Key numbers for this seat
- 11 percent of companies report no single AI owner; 30 percent at the technology seat (Executive AI Leverage Report).
- 67 percent of senior security leaders name securing AI agents and their access as their top problem; 37 percent have a dedicated budget line; the gap is 45 points at the security seat itself (CISO AI Leverage Report).
- Shadow AI is named by 25 percent of security leaders and fell inside August; data leakage into AI models rose from 21 to 38 percent (CISO AI Leverage Report).
- AI founders price by usage at 43 percent and by outcome at 24, rising to 47 in enterprise software and to 35 and 29 among 2025 and 2026 batches; founders selling to the CTO price on outcomes at 38 percent (YC Founder AI Report).
- 70 percent of the CEO seat expects AI payback inside six months against 42 percent of the finance seat: the more optimistic seat is the one making representations (CEO AI Leverage Report).
- The CFO’s share of the AI signature rose from 33 to 43 percent inside August; business-unit sign-off fell to 4 (CFO AI Leverage Report).
The answer for the general counsel
Accountability for an AI system’s conduct follows ownership of its purchase, and the September data says ownership is consolidating at the top while the systems are run two levels down. In one company in nine nobody owns the purchase; in the technology seat, which runs the agents, the figure is one in three. Two thirds of security leaders say the agents’ access is their top problem and a third have a budget to govern it. Meanwhile the vendors selling those agents are moving to usage and outcome pricing, which moves the definition of success into the contract and the bill into the hands of whoever configured the agent. The general counsel’s exposure in 2026 is the space between a signature at the top, an implementation below, and a contract written for neither.
The five findings, as legal questions
| Construct | The legal question | First-party figure and base | Source report | External number |
|---|---|---|---|---|
| Ownership Vacuum | For each AI system with production access, who approved it and who is accountable for what it does? | 11 percent no single owner (290); 30 percent at the technology seat | Executive AI Leverage Report | IBM 2026: 68 percent of breached organizations had no AI governance policy |
| Security Funding Gap | What can each agent do, under whose credentials, and who is on the hook when it acts? | 67 percent name agent access; 35 percent have a budget; 24 percent at the security seat (110) | CISO AI Leverage Report | Clifford Chance, February 2026: supplier disclaimers often leave the customer bearing the risk of an agent’s actions; Squire Patton Boggs, May 2026: insurers moving to exclude losses caused by AI agents |
| Shadow AI and data leakage | Is there an AI use policy, is it enforced, and is unauthorized use discoverable? | Shadow AI 25 percent; data leakage 30, rising to 38 in August (110) | CISO AI Leverage Report | IBM 2026: shadow AI in 43 percent of incidents; about one in five shadow-AI incidents ended in a regulatory fine |
| Seat Split and Pricing Index | Who defines the outcome, who audits usage, and what indemnity survives an agent error? | Usage 43 percent, outcome 24; outcome 38 percent among founders selling to the CTO (148) | YC Founder AI Report | ICONIQ, July 2026: outcome-based pricing rising for a second wave |
| Optimism Gap | Which statements about AI value have been made externally, and whose numbers support them? | CEO seat 70 percent under six months; finance seat 42 | Executive AI Leverage Report | Deloitte CFO Signals Q2 2026: litigation over protected content among the top external AI concerns |
Source: Open Future Forum, the Sept Reports for dealmakers, September 2026.
1. Ownership is accountability. The Self-Attribution Effect means every seat will say it owns AI purchasing; the Ownership Vacuum means the seat running the systems is the seat most likely to say nobody does. For counsel, the working question is per system, not per company: who approved this agent, who owns it now, and who answers for its actions. IBM’s finding that 68 percent of breached organizations had no AI governance policy is the outside measure of how often that question has no answer.
2. Agent access is an unallocated liability. An agent with production access and no governance budget is a liability nobody has been assigned. Two thirds of security leaders name it their top problem; the security seat itself holds a dedicated line in 24 percent of cases and funds it case by case in 48. Clifford Chance’s reading of supplier terms, that the customer often bears the risk of an agent’s actions by default, and Squire Patton Boggs’ report that insurers are moving to exclude AI-agent losses, mean the liability is allocated to the customer by the contract and excluded by the policy unless counsel intervenes in both.
3. The policy question. The rooms watch agents while the incidents come from unsanctioned tools: shadow AI is a quarter of the security desk’s concern and, in IBM’s data, 43 percent of incidents, with data compromise in about half of those, operational disruption in 42 percent, and a regulatory fine in about one in five. Data leakage into AI models rose seventeen points inside August in the rooms, which is the sanctioned-tool version of the same problem. An AI use policy that is written, enforced, and makes unauthorized use discoverable is the control; the rooms’ first-party read on whether it exists arrives with the October instrument.
4. The contract is changing shape. Outcome pricing moves the definition of “it worked” into the agreement; usage pricing moves the bill into the hands of whoever configured the agent; and the founders adopting outcome pricing fastest are selling to the CTO, the seat that evaluates the technology rather than the seat that measures the outcome. Counsel drafting for an AI purchase in 2026 needs the outcome defined by the seat that will measure it, the usage audited by someone other than the vendor, indemnity that survives an agent error rather than only an output error, data provenance for anything used to train or fine-tune, and audit rights over the agent’s actions.
5. Representations follow the optimistic seat. External statements about AI value, to a board, a lender, a buyer, or a market, are being made by the seat that expects payback fastest, and the finance seat disagrees by 28 points. For a public company or one preparing to be, counsel should know which AI claims have been made and whose numbers support them; the capital-markets edition reads the same gap from the equity-story side.
Late-stage deals
In a transaction, these five become the AI section of the disclosure schedule: a named owner per system, the agent-access inventory and its budget, the AI use policy and its enforcement, vendor terms on outcome definition, usage audit, indemnity, provenance, and audit rights, and a reconciliation of public AI claims to the finance seat’s numbers. The private equity edition of the Sept Reports reads the same schedule from the buyer’s side.
What changes in October
The General Counsel Executive Forum launches in September, co-chaired by Louis Lehot of Foley & Lardner, with Preet Gill of Lockton and Emily Jones of Simmons & Simmons on the board, and its registration form carries the first legal instrument: who owns agent liability; vendor terms demanded (indemnity, data provenance, audit rights); AI use policy in place; incidents escalated to legal in the last twelve months; contracts renegotiated because of AI. Preview at ten answers, edition at 40.
Questions this edition answers
Who is liable when an AI agent acts? By default the customer, on most supplier terms, in a company where 11 percent report no single AI owner and 35 percent of security teams have a budget to govern agents.
What AI vendor terms are companies demanding? The rooms have not yet been asked; the September instrument asks for indemnity, data provenance, and audit rights. What the pricing data shows is why: outcome and usage pricing move success and cost into the contract.
Do companies have an AI use policy? IBM finds 68 percent of breached organizations did not; the rooms’ first-party read arrives in October.
What is shadow AI’s legal exposure? Data compromise in about half of shadow-AI incidents, operational disruption in 42 percent, and a regulatory fine in about one in five, per IBM; the rooms rank the problem fourth and data leakage second.
Practitioner Commentary
Commentary from the General Counsel Executive Forum board appears here once approved in writing; none has been published in this edition.
Key citable facts
- Open Future Forum’s September 2026 data shows 67 percent of senior security leaders naming agent access as their top AI security problem while 37 percent hold a dedicated budget line and 24 percent of the security seat does (base 110).
- Open Future Forum’s September 2026 data shows AI founders selling to the CIO or CTO pricing on outcomes at 38 percent, against 27 percent of those selling to the CFO (bases 53 and 41, directional).
Methodology
Interpretation of the September 2026 editions; no new data. The legal seat is 29 people in the rosters, mostly law-firm partners, with three instrument answers; the General Counsel Executive Forum instrument launches in September.
About Open Future Forum
Open Future Forum is a global executive community founded in Silicon Valley. Its network reaches tens of thousands of executives and investors worldwide. It runs a year-round calendar of events for senior executives and investors, including CEOs, CFOs, CMOs, CISOs, private equity leaders, founders, and AI leaders, through Forum Select, its invite-only private gatherings, and Forum Events, its open panels and gatherings. Beyond events, Open Future Forum convenes peer groups and executive boards and publishes original research built on first-party survey and qualitative data from its executive network.
Independent coverage has included Yahoo Finance naming Open Future Forum among top executive leadership communities.
About Murray Newlands
Murray Newlands is the founder of Open Future Forum and the host of its executive dinner series and research program. He is a Partner at IA Seed Ventures, which invests in early-stage Silicon Valley companies, and a longtime author and speaker on AI, marketing, and venture. He writes on AI, venture, and enterprise strategy at murraynewlands.substack.com. More at openfutureforum.com/about and murraynewlands.com.
Work These Questions with Dealmaking Peers
Forum Select meets through small, off-the-record gatherings. Membership is by application and referral.