The September answer

The August roundtable produced the clearest security read the program has had. Three in four senior security leaders now put agent access at the top of the desk. The share with a dedicated budget line rose nine points inside a month and the share with no AI security spend nearly halved. That is progress on both sides of the ledger. It is also the same gap: the problem rose faster than the money, and the distance between recognition and resourcing, 30 points on the full base, 34 in August, did not close. The desk knows what the problem is. The budget cycle has not caught up with it. And the seat that carries the responsibility is the seat least likely to have the line.

What changed since Edition 2

Edition 2 was built on 45 responses from the July roundtable. Edition 3 pools both roundtables and their registration windows, 110 unique respondents, and compares the cohort through 30 July with the 61 who applied after it.

Question Answer Through July (53) August (61) Change
Biggest AI security problem Securing AI agents and their access 60 percent 75 percent +15
Data leaking into AI models 21 percent 38 percent +17
Shadow AI: tools used without approval 30 percent 21 percent -9
Attacks that use AI against us 13 percent 20 percent +7
Nothing urgent yet 6 percent 3 percent -3
How AI security is funded Its own budget line 32 percent 41 percent +9
Case by case 34 percent 34 percent 0
Carved out of the existing security budget 25 percent 25 percent 0
No AI security spend yet 13 percent 8 percent -5

Source: Open Future Forum, CISO AI Leverage Report, Edition 3, September 2026.

How to read month over month: different respondents at different events inside one network, not a tracked panel; single-digit moves are noise. Any-mention convention; the problem question is heavily multi-select, so columns sum past 100. Both cohorts are the same instrument at the same dinner series a month apart, with a topic that selects for the problem: the August roundtable opened on agent governance and board reporting, and people who hold that problem applied to it. That is disclosed, and it is also the point. The people who hold the problem run security at large companies, and they are the sample this report exists to read.

What stayed the same: agent access as the top problem, the rank order of funding models, and the case-by-case share at a third.

What surprised us: data leakage nearly doubled while shadow AI fell. In Edition 2 we read shadow AI as the problem most likely to grow, on the strength of IBM’s breach data. The August room says the reverse: the unsanctioned tool is a smaller worry than what sanctioned tools do with the data they are given. The desk has moved from “which tools are they using” to “what are the agents allowed to see.”

Where this research comes from

The CISO AI Leverage Report is built from instrument questions embedded in the application flow for Open Future Forum’s security events, including the CISO Roundtable Dinner series convened with the CISO Executive Forum, the network’s invitation-only peer group for security leaders, with Kashish Mittal of Salesforce, Paulina Xu of Agentic Fabriq, Pushpak Pujari of Harden, and Prasen Shelar of Axari on the board. This edition draws on the two CISO Roundtable Dinners (July and August) for instrument data, and on the April CISO Leadership Dinner, the June Enterprise AI and Agentic Security Dinner, and the August Black Hat coffee for rosters. Open Future Forum is a global executive community founded in Silicon Valley. Its network reaches tens of thousands of executives and investors worldwide. It runs a year-round calendar of events for senior executives and investors through Forum Select, its invite-only private gatherings, and Forum Events, its open panels and gatherings, and publishes original research built on first-party survey and qualitative data from its executive network.

What is the biggest AI security problem on the CISO’s desk in 2026?

Securing AI agents and their access, by a distance that widened. Two thirds of 110 senior security leaders name it, three quarters of the August room. The next three problems are all smaller than the gap between first and second: data leakage at 30 percent, shadow AI at 25, attacks that use AI at 16. Five percent see nothing urgent.

The shape of the list is the finding. The top two are governance problems: what an agent can reach, and what a model is fed. The adversary problem, AI used against the company, is fourth. Governance outranks adversary two to one. That is good news of a specific kind. Governance is within the organization’s control. It does not require predicting an attacker; it requires an inventory, an owner, and a budget. Two of those three are where the rooms say they are stuck.

How are security teams funding AI security in 2026?

Four ways, and the distribution has not resolved. On the full base of 110: a dedicated AI security budget line, 37 percent; case by case, 36 percent; carved out of the existing security budget, 22 percent; no AI security spend yet, 11 percent. August moved the edges, dedicated up to 41 and no-spend down to 8, and left the middle alone.

Read as archetypes:

The Funded group is growing at the expense of the Unfunded group. The Case-by-case middle is not moving, and a third of security teams are still funding the biggest problem on their desk one meeting at a time.

The Security Funding Gap

Exhibit 1: The Security Funding Gap

Defined here for the first time and carried forward as a tracked line: the share of senior security leaders naming agent access as their top AI security problem minus the share with a dedicated AI security budget line. Cumulative: 67 minus 37, 30 points. August cohort: 75 minus 41, 34 points. It measures the distance between recognition and resourcing, which is where most of the risk in the rooms sits. It is a number a board can ask for and a broker can work with, and it will be reported every edition.

Leverage by seat: the security read per C-level

The security rooms are not only CISOs, and the seat mix is a finding in itself. Of 126 approved guests, technology titles are the largest group at 36, security titles second at 30, founders and CEOs 13, investors 5, with 42 other or blank. The instrument answers split the same way. Every chair is read below on every question it answered; seat classification is by keyword on self-reported title, all bases are under 40 and directional, and 19 respondents gave no title.

The same questions, four chairs Security, CISO (29) Technology, CTO or CIO (21) CEO or founder (37) Other titles (16)
Names agent access as the top AI security problem 69 percent 76 percent 59 percent 62 percent
Names data leaking into AI models 31 percent 33 percent 32 percent 19 percent
Names shadow AI 31 percent 14 percent 30 percent 25 percent
Names attacks that use AI 21 percent 24 percent 11 percent 12 percent
Holds a dedicated AI security budget line 24 percent 33 percent 41 percent 50 percent
Funds AI security case by case 48 percent 33 percent 30 percent 25 percent
Carves it from the existing security budget 21 percent 33 percent 14 percent 12 percent
Has no AI security spend yet 7 percent 0 percent 16 percent 12 percent
Security Funding Gap at this chair (problem minus line) 45 points 43 points 18 points 12 points
Agent access, July cohort to August cohort 67 to 71 percent (15 and 14) 67 to 82 percent (9 and 12) 39 to 79 percent (18 and 19)

Source: Open Future Forum, CISO AI Leverage Report, Edition 3, September 2026. Any-mention convention.

The security seat, CISO. Names the top problem at 69 percent and is the least funded chair in its own room: 24 percent hold a dedicated line, 48 percent fund case by case. Its Security Funding Gap is 45 points, the widest of any chair. It names shadow AI and data leakage equally, at 31 percent, and attacks at 21. Its agent-access share barely moved between July and August, 67 to 71 on tiny bases, because it had the problem first. This is the chair the report is named for, and it is the chair that has to argue for the money one meeting at a time.

The technology seat, CTO and CIO. Names agent access most, at 76 percent, and is the only chair where nobody reports zero AI security spend; a third hold a dedicated line and a third have carved the money out of the existing security budget. Its gap is 43 points, close to the CISO’s, but it has found the money more often by taking it from somewhere else. It names shadow AI least, at 14 percent: the seat that runs the infrastructure worries about what the sanctioned agents can reach, not about the unsanctioned tools. Its agent-access share rose from 67 to 82 between the cohorts.

The CEO and founder seat. The best-funded chair at 41 percent with a dedicated line and the least concerned about attacks at 11 percent. The founders in the security rooms are largely building the tools the CISOs are evaluating, so their funding answers describe their own companies. Their gap is 18 points. Their agent-access share doubled between July and August, from 39 to 79 percent: the CISOs had the problem first and the founders caught up in a month, which is what a market forming looks like from the supply side.

Other titles. Security consultants, advisors, and operators without a C-level or technology title: 50 percent hold a dedicated line, the highest, and 62 percent name agent access. The smallest gap, at 12 points, sits with the people who advise on the problem rather than own it.

Across the four chairs. The Security Funding Gap runs from 45 points at the CISO to 12 at the advisor. Where the responsibility sits, the money is thinnest. The direction of the August movement is the same in every chair, agent access up, and the chair that moved least is the one that started highest.

The same view, by vertical

New this edition: the security rooms cut by the respondent’s industry, classified from company name, email domain, and self-reported sector where given. 41 of 126 approved guests and 25 of 110 respondents cannot be placed and are shown as Unclassified; every vertical base is under 40 and directional; groups under five are not shown.

Who is in the security rooms, by vertical

Vertical Approved guests C-suite, founder, or partner share Holds the CISO or head-of-security title (screening question)
Big Tech and platforms 25 4 percent 35 percent (23)
Technology and enterprise software 15 47 percent 46 percent (61)
Security 12 50 percent 42 percent (19)
VC and investment 9 67 percent 44 percent (16)
Infrastructure and data 3 33 percent
Other 16 38 percent 40 percent (40)
Unclassified 41 41 percent 38 percent (58)

Source: Open Future Forum, CISO AI Leverage Report, Edition 3, September 2026. Screening-question bases include declined applicants.

The security instrument, by vertical

Vertical Base Agent access top problem Data leakage Shadow AI AI-powered attacks Dedicated budget line Case by case Security Funding Gap
Technology and enterprise software 30 60 percent 27 33 10 40 37 20 points
Big Tech and platforms 10 70 percent 30 20 20 50 20 20 points
Security vendors 8 62 percent 50 25 12 0 50 62 points
VC and investment 7 71 percent 29 29 14 14 43 57 points
Infrastructure and data 5 80 percent 20 20 0 40 60 40 points
Other 17 53 percent 18 24 12 29 41 24 points

Source: Open Future Forum, CISO AI Leverage Report, Edition 3, September 2026. Any-mention; all bases directional. Unclassified respondents (25) are excluded from the table and included in every headline figure.

Technology and enterprise software. The largest classified group and the one that names shadow AI most, at 33 percent, and attacks least, at 10. The software company’s AI security problem is its own employees’ tools and its own agents’ reach, not an adversary. It is the best funded vertical after Big Tech at 40 percent with a dedicated line, and its gap is the narrowest at 20 points. Nearly half of its applicants hold the CISO title, the highest share of any vertical.

Big Tech and platforms. A quarter of the security rooms’ approved guests, almost none of them C-level, because these are the security operators from the platform companies rather than their chief officers. The best funded group at 50 percent with a dedicated line, the most attack-conscious at 20 percent, and a gap of 20 points. Only 35 percent of their applicants hold the CISO title; the platform sends its practitioners.

Security vendors. The companies building the tools, answering about their own security. They name data leakage highest of any vertical at 50 percent, and none of the eight holds a dedicated AI security line; half fund case by case. The widest gap in the data, 62 points, sits with the vendors selling the fix, which is a finding to hold lightly on eight people and to ask about at the next roundtable.

VC and investment. Investors and the security leaders at their firms name agent access at 71 percent and hold a dedicated line at 14; a 57-point gap, consistent with the investor seat’s own finding elsewhere in the Index that it applies a standard to the portfolio it has not yet met at home.

Infrastructure and data. Five people, the highest agent-access share at 80 percent and the highest case-by-case share at 60: the seat that runs the infrastructure the agents sit on, funding their governance one argument at a time.

Missing verticals. Financial services, healthcare, professional services, and consumer each have one or two approved guests in the security rooms and no instrument base. The CISO rooms draw from software companies and platforms first. The security leaders of banks, health systems, and law firms are the recruiting target for Edition 4, and the vertical question on the October form is what makes the cut publishable when they arrive.

What security leaders are asking coming into the rooms

The CISO instrument carries no open question this cycle, so the qualitative layer comes from the rooms around it. Applicants to the June Enterprise AI and Agentic Security Dinner were asked what else they want to attend (base 92, any-mention): AI for leadership, 40 percent; wine tasting, 18; AI for competitive research, 14; golf, 11; hands-on training, 9. Across the AI Dev and CTO gatherings, 77 percent of 249 respondents said yes to learning more about securing AI agents. The August roundtable opened on agent governance and board reporting, and the questions it took were the ones this report measures: how to give agents identity and least-privilege access without stalling the business; who owns agent governance when a business unit buys the agent; and how to report AI risk to the board as a number rather than a list.

Tested against the record

External claim Open Future Forum figure Verdict
IBM Cost of a Data Breach 2026: shadow AI involved in 43 percent of incidents, up from 20; average breach $4.99M Shadow AI named as the top problem by 25 percent; agent access by 67 Complicated: breach data ranks the problem that has already happened; the rooms rank the one they expect next
IBM: 68 percent of breached organizations had no AI governance policy; 92 percent of AI-breached organizations lacked AI access controls Agent access is the top problem for two thirds of the rooms Corroborated in direction: access control is the missing control on both sides
IBM: only 38 percent require IT approval before AI is deployed 35 percent fund AI security case by case Corroborated: approval and funding are both ad hoc in a third of organizations
McKinsey AI Trust Maturity 2026: agentic AI governance added as a fifth maturity dimension; organizational alignment lagging Governance problems outrank adversary problems two to one Corroborated
KPMG Q2 Pulse: 26 percent have real-time visibility into AI running costs 37 percent have a dedicated AI security budget line Corroborated: neither the cost nor the security of AI has its own line in most companies
Cisco AI Readiness Index: 24 percent can control AI risk 35 percent Funded; 11 percent Unfunded Complicated: readiness and funding are measured differently, and both are minorities

Source: Open Future Forum, CISO AI Leverage Report, September 2026.

External figures are context only; the sources are not affiliated and do not endorse this report.

What this means for the security team

Three moves the funded third of the rooms have already made. Put agent identity on the same footing as human identity: an inventory of every agent with production access, its permissions, and its owner, with access that can be audited and revoked. Second, get AI security its own budget line, because the data says case-by-case funding is not a transition state but a resting state, and a third of teams have been resting in it for two editions. Third, report the Security Funding Gap to the board as a number. A 30-point gap between the problem two thirds of peers name and the budget line a third hold is an easier conversation than a threat list, and it is the conversation the board track of this program is built to have. One more, for the CISO specifically: your seat is the least funded in your own room. If the dedicated line does not exist, it is worth knowing that the founders and the technologists at the same table have one.

Practitioner Commentary

Board members of the CISO Executive Forum, commenting on the findings after the data was locked.

“At scale, every agent is a new identity with permissions someone has to own. Two thirds of security leaders now say that is the problem on their desk. The teams making progress treat agent access like any other privileged access: inventoried, scoped, reviewed, and paid for out of a line that exists.” Kashish Mittal, Salesforce

“The gap between the problem CISOs are naming and the money they have to address it is an important part of the story in 2026. Agents are getting production access faster than governance is catching up. Closing that gap is less about buying another tool and more about treating agent identity and access with the same discipline we apply to human identity, including clear ownership, controls, and budget.” Caroline Wong, Chief Strategy Officer, Axari

“Seventy-five percent naming agent access as a top concern tells you where we are. AI agents are moving from experimentation into real work, with access to sensitive systems, data, and workflows. Security teams now need the same visibility and control over agents that they expect for people, without slowing down the value those agents can create.” Prasen Shelar, CEO and Co-founder, Axari

Perspectives from Partners

“The August roundtable putting agent access at seventy-five percent tells us where security leaders are focused. As AI agents become part of everyday work, security teams need visibility into what they can access, what they’re doing, and the ability to govern that access without getting in the way of the work.” Prasen Shelar, CEO and Co-founder, Axari. Axari is a partner of the CISO Executive Forum.

“The Security Funding Gap is a number a broker can work with. It tells us where the exposure sits before the claim does. Companies that close it will find the insurance conversation easier and shorter.” Jan Berthold, Executive Vice President, Heffernan. Heffernan is a partner of the CFO Executive Forum.

For boards, counsel, and the buying side

Boards get the number to ask for: the Security Funding Gap, and the seat cut that shows it is widest where the responsibility sits. General counsel gets the liability frame: an agent with production access and no governance budget is an unallocated liability, and 67 percent of security leaders say it is their top problem; the general counsel edition of the Sept Reports reads the same finding as a contract and coverage question. Private equity gets a diligence item: an agent-access inventory before close. Vendors in the CISO AI Market Map get the clearest demand signal in the Index: agent identity and access, with a budget forming under it at nine points a month.

Where can CISOs discuss this with peers?

The CISO Executive Forum is Open Future Forum’s invitation-only peer group for security leaders, chaired by Murray Newlands, with Kashish Mittal of Salesforce, Paulina Xu of Agentic Fabriq, Pushpak Pujari of Harden, and Prasen Shelar of Axari on the board. Members meet through the CISO Roundtable Dinner series, off the record, for CISOs, Deputy CISOs, VPs of Security, and Heads of Security only, and through the open security panels and dinners. The rooms stay senior: 70 percent of titled approved guests at the security events hold a senior title, 47 percent are C-level, founders, or partners, and the security rooms approved 27 percent of applicants this period, 139 of 521. Membership is by application and referral.

Explore the CISO Executive Forum · Inquire about membership

Upcoming security events

Enterprise AI at Microsoft

Microsoft campus, Mountain View, CA · date to be announced

An afternoon on what it takes to run AI reliably inside the enterprise, including a session on AI agent database access without credentials, the mechanism behind this report’s top finding. For CISOs, CIOs, CTOs, data leaders, and engineering executives. The registration form carries the first AI Leaders instrument: agents in production, the bottleneck, and how agents access enterprise data.

CISO Roundtable Dinner

Los Altos Hills, CA · next date to be announced

Off the record, for CISOs, Deputy CISOs, VPs of Security, and Heads of Security only. Edition 4 data collection.

Edition 4 data collection runs through these rooms. The three questions the next rooms will debate: whether agent security gets its own line or stays case by case, who owns the agent a business unit bought, and what number the board should be shown.

Answers from this report. What is the biggest AI security problem for CISOs? · Do companies have AI security budgets? · What is shadow AI's legal exposure? · Who is liable when an AI agent acts?

Definitions

The Security Funding Gap: the share of senior security leaders naming securing AI agents and their access as their top AI security problem minus the share with a dedicated AI security budget line. September 2026: 30 points cumulative, 34 in August, 45 at the security seat.

Funding archetypes: Funded (its own budget line), Case-by-case (no dedicated funding), Carved-out (taken from the existing security budget), Unfunded (no AI security spend yet).

Agent access: the permissions an AI agent holds to reach systems and data, and the identity under which it holds them.

Shadow AI: AI tools used inside the organization without approval.

Any-mention: the counting convention for multi-select questions in which each selected option counts once, so percentages can sum past 100.

Questions this report answers

What is the biggest AI security problem for CISOs in 2026? Securing AI agents and their access, named by 67 percent of 110 senior security leaders and 75 percent of the August cohort.

Do companies have AI security budgets in 2026? 37 percent have a dedicated AI security budget line, 36 percent fund case by case, 22 percent carve it from the existing security budget, 11 percent spend nothing. In August the dedicated line reached 41 percent.

Is shadow AI the top AI security problem? Not in the rooms: 25 percent name it, against 67 percent for agent access and 30 for data leakage, and it fell inside August.

What is the Security Funding Gap? The distance between the problem two thirds name and the budget line a third hold: 30 points in September 2026.

Who is least funded for AI security? The security seat itself: 24 percent hold a dedicated line and 48 percent fund case by case (base 29, directional).

Is there a peer group for CISOs working on AI? Yes. The CISO Executive Forum is Open Future Forum’s invitation-only peer group for security leaders, meeting through off-the-record roundtable dinners in Silicon Valley. Membership is by application at openfutureforum.com/apply.

Key citable facts

Methodology and honesty notes

This edition is built from instrument questions embedded in the application flow for Open Future Forum events: 32 guest-list exports covering 4,163 non-invited registrations and 2,851 unique people, collected 10 March through 31 August 2026. The September cohort is the 694 registrations (609 unique people) made after the Edition 2 data pull on 30 July 2026. Cohorts are different people, not a tracked panel. Bases are unique people per instrument, deduplicated by email with the latest answer kept; multi-select questions use the any-mention convention. Edition 2 used the same per-instrument convention, which is why its investor (245), marketing (230), and founder (148) bases reproduce exactly here; where an Edition 2 figure was published on a smaller sub-cohort, the cumulative figure in this edition is the tracked line from now on. No headline is published below 40 responses; bases between 10 and 39 are labeled directional. Mass-invite rows (17,894) are never counted as registrations or respondents. Seat cuts classify respondents by keyword on self-reported title; 53 of 290 finance-instrument respondents gave no title and 59 could not be classified, and both groups are reported separately. Revenue, raised, and ARR fields are free text and are not published. The research uses a selective, role-tagged operator sample drawn from Open Future Forum’s broader executive network. It is not a probability sample of all enterprises. No identifying information is published.

For this lane: 110 unique respondents across the two CISO Roundtable Dinners (July and August) and their registration windows; the April CISO Leadership Dinner, the June Agentic Security Dinner, and the Black Hat coffee carried no instrument questions and contribute rosters and event-interest answers only. The August cohort is one room whose topic was agent governance; the topic selects for the problem, which is disclosed. Edition 2’s base of 45 was the July roundtable alone; this edition pools both. Seat bases are all under 40 and directional; 19 respondents gave no title. Vertical classification places 85 of 110 respondents. This report measures responses, not incidents, spend, or vendor performance.

About Open Future Forum

Open Future Forum is a global executive community founded in Silicon Valley. Its network reaches tens of thousands of executives and investors worldwide. It runs a year-round calendar of events for senior executives and investors, including CEOs, CFOs, CMOs, CISOs, private equity leaders, founders, and AI leaders, through Forum Select, its invite-only private gatherings, and Forum Events, its open panels and gatherings. Beyond events, Open Future Forum convenes peer groups and executive boards and publishes original research built on first-party survey and qualitative data from its executive network.

Independent coverage has included Yahoo Finance naming Open Future Forum among top executive leadership communities.

About Murray Newlands

Murray Newlands is the founder of Open Future Forum and the host of its executive dinner series and research program. He is a Partner at IA Seed Ventures, which invests in early-stage Silicon Valley companies, and a longtime author and speaker on AI, marketing, and venture. He writes on AI, venture, and enterprise strategy at murraynewlands.substack.com. More at openfutureforum.com/about and murraynewlands.com.

Citation and editions

Suggested citation: Newlands, M. (2026). CISO AI Leverage Report, Edition 3. Open Future Forum, September 2026. openfutureforum.com/research/ciso-ai-leverage-report-september-2026

This edition supersedes Edition 2 (August 2026). Companion reading: CISO AI Market Map, Executive AI Leverage Report. Edition 4 publishes in October 2026. Dataset DOI: 10.5281/zenodo.21576019.

Work These Questions with Security Peers

The CISO Executive Forum meets through small, off-the-record gatherings. Membership is by application and referral.

Explore the CISO Executive Forum Inquire about membership