Stay current to protect your environment with F5 Hardened Releases.Learn more

Agentic AI changes the key questions for CISOs

Industry Trends | September 22, 2026

For CISOs today, “Are we secure?” is no longer the question. Exploding AI use has changed the game.

Our 2026 F5 State of Application Security Strategy eBook offers many valuable insights about how security is—and isn’t—keeping pace with AI implementations. One statistic from our research that stood out to me relates to the proliferation of agentic AI.

As AI agents continue to multiply within the enterprise, more than three-quarters (77%) of organizations report that managing the explosion of non-human identities—which includes controlling their access and ensuring they can’t be exploited—is becoming a significant challenge.

Indeed, it's something every organization needs to address, whether or not they’re all-in on AI. With nearly everyone able to build their own AI agents and deploy multiple agents that collaborate, any CISO who doesn’t understand what all these agents are doing doesn’t stand a chance. Accordingly, CISOs increasingly must ask and answer these questions: “What does this AI know?, What is the AI authorized to do?, and Are we able to stop it if we need to?”

According to F5 research, 77% of organizations expect significant challenges with agentic AI, including credential theft, privilege abuse, and impersonation.



The pat answer is “better visibility and effective governance.” It’s impossible to have security or control without runtime-level visibility across every agent accessing models, interacting with data, and triggering workflows. This is true regardless of where you’re running your apps, whether it’s in on-premises data centers or hybrid multicloud deployments.

That’s why shadow AI is a common topic today. With nearly everyone able to build their own AI agents and deploy multiple agents that collaborate, any CISO without the ability to shine a light into those shadows and understand what every agent is doing doesn’t stand a chance.

Expanding—or violating—the trust boundary?

But even if the CISO can ferret out every agent at work for the organization—hardly a given, since non-human identities are quickly outnumbering human identities in the org chart by a factor of three—the challenge of governance is far from straightforward.

First, innovation tends to move faster than control. The people who deal in risk and regulatory compliance typically play catch-up. And as the old saying goes, just because we can do something doesn’t mean that we ought to do it. In Before deploying a specific AI agent, organizations need to consider whether the benefits to the business are worth the work required to secure it.

Second, agents are being built with certain intentions and permissions to accommodate them. They’re accessing data, making decisions, invoking APIs, triggering business processes, and communicating with customers and other agents in accordance with their purpose.

Every one of those non-human identities expands the enterprise’s trust boundary and threat landscape. Therefore, their privileges need to be protected with the same fervor we use for human identities—and maybe even more, since it might be very difficult for security staff to recognize an attacker who hijacks an agentic identity and elevates privileges. That attacker would still look like an authorized user, especially if their behavior remains within certain parameters. That’s where probabilistic security models that focus on behavior may help.

Unfortunately, many organizations haven’t completely figured this out yet. Maturity levels vary widely. But the business implications of a failure, whether regulatory, reputational, or competitive, could be existential. If an uncontrolled agent or agentic identity leads to a data breach, the impact on customer trust or stock price could be tough to recover from.

Finally, we know from several recent, high-profile examples such as the Hugging Face incident with OpenAI that agents frequently do things their handlers didn’t intend. Agent persistence when meeting roadblocks sometimes means they’ll keep trying until they find a completely unanticipated workaround. They’re relentless in doing what they’re programmed to do even in the face of instructions to not do particular things. When the blocker is a guardrail put into place to manage risks or even specifically to stop the agent under certain conditions, that’s a security problem.

The AI developers - can remain in control, not only by making sure everything is configured correctly but also by building fail-safes into our governance systems. A human in the loop usually isn’t enough. Governance must start long before the first prompt is ever executed. The business owners are engaged in the process to ensure their agents execute as desired, and outcomes have traceability and decisions can be explained.

Accountability is often missing

I believe governance starts with human accountability, yet unfortunately, this topic is missing from a lot of discussions. The thing I worry about most, and that I hear other CISOs worrying about, is, “Who is accountable when the model infers something it shouldn’t, or the agent or a series of agents does something we didn’t intend?” Because by default, accountability for those mistakes will lie at the feet of the CISO.

Making CISOs solely accountable or the default owner of the risks isn’t the right answer. A shared accountability model must be adopted. The person driving use of the agent should own accountability, too, because they’re the one who understands the agent’s intention and potential impact on the business both when the agent works well and should it run amok.

I’m already starting to hear about this problem among the CISOs I speak with regularly. They can’t necessarily make determinations about agent intentions, expirations, or the ways they could go wrong. When we’re asked to do so anyway, too often we become “the Office of No,” and that’s not a position most CISOs want. AI governance then risks devolving into a hollow compliance checklist rather than being an operational discipline driven by business strategy.

Instead, CISOs need tools that can help them engage their business leaders in accountability for what every agent should, can, and can’t do. If an AI agent can act on behalf of your organization, someone in the organization must be accountable for it. Then CISOs can be the architects of the solutions, not merely enforcers.

Governance requires good asset management

At heart, governance is partly an asset management issue, whether that asset is a high-profile AI agent known and used by everyone in the company or an unsanctioned non-human identity adopted in the shadows by an employee striving for more productivity.

As with any asset, the company needs to manage when every agent is deployed, who owns responsibility for it, who benefits from it (and at what cost), and when it needs to be upgraded, replaced, or shut down.

Orphaned AI agents can become easy targets for attacks. That’s why it’s critical to establish accountability, by name, for every agent. One individual might have accountability for thousands of agents, or accountability could be shared across C-level roles. But somebody within the organization who understands the business case for those agents must be accountable and help erect the guardrails to keep them on track. Explicit identity, authorization, continuous monitoring, and lifecycle management are all important.

For CISOs, the immediate work is practical: inventory every agentic identity, assign a named business owner, define what each agent is allowed to do, monitor behavior continuously, and establish a clear retirement path. Without those basics, organizations may have AI activity at scale without the accountability, visibility, or control needed to manage risk.

Of course, governance of agentic identities is only one of the big challenges CISOs face today. To learn more about security in the AI era, I highly recommend you check out our 2026 F5 State of Application Security Strategy eBook.

Share

About the Author

Sean Murphy
Sean MurphyField CISO for North America | F5

More blogs by Sean Murphy

Related Blog Posts

Securing the new control points in the AI journey
Industry Trends | 07/01/2026

Securing the new control points in the AI journey

AI architecture is fundamentally different than traditional IT environments and requires a different security strategy to protect critical AI workloads.

The patch window has closed. Here is how F5 is built for what comes next.
Industry Trends | 04/27/2026

The patch window has closed. Here is how F5 is built for what comes next.

As AI models have changed software security, the industry needs to adapt.

Best practices for optimizing AI infrastructure at scale
Industry Trends | 01/21/2026

Best practices for optimizing AI infrastructure at scale

Optimizing AI infrastructure isn’t about chasing peak performance benchmarks. It’s about designing for stability, resiliency, security, and operational clarity

Datos Insights: Securing APIs and multicloud in financial services
Industry Trends | 12/23/2025

Datos Insights: Securing APIs and multicloud in financial services

New threat analysis from Datos Insights highlights actionable recommendations for API and web application security in the financial services sector

Secrets to scaling AI-ready, secure SaaS
Industry Trends | 12/12/2025

Secrets to scaling AI-ready, secure SaaS

Learn how secure SaaS scales with application delivery, security, observability, and XOps.

How AI inference changes application delivery
Industry Trends | 11/19/2025

How AI inference changes application delivery

Learn how AI inference reshapes application delivery by redefining performance, availability, and reliability, and why traditional approaches no longer suffice.