Dive Brief:
- AI agents remain a major cybersecurity risk for businesses, with 81% of CISOs worrying that their AI systems aren’t properly governed, according to a report Okta published on Wednesday.
- Only 47% of companies Okta surveyed said they knew all the AI agents on their networks, and only 46% reported controlling those agents’ access to corporate data.
- Okta’s findings highlight a complicated and dangerous environment in which companies aren’t properly balancing the risks and benefits of agentic AI.
Dive Insight:
Security leaders face immense challenges in governing their companies’ use of AI, and the Okta report catalogs several of those challenges and describes how widespread they are.
Shadow AI is one of the biggest challenges, as users rush to adopt helpful tools without getting permission or even alerting security teams. The resulting visibility gaps and increased risk exposure make it harder for CISOs and their staff to defend networks. In Okta’s survey, 68% of CISOs reported seeing at least some unauthorized AI use.
When it comes to authorized AI tools, companies aren’t doing a very good job of tightly controlling what those tools can do and what they can access. Roughly one-fifth of organizations reported letting AI agents access network resources with shared credentials or highly permissioned agent-specific accounts, both of which represent weak boundaries around agents’ behavior. A similar share of respondents said they allowed the teams that created AI agents to manage them on their own. Only one-quarter of respondents said they managed AI agents through a dedicated access framework.
Leadership alignment is another major challenge facing security leaders as they try to manage AI sprawl. Fewer than one-third of CISOs told Okta that they felt “fully aligned” with their leadership, including CEOs and boards of directors, when it came to the amount of risk they should be taking with AI. In the U.S., only 12% of CISOs said so.
Part of the problem is that many executives still see security controls on AI tools as an impediment to business growth, rather than a protector of corporate wellbeing. According to the survey, fewer than half of CISOs believe that their boards consider AI security a business enabler.
Even as they try to protect their own AI systems, CISOs remain deeply worried about how AI is helping adversaries conduct attacks. More than half (57%) of security leaders in the global survey said they were extremely or very worried about AI-driven breaches; the number was much higher (84%) in the U.S. AI-enhanced phishing attacks, malicious AI agents and authentication-bypassing deepfakes topped the list of security executives’ fears.
Okta’s report is based on a survey of 306 CISOs and other cybersecurity executives in the U.S., the U.K., Japan, Germany, Canada and France