AI Agents Are the Biggest Security Headache for CISOs Right Now

A new survey of global security chiefs finds that controlling AI agents, which are software programs that act independently to complete tasks, has become the dominant worry in corporate security, far outpacing every other concern on the list.

ThreatVectr Newsdesk· Editor: Lee Brown· 3 min read
AI security system with digital shield
Share

Key points

  • 78% of chief information security officers (CISOs, the executives in charge of a company's digital security) named AI and agent security as their biggest pain point, exactly twice the rate of the second-place concern at 39%.
  • Tim Brown, CISO at venture capital firm Team8, says the two core problems are outdated security habits and AI agents that do unexpected things.
  • The findings come from Team8's annual survey of its invitation-only CISO Village, a global community of senior security leaders from large enterprises.

Security leaders are scrambling, and most of them will tell you the thing keeping them up at night is not a hacker with a crowbar. It's software they built themselves.

Team8, a venture capital firm focused on enterprise technology and cybersecurity, publishes an annual survey drawn from its CISO Village, a private network of senior security executives at major companies worldwide. This year's results, discussed with SecurityWeek, show AI has eaten the agenda whole.

Why are AI agents so hard to control?

AI agents are software programs that work on their own to complete a goal, browsing the internet, reading files, sending emails, without a human approving each step. The problem is that people are not precise writers, and agents do exactly what they think they have been told.

Tim Brown put it plainly: "An AI agent is not just another employee. It's a very resourceful employee that will do whatever it takes to accomplish the task it believes it has been given."

His example is clarifying. Tell an agent to gather background information on a company from "whatever it can find," and it may search a live production system on the internet instead of the safe test environment you assumed it would use. No malicious code was written. No rules were broken. The agent simply followed its instructions to the letter.

The fix, Brown says, is building guardrails directly into how agents are created: hard limits on where an agent can go and what data it can touch. Nail those limits before the agent is turned loose and a misunderstood instruction can't cause real damage. Leave them loose, and the only guaranteed safe option is, as Brown put it, "I unplug it, I throw it into the ocean. Then it's safe. Useless, but safe."

What about ordinary security habits?

Standard defences are no longer enough. Brown's second warning is that security advice organisations have followed for a decade or two, things like multi-factor authentication (MFA, where you confirm your identity with a second device after entering a password) and firewalls (software barriers that filter internet traffic), no longer provide the protection they once did.

AI gives attackers new ways to find and exploit weaknesses faster than traditional defences were designed to handle. The corporate mindset around what "good enough" security looks like needs to change.

Concern CISOs citing it as top pain point
AI and agent security 78%
Second-ranked concern 39%

Brown's practical recommendation for dealing with both problems is straightforward: share more. Security leaders who have already wrestled with a rogue agent or an AI-enabled attack have knowledge that could save another company weeks of painful discovery.

"Let's share more often," he said. "Why do I have to learn everything from scratch when my friend in company X has already done this?"

On 3 September we reported that agentic AI may have quietly made zero-trust architectures obsolete. This survey puts numbers behind that concern. The tooling for building AI agents is now available to any employee with a laptop, through products like Claude Code and Cursor. Security teams are not always in the room when those agents get created. The gap between how fast these tools spread and how fast controls catch up is where the real risk lives.

© 2026 Threat Vectr