AI Security: Why It’s Now a Board-Level Priority (And What To Do About It)

AI Security means protecting three things at once: the AI systems your organisation uses, the infrastructure that runs them, and your business from AI-powered attacks. Most cybersecurity teams aren’t involved early enough in AI decisions to do this well, and the gap is widening as AI agents spread faster than governance can keep up. The fix starts with visibility: know what AI is running in your organisation before you try to secure it.

✓  By 2028, Gartner expects generative AI to be a factor in 22% of all cyberattacks and data leaks.[1]

✓  Only 30% of cybersecurity leaders at midsize enterprises consider their teams effective at securing generative AI tools.[1]

✓  Non-human identities (including AI agents) now outnumber human ones by roughly 17 to 1 in the enterprise, and a third sit dormant and ungoverned.[3] 

✓  Five foundational steps (discovery, identity management, information governance, oversight, continuous assurance) cover most of what AI security requires today.[3]

Introduction 

AI rolled into the businesses faster than almost any technology before it. Employees started using ChatGPT before IT had a policy for it. Vendors bolted Copilot-style assistants onto every product. Now agentic AI is showing up in code repositories, browsers, and SaaS platforms, often without anyone in security having approved it, or even knowing it’s there. 

That speed is the whole problem. Security teams are being asked to protect something they didn’t get to help design, using budgets and headcount that haven’t caught up. This article walks through what’s actually causing the pressure, what AI security means in practice, and the concrete next steps that get an organisation from ‘exposed’ to ‘in control’. 

The AI security pain points every organisation is feeling right now

Security teams are the last to know

Across midsize enterprises, only 41% of cybersecurity teams are involved in the planning phase of a generative AI rollout, and even fewer, 38%, are involved once development starts, according to Gartner’s 2024 Data Security in the Age of AI Advancements Survey. Two-thirds don’t have the final say on decisions as important as incident response plans or kill-switch policies. Business teams move first, and security finds out after the tool is already in production.[1]

This isn’t a training problem. It’s a sequencing problem. When security is looped in only after a tool has been selected, teams are left reacting to decisions rather than shaping them.

Shadow AI is the default, not the exception

Employees adopt AI tools whether or not IT approves of it. Gartner has found that 89% of business technologists would bypass cybersecurity guidance entirely if it stood between them and a business objective.[2] Nearly half of midsize enterprises are effectively letting employees use their own judgement on data risk when working with generative AI, rather than building safe environments for experimentation.[1]

The result is an AI attack surface that keeps expanding in the dark: unsanctioned SaaS tools, browser-based AI extensions, and coworking agents that no one has inventoried.

AI agents multiply faster than identity management can track them

Agentic AI has turned a governance problem into an identity problem. Non-human identities, including service accounts and AI agents, now outnumber human identities by roughly 17 to 1 in the average enterprise, and a third of them are dormant and effectively ungoverned. Gartner’s 2025 research found that while half of IT leaders believe they have sufficient governance in place, 84% privately admit they need stronger technical controls to actually secure their AI agents. Most organisations already suspect, or have direct evidence of, unsanctioned AI agent activity somewhere in their environment.[3]

Boards are demanding AI adoption faster than budgets and talent can support

Forrester’s research on boardroom AI narratives puts this plainly: executive enthusiasm for AI is expanding the CISO’s mandate faster than most organisations can realistically resource it.[4] Boards want the productivity story. They’re less interested in the fact that, per Carnegie Mellon’s The Agent Company benchmark, even the most capable AI agents fail to complete the majority of simulated office tasks without help. The economics point toward more automation regardless, so CISOs who show up only with failure data lose the argument. What works instead is tying AI security investment directly to revenue protection, regulatory exposure, and customer trust, the three things boards already care about.

The costs are shifting, and the talent pipeline is thinning

Agentic workflows consume dramatically more compute than a simple chat interaction, and licensing models are changing mid-contract as vendors move from flat fees to consumption-based pricing. At the same time, early-career hiring into cybersecurity roles is contracting as AI absorbs entry-level tasks, which quietly erodes the pipeline of practitioners who’ll be needed to govern these systems in five years.[4]

What is AI security, exactly?

AI security covers three distinct jobs, and most conversations only mean one of them:

Using AI to strengthen security. Chat-style assistants for security operations centers, automated alert triage, and faster threat summarisation. This is “defending with AI.”

Securing how the organisation builds and uses AI. Every AI tool, agent, browser plugin, service identity, and Model Context Protocol (MCP) connection an organisation touches adds to what’s often called the AI attack surface. Securing it means applying the same rigor to AI assets that’s already standard for endpoints, identities, and cloud infrastructure.

Defending against AI-powered attacks. Attackers use generative AI the same way defenders do: to move faster, write more convincing phishing lures, and scale attacks that used to require more manual effort.

Gartner frames this as four impact areas CISOs need a plan for: defending with generative AI, being attacked by it, securing what the organisation builds with it, and governing how the organisation consumes it. Put together, this is the AI Trust, Risk and Security Management (AI TRiSM) framework, and it’s quickly becoming a baseline expectation rather than a nice-to-have.[2]

The risks that matter most right now include prompt injection (malicious instructions hidden in content that hijacks an AI agent’s behaviour), excessive agent permissions that let a tool take actions it was never meant to take, non-human identity abuse, compromised AI supply chains (a poisoned MCP server or plugin), and plain old shadow AI: tools nobody signed off on, running with nobody watching.

Gartner’s guidance on AI agent assurance breaks the response into five steps: discover every agent in the environment, treat agents as first-class identities within identity and access management, apply information governance to everything agents touch, add automated oversight (“guardian agents”) for continuous monitoring, and build feedback loops that let the whole system improve over time. It’s a sequence, not a checklist. Discovery has to come first, because it’s impossible to govern what hasn’t been found.[3]

Next steps: building an AI security program that keeps pace

1. Start with visibility, not policy. Before writing an acceptable-use policy, find out what’s actually running: AI-integrated SaaS applications, browser extensions, installed agents, and the service identities tied to them. An inventory is the prerequisite for everything else on this list.[3]

2. Bring security in at the start, not the end. Embed a lightweight security checkpoint into the AI adoption process itself, and create a pre-approved list of vetted AI tools so business teams can move quickly without bypassing security altogether. Where internal capacity is tight, shifting continuous monitoring to a managed detection and response partner frees the in-house team to focus on incident response, where their business context matters most.[1]

3. Treat AI agents as identities, not background processes. Every agent needs a unique, auditable identity, least-privilege access, and just-in-time permissions rather than standing access. Build in a process for retiring agents that are abandoned mid-experiment, which happens more often than most inventories admit.[3]

4. Extend data governance to everything an agent touches. Agents access, generate, and move data at a scale and speed manual reviews can’t match. Comprehensive, AI-aware data classification and monitoring needs to cover both structured and unstructured data, in transit and at rest, with acceptable-use violations escalated automatically rather than caught after the fact.[3]

5. Make the case to the board in terms it already uses. Link AI security spend to revenue protection, regulatory exposure, and customer trust rather than treating it as a standalone security line item. Distribute the cost across the functions actually deploying AI, since risk now originates well outside the security team, in marketing, product, and operations alike. Treat token and compute consumption the way FinOps treats cloud spend: with budgets, anomaly detection, and accountability per business unit.[4]

6. Build the talent pipeline deliberately. Reskilling internal staff into AI-oversight roles, rather than relying solely on hiring, is proving to be a real competitive advantage as the market for AI-fluent security talent tightens.[4]

 

Challenge  What’s actually happening  The practical fix 
No visibility into AI use  Shadow AI tools and agents run unmonitored across SaaS, browsers, and endpoints  Continuous, automated discovery covering installables, browser plugins, SaaS, and service identities 
Security involved too late  Business teams adopt AI tools before security reviews them  Lightweight checkpoints early in the adoption process, plus a pre-approved tool list 
Ungoverned AI agents and identities  Non-human identities outnumber human ones and a third are dormant  Register every agent as a first-class identity with least-privilege, time-limited access 
Board pressure outpacing resourcing  Executives push AI adoption faster than budget and talent allow  Tie security investment to revenue, regulatory, and trust outcomes the board already tracks 

Frequently asked questions 

What is AI security? 

AI security is the practice of protecting the AI systems an organisation uses and builds, the infrastructure behind them, and the business from attacks that use AI. It spans AI agents, SaaS tools, browser plugins, and the identities tied to all of them.[2]

Why is AI security a board-level issue now? 

Because AI adoption is expanding faster than governance, budget, or talent can support it, and boards are pushing for it regardless. Gartner projects generative AI will factor into 22% of cyberattacks and data leaks by 2028, making this a business risk, not just a technical one.[1,4] 

What’s the biggest AI security risk today? 

Shadow AI and ungoverned agents. Most organisations already suspect unsanctioned AI activity exists somewhere in their environment, and non-human identities now vastly outnumber human ones, often without matching oversight.[3]

Where should a company start with AI security? 

With discovery. Find out what AI tools, agents, and identities already exist before writing policy or buying tools. Visibility is the prerequisite for every other control.[3]

How is AI security different from traditional cybersecurity? 

It adds new categories of risk, like prompt injection, agent identity abuse, and AI supply-chain compromise, that don’t map cleanly onto existing endpoint or network controls. It requires extending existing identity, data, and detection programs to cover AI-specific assets, rather than building something entirely separate.[2] 

Where this leaves you 

AI isn’t a category that will eventually go away and become “just security” again, but it isn’t there yet either. Right now, the organisations managing it well are the ones treating visibility as step one and building identity, data, and oversight controls around what they find, rather than waiting for a perfect policy before they start.

Sources 

[1] Gartner, 3 Generative AI Security Red Flags for Midsize Enterprise CIOs, Patrick Long, Srishti Khanna, 2 May 2025.

[2] Gartner, 4 Ways Generative AI Will Impact CISOs and Their Teams,  Jeremy D’Hoinne,  Avivah Litan , Peter Firstbrook, 29 June 2023.

[3] Gartner, Act Now: Take These 5 Steps for AI Agent Assurance, Avivah Litan, Max Goss, Carlton Sapp, 21 January 2026 

[4] Forrester, Resetting Security’s AI Narrative With Boards And Executives, September 2026 

AI Security means protecting three things at once: the AI systems your organisation uses, the infrastructure that runs them, and your business from AI-powered attacks. Most cybersecurity teams aren’t involved early enough in AI decisions to do this well, and the gap is widening as AI agents spread faster than governance can keep up. The fix starts with visibility: know what AI is running in your organisation before you try to secure it.

✓  By 2028, Gartner expects generative AI to be a factor in 22% of all cyberattacks and data leaks.[1]

✓  Only 30% of cybersecurity leaders at midsize enterprises consider their teams effective at securing generative AI tools.[1]

✓  Non-human identities (including AI agents) now outnumber human ones by roughly 17 to 1 in the enterprise, and a third sit dormant and ungoverned.[3] 

✓  Five foundational steps (discovery, identity management, information governance, oversight, continuous assurance) cover most of what AI security requires today.[3]

Introduction 

AI rolled into the businesses faster than almost any technology before it. Employees started using ChatGPT before IT had a policy for it. Vendors bolted Copilot-style assistants onto every product. Now agentic AI is showing up in code repositories, browsers, and SaaS platforms, often without anyone in security having approved it, or even knowing it’s there. 

That speed is the whole problem. Security teams are being asked to protect something they didn’t get to help design, using budgets and headcount that haven’t caught up. This article walks through what’s actually causing the pressure, what AI security means in practice, and the concrete next steps that get an organisation from ‘exposed’ to ‘in control’. 

The AI security pain points every organisation is feeling right now

Security teams are the last to know

Across midsize enterprises, only 41% of cybersecurity teams are involved in the planning phase of a generative AI rollout, and even fewer, 38%, are involved once development starts, according to Gartner’s 2024 Data Security in the Age of AI Advancements Survey. Two-thirds don’t have the final say on decisions as important as incident response plans or kill-switch policies. Business teams move first, and security finds out after the tool is already in production.[1]

This isn’t a training problem. It’s a sequencing problem. When security is looped in only after a tool has been selected, teams are left reacting to decisions rather than shaping them.

Shadow AI is the default, not the exception

Employees adopt AI tools whether or not IT approves of it. Gartner has found that 89% of business technologists would bypass cybersecurity guidance entirely if it stood between them and a business objective.[2] Nearly half of midsize enterprises are effectively letting employees use their own judgement on data risk when working with generative AI, rather than building safe environments for experimentation.[1]

The result is an AI attack surface that keeps expanding in the dark: unsanctioned SaaS tools, browser-based AI extensions, and coworking agents that no one has inventoried.

AI agents multiply faster than identity management can track them

Agentic AI has turned a governance problem into an identity problem. Non-human identities, including service accounts and AI agents, now outnumber human identities by roughly 17 to 1 in the average enterprise, and a third of them are dormant and effectively ungoverned. Gartner’s 2025 research found that while half of IT leaders believe they have sufficient governance in place, 84% privately admit they need stronger technical controls to actually secure their AI agents. Most organisations already suspect, or have direct evidence of, unsanctioned AI agent activity somewhere in their environment.[3]

Boards are demanding AI adoption faster than budgets and talent can support

Forrester’s research on boardroom AI narratives puts this plainly: executive enthusiasm for AI is expanding the CISO’s mandate faster than most organisations can realistically resource it.[4] Boards want the productivity story. They’re less interested in the fact that, per Carnegie Mellon’s The Agent Company benchmark, even the most capable AI agents fail to complete the majority of simulated office tasks without help. The economics point toward more automation regardless, so CISOs who show up only with failure data lose the argument. What works instead is tying AI security investment directly to revenue protection, regulatory exposure, and customer trust, the three things boards already care about.

The costs are shifting, and the talent pipeline is thinning

Agentic workflows consume dramatically more compute than a simple chat interaction, and licensing models are changing mid-contract as vendors move from flat fees to consumption-based pricing. At the same time, early-career hiring into cybersecurity roles is contracting as AI absorbs entry-level tasks, which quietly erodes the pipeline of practitioners who’ll be needed to govern these systems in five years.[4]

What is AI security, exactly?

AI security covers three distinct jobs, and most conversations only mean one of them:

Using AI to strengthen security. Chat-style assistants for security operations centers, automated alert triage, and faster threat summarisation. This is “defending with AI.”

Securing how the organisation builds and uses AI. Every AI tool, agent, browser plugin, service identity, and Model Context Protocol (MCP) connection an organisation touches adds to what’s often called the AI attack surface. Securing it means applying the same rigor to AI assets that’s already standard for endpoints, identities, and cloud infrastructure.

Defending against AI-powered attacks. Attackers use generative AI the same way defenders do: to move faster, write more convincing phishing lures, and scale attacks that used to require more manual effort.

Gartner frames this as four impact areas CISOs need a plan for: defending with generative AI, being attacked by it, securing what the organisation builds with it, and governing how the organisation consumes it. Put together, this is the AI Trust, Risk and Security Management (AI TRiSM) framework, and it’s quickly becoming a baseline expectation rather than a nice-to-have.[2]

The risks that matter most right now include prompt injection (malicious instructions hidden in content that hijacks an AI agent’s behaviour), excessive agent permissions that let a tool take actions it was never meant to take, non-human identity abuse, compromised AI supply chains (a poisoned MCP server or plugin), and plain old shadow AI: tools nobody signed off on, running with nobody watching.

Gartner’s guidance on AI agent assurance breaks the response into five steps: discover every agent in the environment, treat agents as first-class identities within identity and access management, apply information governance to everything agents touch, add automated oversight (“guardian agents”) for continuous monitoring, and build feedback loops that let the whole system improve over time. It’s a sequence, not a checklist. Discovery has to come first, because it’s impossible to govern what hasn’t been found.[3]

Next steps: building an AI security program that keeps pace

1. Start with visibility, not policy. Before writing an acceptable-use policy, find out what’s actually running: AI-integrated SaaS applications, browser extensions, installed agents, and the service identities tied to them. An inventory is the prerequisite for everything else on this list.[3]

2. Bring security in at the start, not the end. Embed a lightweight security checkpoint into the AI adoption process itself, and create a pre-approved list of vetted AI tools so business teams can move quickly without bypassing security altogether. Where internal capacity is tight, shifting continuous monitoring to a managed detection and response partner frees the in-house team to focus on incident response, where their business context matters most.[1]

3. Treat AI agents as identities, not background processes. Every agent needs a unique, auditable identity, least-privilege access, and just-in-time permissions rather than standing access. Build in a process for retiring agents that are abandoned mid-experiment, which happens more often than most inventories admit.[3]

4. Extend data governance to everything an agent touches. Agents access, generate, and move data at a scale and speed manual reviews can’t match. Comprehensive, AI-aware data classification and monitoring needs to cover both structured and unstructured data, in transit and at rest, with acceptable-use violations escalated automatically rather than caught after the fact.[3]

5. Make the case to the board in terms it already uses. Link AI security spend to revenue protection, regulatory exposure, and customer trust rather than treating it as a standalone security line item. Distribute the cost across the functions actually deploying AI, since risk now originates well outside the security team, in marketing, product, and operations alike. Treat token and compute consumption the way FinOps treats cloud spend: with budgets, anomaly detection, and accountability per business unit.[4]

6. Build the talent pipeline deliberately. Reskilling internal staff into AI-oversight roles, rather than relying solely on hiring, is proving to be a real competitive advantage as the market for AI-fluent security talent tightens.[4]

 

Challenge  What’s actually happening  The practical fix 
No visibility into AI use  Shadow AI tools and agents run unmonitored across SaaS, browsers, and endpoints  Continuous, automated discovery covering installables, browser plugins, SaaS, and service identities 
Security involved too late  Business teams adopt AI tools before security reviews them  Lightweight checkpoints early in the adoption process, plus a pre-approved tool list 
Ungoverned AI agents and identities  Non-human identities outnumber human ones and a third are dormant  Register every agent as a first-class identity with least-privilege, time-limited access 
Board pressure outpacing resourcing  Executives push AI adoption faster than budget and talent allow  Tie security investment to revenue, regulatory, and trust outcomes the board already tracks 

Frequently asked questions 

What is AI security? 

AI security is the practice of protecting the AI systems an organisation uses and builds, the infrastructure behind them, and the business from attacks that use AI. It spans AI agents, SaaS tools, browser plugins, and the identities tied to all of them.[2]

Why is AI security a board-level issue now? 

Because AI adoption is expanding faster than governance, budget, or talent can support it, and boards are pushing for it regardless. Gartner projects generative AI will factor into 22% of cyberattacks and data leaks by 2028, making this a business risk, not just a technical one.[1,4] 

What’s the biggest AI security risk today? 

Shadow AI and ungoverned agents. Most organisations already suspect unsanctioned AI activity exists somewhere in their environment, and non-human identities now vastly outnumber human ones, often without matching oversight.[3]

Where should a company start with AI security? 

With discovery. Find out what AI tools, agents, and identities already exist before writing policy or buying tools. Visibility is the prerequisite for every other control.[3]

How is AI security different from traditional cybersecurity? 

It adds new categories of risk, like prompt injection, agent identity abuse, and AI supply-chain compromise, that don’t map cleanly onto existing endpoint or network controls. It requires extending existing identity, data, and detection programs to cover AI-specific assets, rather than building something entirely separate.[2] 

Where this leaves you 

AI isn’t a category that will eventually go away and become “just security” again, but it isn’t there yet either. Right now, the organisations managing it well are the ones treating visibility as step one and building identity, data, and oversight controls around what they find, rather than waiting for a perfect policy before they start.

Sources 

[1] Gartner, 3 Generative AI Security Red Flags for Midsize Enterprise CIOs, Patrick Long, Srishti Khanna, 2 May 2025.

[2] Gartner, 4 Ways Generative AI Will Impact CISOs and Their Teams,  Jeremy D’Hoinne,  Avivah Litan , Peter Firstbrook, 29 June 2023.

[3] Gartner, Act Now: Take These 5 Steps for AI Agent Assurance, Avivah Litan, Max Goss, Carlton Sapp, 21 January 2026 

[4] Forrester, Resetting Security’s AI Narrative With Boards And Executives, September 2026 

Blog post

Read our latest blogs

Industry Recognition

Endpoint Security

Certified Leader in AV-Comparatives’ Endpoint Prevention and Response

AV-Comparatives named WithSecure ‘Certified Leader’ for Endpoint Prevention and Response (EPR), ‘Advanced+ Performance’ for Windows, ‘Advanced Real-World Protection’ for Windows, ‘Approved Mac Security’ for MacOS and ‘Approved Mobile Security’ for Android.

Blog

AI Security Exposure Management Identity Security Proactive Security

Exposure Management That Keeps MSPs Ahead of Attackers

One workflow from exposure to containment. WithSecure Elements gives MSPs near real-time exposure management with one-click response across every customer.

Industry Recognition

Incident Response Managed Security

Among Notable Vendors in Cybersecurity Incident Response Services by Forrester

Forrester named WithSecure among Notable Vendors in the Forrester report, The Cybersecurity Incident Response Services Landscape, Q3 2026.