top of page
James F. Kenefick Website Icon

JAMES F.

   KENEFICK

Agentic AI Makes Cybersecurity More Urgent, Not Less

  • 11 hours ago
  • 6 min read

Boards spent the last two years asking whether generative AI would deliver a return. In 2026 the question has changed. Agentic AI, systems that plan, decide, and act across enterprise tools with limited human supervision, is no longer a pilot conversation. Gartner's 2026 Hype Cycle for Agentic AI projects that 40 percent of enterprise applications will embed task-specific AI agents by the end of this year, up from under 5 percent in 2025, and its 2026 CIO survey found that 17 percent of organizations have already deployed agents while more than 60 percent expect to within two years, the most aggressive adoption curve of any technology the survey has measured.


The instinct in many boardrooms is to treat this as a productivity story, agents that book meetings, triage tickets, and close the books faster. That instinct is not wrong, but it is incomplete. Every agent that gains the authority to act on a system is also a new actor with credentials, permissions, and a decision history that someone has to secure and someone has to answer for. As autonomy scales, agentic AI cybersecurity risk does not shrink. It multiplies.


Executives in a modern boardroom reviewing a glowing digital network display representing AI agent identity and access governance.

Why Agentic AI Cybersecurity Risk Is Rising


The economics already show it. IBM's 2026 Cost of a Data Breach Report, produced with the Ponemon Institute, puts the global average breach cost at a record 4.99 million dollars, a 12 percent increase over the prior year, and finds that AI-driven attacks rose 56 percent in the same period. Among organizations that suffered an AI-related breach, 92 percent had no proper access controls on the AI systems involved. That is not a model quality problem. It is a governance and identity problem, and it is showing up on the income statement.


The World Economic Forum's Global Cybersecurity Outlook 2026, developed with Accenture, reinforces the point from the boardroom side. Ninety-four percent of surveyed leaders name AI as the most significant driver of cybersecurity change this year, and 87 percent identified AI-related vulnerabilities as the fastest-growing risk category of the past year. Executives are not confused about where the risk is moving. The harder question is whether governance is moving with it. McKinsey's 2026 AI Trust Maturity Survey found that only about one-third of organizations report governance maturity at level three or higher, even as nearly two-thirds of respondents cite security and risk concerns as the top barrier to scaling agentic AI further. Capability is outrunning control, and the gap is where cost accumulates.


The Core Framework: Identity Becomes the New Perimeter


For twenty years, enterprise security was largely a story about protecting a network boundary and the humans who logged into it. Agentic AI breaks that model because agents are non-human identities that request access, invoke tools, and accumulate privileges on their own timeline. NIST's National Cybersecurity Center of Excellence made this explicit in its February 2026 concept paper on software and AI agent identity and authorization, which argues that existing identity standards, including OAuth, OpenID Connect, and SPIFFE, need to be adapted rather than replaced, but that agents must be treated as first-class, auditable identities with a named human owner rather than as generic service accounts.


That reframing carries four practical implications for how an agentic AI program should be architected, and each maps to a decision the executive team, not just IT, needs to own.

  1. Decision authority. Every agent needs an explicit, documented scope of what it is permitted to decide versus what it must escalate. Ambiguity here is the single most common source of the accountability failures boards later have to explain.

  2. Workflow autonomy and escalation. Autonomy should be granted in increments tied to demonstrated reliability, with clear escalation paths back to a human when confidence drops or the action is high stakes.

  3. Auditability. Every agent action needs to be attributable, after the fact, to a specific non-human identity and the human authority that delegated its permissions. Shared credentials defeat this by design.

  4. Business ownership. Someone in the business, not only in security, has to own each agent's outcomes. IBM's identity management guidance for agentic AI frames this as the shift from identity as access to identity as authority, and it is the framing boards should adopt.


Microsoft's security team made a similar case at its RSAC 2026 briefing, noting that agents are becoming a new class of insider risk precisely because they can be turned into what the company calls double agents when compromised, acting with legitimate credentials in illegitimate ways. The company's response, giving every agent its own identity inside existing identity infrastructure rather than a shared service account, reflects the same principle NIST is standardizing: agents are identities, and identities need lifecycle management, least privilege, and continuous verification, not a one-time approval.


Governance: What the Board Needs to Ask


Board oversight of agentic AI comes down to four questions, and they are the same four questions that have always anchored good cybersecurity governance, applied to a faster-moving asset class.


What is the board's role? It is to require that every agentic deployment has a named accountable owner, a documented permission scope, and a kill switch, before it is treated as a scaling decision rather than a pilot.


What risks exist? Beyond the model's accuracy, the material risks are credential sprawl, privilege escalation without review, and the loss of a clean audit trail when an agent's actions cannot be separated from a human's. IBM found that model inversion and prompt injection attacks, both tied to how agents access and expose data, cost an average of 6.07 million and 5.89 million dollars per breach respectively, well above the global average.


What metrics matter? Time to detect and contain an AI-related incident, the percentage of agents with a documented human owner, and the share of privileged access that is just-in-time rather than standing. IBM's report found that organizations making extensive use of security AI and automation cut breach costs by 1.93 million dollars and shortened breach lifecycles by 65 days, which is the kind of metric a board can track quarter over quarter.


What oversight is required? Regular reporting on agent inventory, not just tool inventory, and a governance cadence that keeps pace with deployment rather than trailing it by a quarter, which McKinsey's research shows is currently the norm. Cyber insurance and compliance posture follow directly from this. Underwriters and regulators are increasingly asking the same identity and audit questions the NIST framework raises, and organizations with a clean answer on agent ownership and access scope are better positioned on both fronts, with faster recovery when an incident occurs.


Executive Actions


Three moves separate organizations that scale agentic AI safely from those that accumulate risk while they scale. First, inventory every agent in production or pilot today and assign a named human owner to each one, not a department. Second, require least privilege and just-in-time credentials for agent access by default, treating standing permissions as an exception that requires sign-off. Third, put agentic AI governance on the board's risk committee agenda on a recurring basis, not as a one-time briefing, since the technology, the regulatory landscape, and the threat actors targeting it are all moving quarter to quarter.

Organizations working through this transition are the ones served well by pairing operational discipline with technical controls, since governance gaps are as often a process failure as a technology gap. Firms that have already built AI readiness into their operating model tend to move through this faster because the accountability structures already exist.


Agentic AI cybersecurity risk is not a reason to slow adoption. It is a reason to adopt with the same discipline that mature organizations already apply to financial controls and physical security. The boards and executive teams that treat agent identity, permission scope, and auditability as governance fundamentals from the outset will scale faster and more safely than those that treat security as a follow-on step. The technology has changed what an identity is. The obligations of good governance have not.


For organizations building or strengthening this discipline, a cybersecurity assessment is the most direct way to see where agent identity and access controls stand today, and a broader review of managed cybersecurity services can show what a mature program looks like in practice. Incident readiness planning and SOC 2 aligned compliance work are the next layer, and both matter more, not less, as agents take on more of the operational load. Executive teams that want a structured way to bring this to their board can also draw on Working Excellence's operating model guidance and on further reading in the BetterWorld Technology resource library and the broader James F. Kenefick blog archive for related governance frameworks, along with a look at why BetterWorld Technology approaches security this way and James Kenefick's perspective on executive leadership in the AI era.

Comments


bottom of page