Image Credit: Unsplash 

Over the past year, I have sat in a lot of rooms with the people responsible for securing some of the largest enterprises in the world. CISOs at banks, healthcare systems, technology companies, and critical infrastructure operators. Smart, experienced leaders who have navigated ransomware epidemics, supply chain attacks, and nation-state intrusions. People who are not easily rattled.

Right now, many of them are rattled. Not by the AI capabilities their organizations are deploying, which they mostly find impressive. By the governance gap between what those systems can do and what their organizations have built to oversee them.

Here is what the conversations actually sound like.

“We don’t know what our AI agents are doing right now.”

This is the most common thing I hear, and it is more alarming than it sounds. It is not that these organizations have no AI deployments. They have many. The problem is that they have no behavioral monitoring infrastructure calibrated to those deployments. They can tell you what their AI agents are configured to do. They cannot tell you, with any confidence, what their agents are actually doing at any given moment — whether they are behaving within their intended parameters, whether they have been manipulated by adversarial inputs, or whether a failure is accumulating that will materialize as a significant incident in three weeks.

The 2026 CISO AI Risk Report, which surveyed security leaders across major enterprises, found that 95 percent of organizations doubt they could detect or contain AI agent misuse if it occurred. Nearly half have already observed AI agents exhibit unintended or unauthorized behavior. These are not theoretical concerns. They are operational realities that CISOs are managing right now, without the visibility infrastructure to manage them well.

They can tell you what their AI agents are configured to do. They cannot tell you what their agents are actually doing right now.

“Our AI agents have more access than our most privileged humans — and we never formally authorized it.”

The second thing I hear constantly is a version of credential shock. Organizations deploying AI agents in 2024 and 2025 were focused on capability: what can this agent do, how fast can we get it working, what workflows can it automate? The access questions — what data can this agent reach, what systems can it touch, what actions can it take — were treated as configuration details to be addressed by the technical team.

Eighteen months later, security leaders are discovering that their AI agents hold credentials that were never formally reviewed, permissions that were scoped broadly to avoid deployment friction, and access to core business systems that no human user would be granted without a formal access review. One CISO I work with described finding an AI agent with read-write access to their financial reporting system, their customer database, and their external communications platform — a combination of access that would trigger an immediate security review for any human employee but that had been granted to the agent without any formal governance process.

This is not an unusual story. Seventy-one percent of organizations report that AI tools now have access to core business systems like Salesforce and SAP, but only 16 percent say that access is governed effectively. The gap between what AI agents can reach and what any governance process has formally authorized is, in most enterprises I work with, substantial.

“When something goes wrong, we don’t know who owns it.”

The third concern is accountability. When an AI agent sends an unauthorized communication, produces a flawed recommendation that influences a significant decision, or processes a manipulated input that redirects its behavior, the question of who is responsible does not resolve cleanly in most organizations. The vendor points to the deployment decisions. The IT team points to the use case specification. The business unit points to the technical configuration. The CISO points to the business unit.

I have watched this dynamic play out in real incidents, and it is organizationally costly in ways that go beyond the immediate harm. When accountability is diffuse, organizational learning is slow. The same governance failures recur because no one is clearly responsible for preventing recurrence. And when regulators come asking – which they increasingly are, given that the SEC has designated AI governance a 2026 examination priority and multiple state legislatures are passing AI accountability legislation – diffuse accountability is not a defensible position.

When accountability is diffuse, organizational learning is slow. The same governance failures recur because no one is clearly responsible for preventing recurrence.

“We are being asked to move faster than we can govern.”

The fourth thing I hear is the one that concerns me most, because it reflects a structural problem rather than a fixable gap. Business units and executive leadership are pushing for AI deployment at a pace that outstrips the governance infrastructure security teams can build. The pressure is real, the business case for AI is genuine, and the security team that says “slow down” becomes the obstacle rather than the enabler.

The CISOs navigating this best are not the ones who are winning the argument for slowing down. They are the ones who have reframed the conversation: instead of positioning governance as a brake on velocity, they are positioning it as the infrastructure that makes sustained velocity possible. The organizations that deploy AI agents without governance are not moving faster in any durable sense. They are accumulating organizational debt that will constrain their deployment ambition later, when the compliance gaps, ungoverned credentials, and accountability failures that fast ungoverned deployment generates have to be cleaned up.

That reframe is easier to make when you can show the data. Organizations with mature AI governance achieve significantly higher AI ROI than those without. Boards that discuss AI governance at every meeting report returns nearly five times higher than those that do not. Governance is not the cost of responsible AI adoption. It is the enabler of ambitious AI adoption. The CISOs who can make that case in business terms are the ones making progress.

What this means if you’re building or deploying AI

If you are building AI-powered products for enterprise customers, the governance gap your customers are experiencing is your sales cycle. Enterprise security teams are asking harder questions about AI governance in vendor reviews than they were eighteen months ago, and the products that can answer those questions, with audit logs, scoped permissions, behavioral monitoring, and named accountability, are moving through procurement faster than those that cannot.

If you are deploying AI internally, the four concerns I hear from CISOs are a practical checklist. Do you know what your AI agents are doing right now? Have you formally reviewed and authorized the access they hold? Is there a named owner accountable for each consequential deployment? And is your governance infrastructure building capability that makes the next deployment faster, or accumulating debt that will make it slower?

The CISOs keeping me busy are not worrying about AI in the abstract. They are solving specific, concrete governance problems that most organizations have not yet recognized as governance problems at all. The gap between where most organizations are and where they need to be is significant. It is also closable, for the organizations that start closing it now.

Disclaimer: GeekWire newsroom and editorial staff were not involved in the creation of this content..

Harsh Doshi is a cybersecurity products leader focused on securing enterprise AI systems. He has over 15 years of experience building cybersecurity technologies used by large global enterprises, and currently leads AI Security product initiatives at Zscaler. His work focused on developing governance frameworks and runtime protections that enable organizations to adopt AI responsibly at scale. Opinions are his own.