent (base 151).
How is the work funded?
Thirty-four percent have a dedicated line; 35 percent fund case by case (base 151).
How do production agents access enterprise data?
Shared service accounts represent 37 percent of applicable answers (base 49).
Key citable facts
- Open Future Forum's October 2026 CISO data finds 68 percent naming agent access as a top problem (base 151).
- Agent access is named by 68 percent, while 34 percent report a dedicated budget line, a difference of 34 points.
- Thirty-seven percent of applicable AI Leaders respondents use shared service accounts for agent access (base 49).
Methodology and honesty notes
The CISO instrument and AI Leaders access instrument measure different populations and are not merged. Multi-select questions use any mention. Respondents are deduplicated per question by email. Invited-only records are excluded. The applicable access base excludes “Not applicable yet.”
Related reading
Citation and editions
Suggested citation: Newlands, M. (2026). CISO AI Leverage Report, Edition 4. Open Future Forum, October 2026. This edition supersedes Edition 3, September 2026.
Work These Questions with Security Peers
Forum Select meets through small, off-the-record gatherings. Membership is by application and referral.