
Someone offered me a bigger title once, and the thing I remember isn’t the title. It’s the list that came with it. Everything I’d now be responsible for, printed out, longer than the list before it. I kept waiting for the second page, the one that says what I’d be allowed to decide, and it wasn’t in the folder. Nobody hands you that page. You’re supposed to be too flattered to ask for it.
I’ve been thinking about that folder a lot lately, because the numbers say the entire security profession is being handed the same one. This April, Gravitee put a survey in front of 750 senior technology leaders across the UK and US. 54% reported an experienced or suspected AI agent security or data-privacy incident in the prior twelve months. Over a third confirmed one outright.
Now set the growth curve next to that number: the enterprise agent footprint roughly doubled between December 2025 and April 2026, and nearly 38% of organizations already run more than 100 agents in production. The incidents aren’t trailing adoption. They’re pacing it.
When one surfaces, the board often asks this question: why didn’t you see it?
Notice the pronoun. Not why didn’t we see it. You. Accountability had already landed on one chair, and nobody paused to ask whether that chair came with the access to answer.
AI governance has now been added to the job description, usually as one line: ensure AI safety. Splunk’s 2026 CISO Report asked 650 CISOs across nine countries, and 96% said they oversee AI governance and risk across the enterprise.
Fine. Look at what the mandate actually covers, though. Procurement runs agents that negotiate vendor terms and HR has them screening candidates and drafting offer letters. These systems don’t retrain themselves overnight, but they don’t hold still either. Configurations drift. Prompts get tuned. A vendor pushes an update and tool access quietly widens. The agent your team reviewed on Monday isn’t quite the agent making decisions on Friday and no change ticket marks the difference. Many were bought and wired in by teams the security org has never audited.
I call them shadow agents. Some were never approved. Others were approved once and changed underneath the approval. They’re shadows not because someone deliberately hid them, but because no one built a durable line of sight from deployment to consequence.
Forrester thinks they’re security’s problem now: its 2026 threat list ranks AI agents second, personal agents slipping in through browser hooks and inbox access, acting at machine speed outside governance, with CISOs accountable for exposure they have limited control over. And they don’t enter at the bottom of the org chart. TrustedTech Team surveyed 2,001 UK and US employees this spring: 65% of senior decision-makers use AI tools their employer hasn’t approved. The employees under them? 31%.
So here’s the ledger the board never reads. The mandate: clear. The tooling: partial and fragmented. The access: restricted, since the systems live under budget lines security doesn’t own. The authority to pull one out of production? Often zero.
Accountability moved into the seat. It doesn’t appear that anything else came with it.
The generous read says I’m describing a promotion, not a trap.
And it’s worth taking seriously, because smart people make it. Deloitte’s 2026 Global Technology Leadership Study surveyed more than 660 senior technology executives and put the shift in one line: “the era of the operational technologist is over.” The argument runs: security spent twenty years asking for a seat at the strategy table and AI governance is finally that seat. The CISO stops being the firewall keeper and becomes steward of the organization’s digital conscience. Not compliance anymore: judgment.
There’s real logic here. Somebody has to lead the security and assurance side of AI governance, and few executives in the building have spent a career studying how systems fail when a motivated person wants them to fail. Legal thinks in liability. Engineering thinks in uptime. Security already lives in adversaries and blast radius, which is exactly the muscle this moment demands.
If the CISO can’t lead this, who can?
It’s a fair question.
So I ran the test it implies.
Pick one AI agent already in production. Something touching real money: loan underwriting, maybe payment routing. Then ask the executive who’s accountable for it to map that single agent’s lifecycle end to end: where the data comes from, what the agent can touch and who owns the decision when the agent gets it wrong. And somewhere in that map, make them show you the gate between recommendation and action. For consequential decisions, the model proposes; something more deterministic - a policy engine, a validation check or, where the stakes require it, a human - disposes.
My bet on where it breaks: the surface answers arrive fast. Vendor name, model family, the liability clause in the contract. Then you ask what the agent actually saw before last Tuesday’s decision, what context and instructions shaped its recommendation, and what authorized the system to act on it. The trail dies at the first integration boundary. Not because anyone’s hiding it... because nobody built the layer that would show it. Opaque to the buyer and often to the builder too.
If the ownership and evidence actually exist, a credible first-pass map shouldn’t require an excavation. I doubt most organizations could produce that map today. Gravitee’s numbers suggest that isn’t just my experience: mean monitoring coverage sits near 52%, leaving roughly half of production agents outside security’s line of sight.
Stewardship of a system you can’t inspect isn’t stewardship. It’s faith.
The trap is the assumption underneath the title: visibility tells you what happened. Authority lets you stop it. Evidence lets you defend what you did afterward. Boards are assigning the outcome while leaving all three incomplete. A dashboard doesn’t help if you can’t change what sits behind it. And shadow agents don’t necessarily announce themselves in the logs security already watches. Their consequential moves may happen across orchestration layers, tool calls, vendor APIs and downstream workflows that were never designed to preserve the model’s context or explain why an action was allowed. By the time the transaction reaches the system of record, the trail you’re being asked to audit may begin after the decision it was supposed to explain.
The log isn’t the event. It’s the residue.
So one desk owns the outcome while the causes sit inside systems that desk can’t open. Ask why a specific decision went the way it did and you may get an explanation generated after the fact, not evidence of the path that produced it. That’s not oversight. That’s a performance audit where the auditor is denied the working papers, then graded on the result.
I’d call it a control gap, except a gap implies two edges you could someday close. This is accountability on one side and nothing on the other.
Elevation and exposure look identical on the org chart.
Both arrive with the bigger title and the seat at the table. The difference doesn’t show until something breaks. Elevation means authority moved with the responsibility. Exposure means the responsibility landed alone. One has the keys. The other just holds the seat.
The board says it wants a guardian. A guardian can act. What they’ve built instead is a witness: someone positioned close enough to the failure to describe it under oath, too far from the machinery to stop it.
That’s not a promotion. It’s a one-way door. You can walk into the seat. The accountability doesn’t walk back out with you.
The record already shows what the seat can cost. Joe Sullivan, Uber’s former chief security officer, was criminally convicted of obstructing an FTC proceeding and concealing a felony in connection with the company’s 2016 breach. The SEC later named SolarWinds CISO Timothy Brown individually in its SUNBURST case. That case ultimately ended without liability - the remaining claims were dismissed with prejudice in November 2025, with no finding against Brown - but he still spent two years as the named defendant.
CISOs did the math. In Splunk’s same survey, 78% said they’re concerned about personal liability for security incidents, up from 56% a year earlier. A 22-point jump in twelve months. And the seat doesn’t hold long enough to fix what it gets blamed for: One industry estimate from Cybersecurity Ventures puts typical large-enterprise CISO tenure at 18 to 26 months, compared with nearly five years across the rest of the C-suite.
So the practical move, the whole reason I’m writing this, is boring and it’s the only real defense I know. When they offer you the seat, do the arithmetic nobody does out loud. Put the new accountability in one column and the new authority in the other. The power to say no. The budget to see. The headcount to keep pace. The standing to halt a deployment that scares you. If the second column keeps up with the first, take the seat and do good work in it. If the first column runs a full page and the second is one sentence, you weren’t elevated. You were positioned. (You might have accepted both kinds of offers previously. The second kind pays about the same and sleep is a lot worse.)
Boards keep saying they want someone who can spot the failure before it happens. (I’m not sure “see” is even the right verb for what they’re asking. Predict, maybe. Or absorb.) The architecture they’ve funded guarantees the opposite: agents that act before the audit trail begins and vendor systems that hide the prompts, context, orchestration and version changes needed to reconstruct what happened. Every quarter the demand for accountability grows. Every quarter the visibility shrinks. Those two curves cross exactly where the CISO is standing.
So the question I’d put to any board isn’t whether their CISO can govern AI. It’s this: what have you let them see? Not the dashboards. The decisions.
Demand the accountability without answering that question and you haven’t built oversight. You’ve cast the trial in advance. When your organization joins Gravitee’s 54%, the CISO will be asked: why didn’t you see it? The answer won’t be in the logs. It’ll be in the contract.
Resources
The CISO Report 2026: From Risk to Resilience in the AI Era (Splunk) - Primary survey of 650 global CISOs on AI governance ownership and personal-liability concern (78% vs 56% year-over-year).
Announcing Forrester’s Top Cybersecurity Threats For 2026 - Forrester’s own framing of agent threats as its second-ranked 2026 cybersecurity threat, including the “accountable for increased exposure with limited control” language.
SEC Charges SolarWinds and Chief Information Security Officer with Fraud, Internal Control Failures - SEC’s original October 30, 2023 press release naming CISO Timothy Brown individually - the cautionary precedent the article uses.
SEC Voluntarily Dismisses Landmark Enforcement Action Against SolarWinds and its CISO - Law-firm writeup of the November 20, 2025 dismissal with prejudice that closed the Brown case.
State of AI Agent Security Report 2026 (Gravitee) - 750-leader survey on AI agent visibility, monitoring coverage and incident rates - the core shadow-AI-agent evidence base.
Turns out the C-suite loves shadow AI (Help Net Security, on TrustedTech Team’s 2026 report) - Censuswide-fielded survey showing decision-makers use unapproved AI at more than twice the rate of the employees they manage (65% vs 31%).
From Operators to Orchestrators: Deloitte’s 2026 Global Technology Leadership Study - 660+ tech-leader survey framing the broader operator-to-orchestrator mandate shift the CISO promotion narrative sits inside.
CISOs Turnover Persists As AI Makes Cybersecurity More Crucial Than Ever (Cybersecurity Ventures) - Source for the 18-26 month CISO tenure figure used as exposure evidence.

