The defensive discipline at the intersection of two simultaneous expansions: AI deployed inside the enterprise (shadow AI, agentic workflows, new data pipelines, non-human identities) and AI deployed against the enterprise by attackers (voice phishing at scale, deepfake CEO fraud, AI-accelerated ransomware, prompt injection, model supply-chain compromise). Covers the CISO-level reframe that AI risk does not fit traditional software risk models, the control floor for mid-market companies without dedicated security staff, and the governance-as-defense posture that IBM IBV / Palo Alto Networks research shows differentiates the 24% pulling ahead from the 28% falling behind.

The asymmetric fact is that AI has collapsed attacker cost while expanding defender attack surface. Voice phishing surged 442% H1→H2 2024 (CrowdStrike Global Threat Report 2025). Average eCrime breakout time is 29 minutes, fastest 27 seconds (CrowdStrike 2026 Global Threat Report). Ransomware appears in 88% of breaches at organizations with limited security maturity (Verizon 2025 DBIR, n=22,052 incidents). Meanwhile, IBM’s Cost of a Data Breach 2025 (n=600) finds 97% of organizations breached via AI lacked proper access controls, and shadow AI breaches add $670K to average incident cost. The collision point is the mid-market: SMBs are targeted nearly 4x more than large enterprises and typically have neither dedicated security teams nor the AI governance maturity to track both fronts.

Why this matters to mid-market buyers

  • Mid-market companies are inside a two-front war that Fortune 500 firms largely avoid. Large enterprises have staffed security teams tracking both internal AI expansion and external AI-enabled attacks. 200-2,000 person companies usually have neither, yet face nearly 4x the attack rate. This is the population where the attack-rate and governance-maturity curves diverge most.
  • Non-human AI identities now outnumber human users 82-to-1 in enterprise networks, and 92% of CISOs lack confidence that legacy IAM tools can govern them (CyberArk 2026; Saviynt/Cybersecurity Insiders n=235, 2026). The identity perimeter that protected the last decade’s enterprise stack does not scale to agentic workloads.
  • Cyber insurance carriers (WR Berkley, AIG, Great American, Hiscox, AXA XL) have added AI-specific questionnaire sections to 2026 renewals. The CISO or CFO who last renewed with a standard checklist will encounter five new questions on AI tool inventory, acceptable use, data exposure, human oversight, and AI-specific incident response. Companies that cannot answer face sublimits, exclusions, or declination; companies that can answer lock in flat-to-negative renewals versus 15-20% premium increases (S&P Global Ratings; Forrester 2025-2026).
  • The mid-market security floor is not complicated. The 10-control minimum mapped to NIST AI RMF, OWASP LLM Top 10, and CIS Controls v8.1 costs $15K-$45K and takes two weeks to implement. Organizations that deploy it reduce data leakage incidents by 46% (Practical DevSecOps 2026) and save $1.9M per breach with 80-day shorter incident lifecycles (IBM 2025).

Practitioner voices (pillar 13)

“Security is going to be a prerequisite for successful adoption of AI. Because if people don’t trust these systems, they’re not gonna use them.” — Jeetu Patel, President and Chief Product Officer, Cisco (Me, Myself, and AI, October 14, 2025). Source: research/13-multimodal-sources/me-myself-and-ai/2025-10-14-never-fight-a-megatrend-ciscos-jeetu-patel.md

“One of the things you see with AI, you see some of the problems with AI is that we give them too much power. It’d be like you giving Alexa as an AI agent or Siri as an AI agent access to your bank account. You wouldn’t do that, right? But that’s what companies are doing with some of their AI agents. They’re giving them way too much control, authority, too much access to protected data.” — Mike Morris, Former FBI Cybersecurity Agent, Western Governors University (Beyond the Pilot, October 13, 2025). Source: research/13-multimodal-sources/beyond-the-pilot/2025-10-13-venturebeat-in-conversation-fbi-veterans-on-ai-cyber-threats.md

“A lot of times companies, I mean, they can’t afford to build it. So then they use a lot of the platforms that are out there and they already have trained models out there. The question becomes, how do you know how was it trained? Who’s testing that to make sure there’s not a backdoor or malware put into it? And there have been multiple cases now with multiple platforms that offer these tools where hackers are putting malware out on it.” — Mike Morris, Former FBI Cybersecurity Agent, Western Governors University (Beyond the Pilot, October 13, 2025). Source: research/13-multimodal-sources/beyond-the-pilot/2025-10-13-venturebeat-in-conversation-fbi-veterans-on-ai-cyber-threats.md

“We’re looking at it from a few angles. One, from a pure security standpoint, how can this help me and my team do our jobs more efficiently, more effectively, and connect with our internal stakeholders.” — Tomas Maldonado, Chief Information Security Officer, NFL (Beyond the Pilot / VentureBeat, September 2025). Source: research/13-multimodal-sources/beyond-the-pilot/2025-09-15-venturebeat-in-conversation-inside-the-super-bowls-cyber-war.md

Maldonado is describing the CISO’s dual mandate

Beyond the Pilot — Johan Gerber, EVP Security Solutions, Mastercard (February 2026)

Mastercard operates at a scale that tests every AI security claim in production: 160 billion transactions per year, peaking at 70,000 transactions per second at holiday periods. DI Pro (deep learning, recurrent neural networks) makes fraud decisions in under 300 milliseconds across this volume — the most consequential real-time AI decisioning deployment in financial services.

“Many people don’t like it when I say this, but this is when security professionals view themselves as bodyguards, not wardens. It’s not our responsibility to lock things and make sure they don’t happen. It’s our responsibility to make sure they can get out there and grow, but with security and design around them.” — Johan Gerber, EVP of Security Solutions, Mastercard (Beyond the Pilot, February 4, 2026). Source: research/13-multimodal-sources/beyond-the-pilot/2026-02-04-mastercards-160-billion-transactions-ais-biggest-test.md

The operational implication for mid-market security leaders: the defender posture at scale is not restriction but designed permission — security architecture that enables AI adoption by defining safe operating boundaries rather than blocking deployment. Mastercard’s “bodyguard not warden” framing pairs with AISI UK’s finding that AI delivers zero productivity gain on unstructured planning tasks but large gains on structured information tasks — the security function is defining what counts as structured and safe, not deciding whether the business uses AI. that mid-market buyers face: AI-as-risk (threats incoming) and AI-as-capability (security team efficiency). A lean security team that cannot afford to add analysts has the same first question — how does AI extend what we already have?

Microsoft Security Copilot Agent RCTs: First Causal Evidence in SOC (Bono et al., November 2025)

Two randomized controlled trials measuring AI agent impact on specific security tasks — currently the most causally rigorous evidence in security operations productivity.

  • Phishing Triage Agent RCT (arXiv:2511.13860, n=167 professional analysts): 6.5× true positives per analyst minute vs. control (ground truth); 3.1× under 80% accuracy assumption. +77% F1 accuracy. Three-arm design isolated queue prioritization (79–84% of gain) from verdict labels (13–22%). Analysts spent 53% more time on malicious emails — reallocating effort rather than rubber-stamping.
  • Conditional Access Optimization Agent RCT (arXiv:2511.13865, n=162 identity admins): +48% accuracy, −43% task time across four Conditional Access policy tasks. Largest single effect: Zero-Trust baseline gap detection +204% accuracy (F1 from 0.15 → 0.46). Simulated Entra environment; Upwork participant pool.
  • Caveat: Both authored by Microsoft employees; participants from freelance marketplace (not enterprise SOC staff); one-session studies. No independent replication yet published. Results represent best-case, not median-case, enterprise deployment.
  • What this adds: These are the first RCTs of AI agents on defined security tasks. They establish the causal mechanism that surveys and cost-benefit analyses assume: agents prioritize and triage; humans review and decide. The 79–84% attribution to queue prioritization (not verdict accuracy) is the operationally important finding — it means agent sequencing value exceeds agent classification accuracy.

Source: research/06-security-frontier/microsoft-security-copilot-agent-rcts-2025.md


AI in the SOC: Independent ROI Evidence (Pass 593, April 2026)

The most business-case-ready evidence for AI in security operations comes from three sources with different credibility levels:

  • IBM/Ponemon Cost of a Data Breach 2025 (n=600, Tier 2): Organizations using AI/automation extensively average $3.62M per breach vs. $5.52M without — a $1.9M per-incident savings. Shadow AI adds $670K to breach cost. This is the only large-n independent financial benchmark.
  • Microsoft Research (arXiv:2411.03116, n=177 organizations, Nov 2024, Tier 3): Difference-in-differences analysis with propensity score matching found 30.13% MTTR reduction at month 3 (p=0.0487). Not causal — selection bias acknowledged by authors. Current models likely stronger, but this is the methodology floor.
  • Forrester TEI studies (vendor-commissioned): Palo Alto Cortex XSIAM 257% ROI / 85% MTTR reduction; ReliaQuest GreyMatter 224% ROI / 50% MTTR reduction. Composite model from selected customers — directionally useful, not precision instruments.

The structural driver: 4.8 million unfilled cybersecurity roles globally (ISC2, n=16,000+, 2025); 40% of alerts uninvestigated; 61% of teams ignored critical alerts. Mid-market companies running 1-3 analyst teams cannot hire their way to adequate coverage. AI that automates tier-1 triage (85-95% of alerts) is the structural answer, not a productivity add-on.

Source: research/06-security-frontier/soc-ai-automation-roi-benchmarks-2025-2026.md

“The success of those operations was actually predicted by the success of all the trainings ahead of time… as we prepare for this combat that we’re going to have with our adversaries, the success is not gained, won or lost in the moment of the conflict. The success is going to be gained in the planning and the practicing of that plan well ahead of time.” — Paul Bingham, Former FBI Cybersecurity Agent, Western Governors University (Beyond the Pilot, October 13, 2025). Source: research/13-multimodal-sources/beyond-the-pilot/2025-10-13-venturebeat-in-conversation-fbi-veterans-on-ai-cyber-threats.md

WEF/KPMG “Empowering Defenders: AI for Cybersecurity” (May 2026, 84 orgs/15 industries)

The WEF/KPMG white paper (May 2026) synthesizes case studies from 105 representatives across 84 organizations in 15 industries — the broadest multi-org treatment of AI in defensive security published in the first half of 2026.

  • 77% of organizations now use AI in cybersecurity, but depth varies sharply by size — larger firms lead; mid-market companies and NGOs lag on financial constraints, skills, and data maturity.
  • $1.9 million breach cost reduction and ~80 day shorter breach lifecycle for organizations using AI extensively — corroborates IBM Cost of a Data Breach 2025 (same underlying dataset, different analysis layer).
  • 88% of security teams report time savings from AI; but 54% identify talent shortage as the primary adoption barrier, and 76% of cybersecurity professionals reported exhaustion in 2025.
  • AI use case concentration: phishing detection (52%), intrusion/anomaly detection (46%), user behavior analytics (40%) — all reactive/detection functions. Governance and recovery functions are underdeployed.
  • Agentic AI is the next wave: 88% of enterprises are investing in AI agents; 92% of tech executives say AI agent management will be a non-negotiable security skill within five years. The governance challenge — pre-authorization frameworks, audit trails, human escalation triggers — is not yet solved.
  • Skills atrophy warning: AI automation of routine analyst tasks reduces hands-on practice opportunities, potentially eroding the judgment needed when automation fails.

Source: research/06-security-frontier/wef-kpmg-ai-cybersecurity-2026.md

EY Technology Pulse Poll: Cybersecurity Is the #1 AI-Era Investment (Mar 4, 2026, n=500)

  • 79% plan to increase cybersecurity investment — the top-ranked line item, ahead of cloud (67%), AI-specific talent (65%), and compute/infrastructure (62%). The top four investment categories are all about absorbing the risk surface that autonomous AI creates; offensive investment (back-office AI for productivity gains) is #5 at 56%. The ratio cuts against “AI drives top-line growth” framing and toward “AI expands attack surface, defense funding catches up.”
  • Geopolitics moves into the CISO portfolio: 62% flag geopolitical tensions and sovereign AI mandates as active concerns. Pairs with IBM IBV 5 Trends 2026 (n=1,028 C-suite) where 93% must factor AI sovereignty into 2026 strategy. The EY number is the tech-sector subset — a defensible floor for mid-market planning.
  • The 45% confirmed/suspected data-leak and 39% IP-leak incidence rates are a lower bound for what breach-cost models (IBM Cost of a Data Breach 2025, n=600) already price — shadow AI adds $670K to average breach cost, 97% of AI-breached organizations lacked proper access controls. The EY prevalence data converts those per-incident numbers into an annual-exposure estimate a CFO can defend.
  • The single-sentence board framing: “EY’s Technology Pulse Poll, n=500 US tech-industry leaders at 5,000±employee firms, finds 79% increasing cybersecurity spend, 52% of department AI ungoverned, 45% confirmed/suspected sensitive-data leaks via unauthorized AI tools. If that’s what the governance-resourced cohort reports, our baseline is above it, not below.”

Source: research/04-consulting-firms/ey-autonomous-ai-tech-pulse-2026.md

Forrester “The AI CISO” (Amy DeMartine, Apr 9, 2026)

  • Names the CISO role redefinition the same week Forrester named the CIO’s (Moccia, Apr 9, 2026): the job shifts from “protector of systems” to “provider of trust and assurance” over autonomous AI outcomes.
  • Key driver quantified: 56% of generative AI decision-makers call agentic sprawl a current challenge (Forrester Q4 2025 AI Pulse Survey). The problem is present-tense, not forecast.
  • Three immediate CISO actions: (1) map how the business actually delivers value end-to-end using existing BCP/operational-resilience programs as the starting substrate; (2) define the future security org — the “trust and assurance” function — and start reskilling through AI experimentation rather than certification curricula; (3) CISO personally uses AI to automate their own reporting/analysis to build the governance instincts that cannot be delegated.
  • Explicit personal-risk framing: “In many enterprises, that accountability will land squarely with the CISO, making trust and assurance not just a capability gap but a personal risk.” Regulatory accountability converges on the CISO across third-party AI supply chains.
  • Triangulates with Forrester AI CIO (Moccia, Apr 9), Gartner assistive-AI-abandonment (Apr 2), McKinsey AI Transformation Manifesto (Apr 7), Anthropic Trustworthy Agents (Apr 9), and IBM IBV + Palo Alto Networks n=1,000 (Mar 22) — six institutional artifacts in a six-week window describing the same security operating-model shift.

Source: research/04-consulting-firms/forrester-ciso-ai-driven-future-2026.md

Forrester “2026 Really Is This Risky: Our Top Recommendations For CISOs” (Burn + Pollard, Mar 4, 2026)

  • The tactical 2026 security-program playbook companion to DeMartine’s CISO role-redefinition POV above. Burn (Principal Analyst) and Pollard (VP, Principal Analyst) lead Forrester’s Security & Risk practice; this is the public preview of the client-gated Top Recommendations For Your Security Program, 2026 report (4 of 12 recommendations visible).
  • Thesis: “Economic pressure, geopolitical instability, accelerating artificial intelligence adoption, and renewed technology consolidation have turned volatility into a structural condition rather than a temporary disruption.” Programs designed for periodic disruption are exposed when all four assumptions break simultaneously.
  • Four themes, one representative recommendation each: (1) Budget dynamics — shift AI security costs out of the security budget and into enterprise AI investments; AI security funded as a business cost that scales with adoption, not as a CISO tax. (2) AI-driven disruption — identify, assess, and socialize AI risk; “you cannot govern what you cannot inventory or explain”; embed AI risk into existing governance processes, not standalone ethics committees. (3) Shifting security-tech power — avoid single-platform dependency; demand vendor accountability; plan for scenarios where security tooling itself is unavailable or compromised. (4) Geopolitical risk — rehearse regional cloud isolation, supplier compromise, and service-shutdown decisions tied to real business dependencies; “the goal is not to predict the next disruption perfectly but to ensure that when it arrives, decision-making is deliberate rather than reactive.”
  • Highest-leverage recommendation for mid-market CISOs is #1 — budget restructure. Every other recommendation assumes the security program has room to fund it; when AI security is a line item inside the security budget, every new AI deployment the business ships cannibalizes a foundational control the CISO already paid for. The fix is a CFO conversation, not a security-architecture change.
  • Pairs with DeMartine The AI CISO (role-redefinition) + MIT CISR Minimum Viable Governance (FinCo governance-paralysis failure mode the “socialize AI risk” recommendation exists to prevent) + IBM IBV 5 Trends for 2026 (93% of executives must factor AI sovereignty into 2026 strategy — the executive strategic context above the scenario-planning recommendation).

Source: research/06-security-frontier/forrester-ciso-2026-recommendations.md

Anthropic Project Glasswing + Claude Mythos Preview (Apr 7–9, 2026)

  • First first-party-vendor autonomous-offensive-AI empirical anchor in the corpus. Anthropic announced Project Glasswing — a 12-partner industry program (AWS, Anthropic, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, Linux Foundation, Microsoft, NVIDIA, Palo Alto Networks) + 40+ additional orgs + $100M Mythos Preview usage credits + $4M to Alpha-Omega/OpenSSF/Apache — built around a non-public Claude variant that autonomously discovers and exploits software vulnerabilities.
  • The independently-verified anchor: CVE-2026-4747, a 17-year-old stack buffer overflow in FreeBSD NFSv4 authentication. Mythos found it, chained six sequential RPC requests, split a 20-gadget ROP chain across packets, and achieved unauthenticated remote root access with no human direction after the initial prompt. This is the lone CVE VulnCheck’s Patrick Garrity could directly tie to the initiative — separates verified capability from marketing.
  • The step-change is autonomous exploit development, not discovery. Opus 4.6 achieved near-0% autonomous exploit success; Mythos Preview produced working exploits in 181 of several hundred Firefox vulnerability attempts. OSS-Fuzz benchmark: 595 tier-1/2 crashes + 10 control-flow hijacks vs. ~250 total for Opus 4.6. Security firm Aisle replicated the discovery results using older public models — so the discovery advance is smaller than presented; the exploitation advance is real.
  • The economic disclosure is the CISO operational signal: OpenBSD research <$20K across 1,000 runs → dozens of findings; FFmpeg ~$10K → multiple codec vulns; individual breakthrough exploits $50–$2,000. A ransomware affiliate can now afford to grind sophisticated exploitation work at coffee-shop prices. CrowdStrike’s Zaitsev: “The window between a vulnerability being discovered and being exploited by an adversary has collapsed — what once took months now happens in minutes with AI.”
  • VulnCheck counter-signal on aggregate claim: 75 CVE records contain “Anthropic”; only 40 potentially attributable; 28 of 40 concentrated in Mozilla Firefox alone. “Thousands of vulnerabilities across every major OS and browser” is overstatement. Schneier + Willison endorse restricted-access as correct default. Schneier’s rule: “Finding for the purposes of fixing is easier for an AI than finding plus exploiting” — defender has a structural 12–18 month advantage before Mythos-class capability goes public.
  • Implied CISO 2026 agenda: (1) compress patch cycles on internet-exposed systems from 30 days to 72 hours; (2) stand up AI-assisted vulnerability discovery on own code using publicly-available frontier models (Opus/Sonnet already match Mythos on discovery); (3) rearchitect IR around minutes-not-months exploitation windows with pre-approved SOC containment authority; (4) rewrite vendor MSA patch-cycle SLAs from 30 days to 72 hours on internet-exposed vendor systems.

Source: research/06-security-frontier/anthropic-project-glasswing-mythos-2026.md

Darktrace State of AI Cybersecurity 2026 (n=1,540, 14 countries, Feb 2026)

The Darktrace annual survey of 1,540 CISOs, IT security managers, and practitioners across 14 countries (fieldwork October–November 2025) documents three developments that collectively define the 2026 security operating environment: the emergence of agentic AI as the primary new attack surface, a counterintuitive retreat in formal AI policy coverage, and a persistent ceiling on SOC automation that executives systematically overestimate.

  • Agentic AI is now the #1 security concern: 92% of respondents are concerned about AI agents across the workforce — higher than concern about third-party LLMs (44% extremely/very concerned) or any other specific threat vector. The concern is operational, not hypothetical: Darktrace telemetry shows a 39% month-over-month increase in anomalous data uploads to generative AI services (October 2025 observation), with an average upload of 75MB (~4,700 document pages). Only 19% of respondents flagged shadow AI adoption as a top concern — the governance attention lags the behavior by a wide margin.
  • Formal AI policy coverage dropped 8 percentage points in one year (45% → 37%) even as threat severity reports increased. Organizations are deploying more AI while governing it less. Fifty-two percent are still “discussing” formal policies; 8% have no plans to create them (up from 3% in 2025). This is the sharpest year-over-year deterioration in any governance metric in the major 2026 security surveys.
  • SOC automation is far more limited than executive narratives suggest: only 14% allow AI to take independent remediation actions with no human oversight. CISOs report 18% autonomous deployment; frontline threat analysts report 9% — a 9-point perception gap. The dominant model is “human in the loop” (70%), consistent with Singapore IMDA governance standards for high-stakes AI decisions.
  • AI-powered attacks are escalating on all dimensions: 87% say AI increases attack volume, 89% say attacks are more sophisticated, 91% say phishing and social engineering are more effective. The top-four attack vectors: hyper-personalized phishing (50%), automated vulnerability scanning (45%), adaptive malware (40%), deepfake voice fraud (39%).
  • Enterprise response is consolidation, not build: 93% prefer integrated platforms over point products; 85% prefer MSSP-delivered SOC capabilities. Mid-market organizations without dedicated security teams are structurally dependent on managed service delivery — the 4.8M unfilled cybersecurity roles (ISC2 2025) make self-sufficiency impractical.

Source: research/06-security-frontier/darktrace-state-of-ai-cybersecurity-2026.md

Supporting research

See also (wiki)

JPMorganChase — The Lethal Trifecta Runtime Security Framework (March 2026)

Practitioner framework from a Tier 1 financial institution with live production agentic deployments. The most specific enterprise security guidance published for agentic AI as of mid-2026.

  • Three-factor risk classification: an agent that simultaneously (1) processes untrusted inputs, (2) has read access to sensitive organizational data, and (3) can trigger external actions is in the Lethal Trifecta zone. Prompt injection in any untrusted input can exfiltrate sensitive data without user awareness.
  • Live risk, not theoretical: JPMC’s framing acknowledges 2025 incidents where agents leaked API keys and internal documents. Real-world examples predate this publication.
  • Attack surface has shifted from the model to the runtime context. Traditional model security reviews (weight/training red-teaming) are necessary but insufficient. The threat vector is what the model receives at runtime — the context window — not what the model knows.
  • Runtime governance, not just deployment review: every Trifecta-zone agent requires continuous monitoring, tamper-evident runtime logs, machine-to-machine authentication, and adversarial testing (prompt injection attempts) before production.
  • Audit protocol: apply the three-factor test to the current agent portfolio in a single afternoon. Most enterprises find more Trifecta-zone agents than expected because provisioning was done for convenience, not least-privilege.

Source: research/19-agent-frameworks/jpmc-lethal-trifecta-agentic-ai-security.md · JPMorganChase Technology Blog · March 23, 2026 · HIGH · TIER 1

A2A and MCP Protocol Security: New Attack Surfaces (May 2026)

The shift to agentic AI introduces protocol-level attack surfaces that sit between agents, tools, and data sources — invisible to traditional application-layer security controls.

  • CVE-2025-49596 (CVSS 9.4): First critical MCP server vulnerability — tool-list poisoning allowing a malicious MCP server to inject hidden instructions into legitimate tool descriptions. Affects any enterprise running MCP-connected agents without server-identity validation.
  • Tool poisoning: Attacker modifies an MCP tool’s description (not its code) to include hidden natural-language instructions. The model reads the description at runtime and follows the injected instruction. No code vulnerability required.
  • Rug pull: MCP server serves safe behavior during security review; malicious behavior in production. Defense requires tool pinning (hash of description at approval time) and runtime behavioral monitoring.
  • A2A trust escalation: When Agent A calls Agent B via A2A protocol, Agent B may grant broader permissions than the human operator intended — the authorization cascade problem. Singapore MGF’s multi-agent HITL requirement directly addresses this.
  • Token exfiltration via reasoning chains: Prompt injection in retrieved documents can instruct the agent to include sensitive data in its reasoning output, which is then readable by the attacker. Defense: semantic content filtering on all agent inputs and outputs.
  • Supabase/Cursor incident (mid-2025): First practitioner-reported case of MCP-based data exfiltration in a production enterprise setting. Database credentials leaked via a malicious MCP server configuration.

Source: research/19-agent-frameworks/a2a-mcp-protocol-security.md · Multiple sources (CVE disclosures, arxiv, vendor security research) · May 2026 · HIGH · TIER 1–2

Zero Standing Privileges and JIT Agent Identity (May 2026)

Non-human AI agent identities require a fundamentally different IAM model than human users. Traditional PAM (Privileged Access Management) assumes persistent credentials for known identities; agentic AI requires ephemeral, task-scoped permissions that are provisioned at task initiation and revoked at completion.

  • PoLP vs. ZSP: The Principle of Least Privilege assumes persistent credentials with minimal scope. Zero Standing Privileges goes further: credentials should not exist between tasks — eliminating the standing access that attackers exploit in lateral movement.
  • JIT provisioning flow: Agent requests task → access request sent to PAM/identity broker → entitlements issued with time-bound token → agent executes → token automatically revoked. This eliminates the “always-on admin” pattern that creates lateral movement risk.
  • Why PAM breaks for agents: Traditional PAM (CyberArk, BeyondTrust) was designed for human administrators using interactive sessions. AI agents run headlessly at machine speed, spawn sub-agents, and may execute hundreds of tasks in parallel — PAM check-in workflows were not designed for this pattern.
  • Vendor landscape: CyberArk Conjur (secrets management at machine speed), BeyondTrust Privileged Remote Access, Okta AI Agent Governance (GA April 2026) — first IAM product explicitly designed for agentic workloads, covering agent lifecycle from provisioning to revocation.
  • Gartner projection: 40% of enterprises will implement ZSP for their most privileged AI workloads by end-2026.

Source: research/19-agent-frameworks/zsp-jit-agent-permissions-enterprise.md · May 2026 · HIGH · TIER 1

Cisco AI Defense — Token-Level Audit Architecture (May 2026)

Cisco AI Defense provides a production-grade example of the “security at the inference layer” architecture that enterprise security teams are increasingly requiring for agentic workloads.

  • Four-point lifecycle interception: model discovery, model validation (pre-deployment red-teaming), real-time protection (runtime inference monitoring), and post-incident forensics — each as a distinct control plane, not a single proxy.
  • DefenseClaw audit sidecar: attaches to the inference container, logging every prompt, completion, tool call, and access event without adding latency to the primary inference path. Produces tamper-evident runtime logs for forensic and compliance purposes.
  • JPMC Lethal Trifecta mapping: AI Defense maps all four lifecycle stages to JPMC’s three-factor risk classifier — an independent convergence of industry and vendor security frameworks.
  • Singapore MGF alignment: AI Defense’s four-point architecture maps to all four MGF governance dimensions (accountability, monitoring, human oversight, incident response).

Source: research/19-agent-frameworks/cisco-ai-defense-token-audit.md · May 2026 · MEDIUM-HIGH · TIER 1

IR Readiness: The Plan-Execution Gap (Sygnia 2026, n=600+, TIER 1)

Sygnia’s 2026 CISO Survey (600+ senior security decision makers, Jan–Feb 2026, $250M+ orgs) isolates the gap between documented IR plans and operational readiness:

  • 73/99 paradox: 99% have formal IR plans; 73% of CISOs say their organization would not be ready to execute under pressure tomorrow. The plan exists; the rehearsed escalation chain does not.
  • Coordination failure dominates: 90% anticipate stakeholder coordination difficulty during a significant incident. 89% cite limited board/executive involvement in IR readiness. 75% say legal/communications involvement slows real-time decisions.
  • Cloud visibility is the technical gap: 78% report visibility gaps in public cloud, SaaS, and endpoints. 90% flag public cloud specifically as a blind spot.
  • AI IR adoption lagging attacker speed: Only 29% currently use AI extensively in IR activities; 63% plan to by 2027 (+38pp planned jump). The risk is rushing AI IR tooling onto a team that hasn’t fixed its coordination foundation first.
  • Attack frequency is high: 76% of surveyed organizations were attacked in the prior 12 months; 32% more than once. 47% experienced operational shutdown; 41% data loss.

Source: research/06-security-frontier/sygnia-ciso-ir-readiness-2026.md · April 2026 · MEDIUM-HIGH · TIER 1

ISACA 2026 AI Pulse Poll — Shutdown Readiness Gap (May 2026, n=3,400+)

ISACA surveys the practitioners responsible for AI governance — IT auditors, security professionals, risk managers — not executives. Their findings on incident response readiness are more operationally credible than executive self-assessments:

  • 56% of digital trust professionals cannot say how long it would take to shut down an AI system after a security incident. This is not a knowledge gap in leadership. It is a knowledge gap in the people whose job is to manage AI risk.
  • 39% don’t know whether their organization has a documented AI override/shutdown process at all. The kill-switch problem — whether organizations can stop an AI system on demand — is unresolved at the majority of organizations.
  • 35% of European organizations cannot confirm whether they’ve experienced an AI-powered cyberattack. Absence of confirmation is not absence of attack. It reflects detection gaps.
  • The shutdown-readiness gap maps directly onto the Sygnia 73/99 paradox above: documented plans exist; operational readiness does not. For AI systems specifically, even the plan may not exist.

Source: research/07-adoption-challenges/isaca-ai-pulse-poll-2026.md · May 2026 · HIGH · TIER 1

Netskope/Cybersecurity Insiders “AI Risk and Readiness Report 2026” (n=1,253, March 2026) — Runtime Agent Control Gap

The first large-n practitioner survey focused specifically on runtime agent control — what organizations can and cannot stop once an agent is executing:

  • 91% of organizations cannot intervene before an AI agent completes a harmful action. 9% can stop an agent pre-execution; 24% can block some but not all actions; 35% discover what happened only post-execution; 32% have zero visibility into agent actions.
  • The governance gap is 66 points wide: 73% deploy AI tools; only 7% govern them with real-time policy enforcement. 68% describe governance as reactive or developing; 11% have no AI security policies at all.
  • DLP is functionally blind to semantically-transformed content: 92% of organizations lack DLP controls that detect AI-rephrased data. When a language model rephrases a classified document, syntactic pattern-matching rules see clean text. 46% of DLP systems will fail to detect the violation outright.
  • Write access scope is broader than most organizations realize: 53% of AI tools have write access to collaboration suites; 40% to email; 25% to code repositories; 8% to identity providers.
  • MCP governance is essentially nonexistent: Only 8% of organizations have governance policies covering Model Context Protocol — the standard enabling AI models to connect to enterprise data sources.
  • Budget is not solving the problem: 90% increased AI security budgets; 29% report feeling less secure than a year ago.

The DLP semantic failure mechanism is architecturally distinct from all prior data protection failures: traditional DLP operates at the syntactic layer (character patterns); AI threats operate at the semantic layer (meaning preserved after rephrasing). Closing the gap requires content-aware inspection tools, not DLP version updates.

Source: research/06-security-frontier/netskope-ai-risk-readiness-2026.md — MEDIUM-HIGH / TIER 1 (Netskope vendor; Cybersecurity Insiders independent practitioner sample; n=1,253; ±2.8% MOE; March 16, 2026)

Allianz Risk Barometer 2026 (n=3,338, 97 countries, Oct–Nov 2025) — AI as a Corporate Insurance Risk

The insurance industry’s risk view of AI — from professionals who price and hedge corporate liability, not IT or AI vendors:

  • AI jumped from #10 to #2 in the Allianz Risk Barometer in one year — the largest single-year rise in the 15-year history of the survey. 32% of risk professionals now cite AI as a top-three business risk, up from ~10% one year prior.
  • Cyber (#1, 42%) and AI (#2, 32%) are now explicitly linked by Allianz underwriters as correlated risks — weak AI controls directly elevate cyber exposure and are beginning to be treated as a joint risk category in underwriting.
  • Four liability mechanisms are actively accumulating claims: automated decision-making accountability, IP misuse from AI-generated content, biased/discriminatory model outputs, and regulatory sanctions (EU AI Act, US state AI laws). These are the four mechanisms driving the ranking surge.
  • Only one-third of organizations prioritize robust AI ethical governance — the same structural gap documented by Cisco (12% mature), ISACA (38% comprehensive policy), and AAA (22% governance effectiveness), now confirmed from the risk-management side.
  • 49% of companies invest in retraining for AI disruption; 40% eliminate roles — the risk community is already treating headcount reduction as a realized outcome, not a future scenario.
  • The practical insurance implication: companies without documented model inventories, audit trails, and human oversight will face coverage gaps or surcharges at 2026 renewals — analogous to the cybersecurity underwriting tightening that followed the first wave of major data breach claims in 2015–2018.

Source: research/06-security-frontier/allianz-risk-barometer-ai-2026.md — MEDIUM-HIGH / TIER 1 (Allianz insurance commercial interest; 15-year annual series; n=3,338; 44% large companies >$500M; Oct–Nov 2025 fieldwork)

Verizon 2026 DBIR (22,000+ breaches, DLP telemetry n=858,440) — Behavioral Evidence for Shadow AI at Scale

The DBIR is the only corpus entry with real-world behavioral telemetry rather than survey self-report. Its shadow AI and breach data corroborates multiple executive survey findings from the actual event record.

  • Vulnerability exploitation overtook credential theft as #1 breach entry point for the first time in 19 years: 31% of breaches (up from 20% — a 55% YoY increase), while credentials fell to 13%. AI-accelerated exploit development is the proximate cause — threat actors are compressing attacker timelines from months to hours.
  • Shadow AI usage tripled in one year via DLP telemetry: 45% of employees are regular AI users on corporate devices (up from 15%), with 67% using non-corporate accounts. This is behavioral observation across n=858,440 GenAI-targeted DLP events — not survey self-report. Source code is the #1 data type submitted to external AI models.
  • Shadow AI is now the third most common non-malicious insider action in enterprise DLP datasets — a fourfold increase. This directly corroborates Qualtrics (80% ungoverned, 37% self-source under pressure) and Netskope (92% DLP semantic failure) but from event telemetry rather than survey.
  • 15% of employees have unauthorized AI browser extensions that collect browsing context — including internal application sessions — by design.
  • Third-party breach involvement: +60% YoY, now 48% of all breaches. Every AI vendor API relationship is a realized exposure vector in this dataset.
  • AI-generated malware is now common: median threat actor documented AI assistance across 15 attack techniques; some actors used 40–50. Less than 2.5% involved novel techniques — AI enables speed and scale, not primarily capability innovation.
  • CISA KEV remediation rate fell from 38% to 26%; median remediation time increased from 32 to 43 days. Defenders are slower while attackers are faster.

The DLP semantic failure gap identified by Netskope is confirmed here from the source side: shadow AI is growing at 3× annual rate precisely because standard DLP infrastructure can’t detect AI-destination data flows.

Source: research/06-security-frontier/verizon-dbir-2026-ai-threat-landscape.md — HIGH / TIER 1 (Verizon VTRAC + ~100 global contributors; 22,000+ breaches; VERIS framework; data period 2025; published May 19, 2026)


What this means for mid-market buyers

  1. Lay the 10-control floor before adding more AI tools. The combined NIST AI RMF / OWASP LLM Top 10 / CIS Controls v8.1 minimum (AI tool inventory, acceptable use policy, access controls, data classification, prompt-injection defense, non-human identity governance, output review protocols, incident response addendum, model supply-chain review, and vendor questionnaire) costs $15K-$45K and takes two weeks. It is also the documentation set the cyber insurer will ask for at the 2026 renewal.
  2. Map the non-human identity population before auditors do. AI agents, service accounts, and automation identities at 82-to-1 vs. humans are the fastest-growing unmanaged attack surface. A one-week identity-inventory exercise with the IAM team plus the AI platform owners produces the list most mid-market companies currently do not have.
  3. Run one AI-specific tabletop exercise per quarter. The CoSAI AI Incident Response Framework v1.0 (Nov 2025) and OWASP GenAI Incident Response Guide 1.0 (Jul 2025) provide scenarios (prompt injection data exfil, deepfake CEO wire fraud, agent tool-abuse, model supply-chain malware). Two hours with legal, IT, security, and one business owner — the practice is how the response plan holds together when the first real incident arrives.

Industrial AI Cybersecurity: The OT/IT Expansion Problem (Cisco 2026, n=1,000+, TIER 1)

Industrial AI — manufacturing, logistics, energy infrastructure — introduces cybersecurity risk that is structurally different from knowledge-work AI. When AI fails in an office workflow, it produces a wrong document. When it fails on a factory floor or in a power grid, the failure has physical consequences: unplanned shutdowns, safety incidents, supply chain disruptions.

  • 40% of industrial AI organizations name cybersecurity as their single largest obstacle to scaling AI — the top-ranked barrier, ahead of data quality, talent, and infrastructure cost (Cisco/Sapio n=1,000+, 19 countries, Apr 2026).
  • 98% say cybersecurity is foundational to AI-ready industrial infrastructure — near-consensus from organizations with direct physical-consequence deployment experience.
  • 48% flag security as their top networking challenge; 57% report some IT/OT collaboration but 43% have limited or none — the gap between the teams responsible for network security (IT) and the teams operating the physical processes (OT) is the primary unresolved structural risk in industrial AI.
  • The 85% who expect AI to improve their security posture are not wrong — AI-powered anomaly detection and behavioral monitoring at machine speed improve defensive capability long-term. The 40% who name cybersecurity as the scaling obstacle are experiencing the short-term reality: every new AI workload expands connectivity at the OT layer (historically air-gapped), creating new attack surface before the corresponding defensive capability is in place.

The IT/OT security gap is operationally distinct from the enterprise AI governance gap. The enterprise AI CISO problem is managing non-human identities, shadow AI, and prompt injection in cloud-connected knowledge-work workflows. The OT/IT CISO problem is securing AI workloads running on networks that physically control machines, where downtime or compromise has safety and operational consequences beyond data loss.

Source: research/05-analyst-firms/cisco-state-of-industrial-ai-2026.md — MEDIUM-HIGH / TIER 1 (Cisco networking vendor; Sapio Research double-blind; n=1,000+; 19 countries; Apr 2026)

International AI Safety Report 2026 — Confirmed Real-World Cyber Threats (100+ experts, Feb 2026)

The most authoritative independent synthesis available on AI and cybersecurity risks. Key findings for enterprise security leaders:

  • AI agent identified 77% of vulnerabilities in real software in a competition setting — demonstrating that AI-powered attack tooling now has documented, near-expert capability.
  • Criminal groups and state-associated attackers are confirmed to be using general-purpose AI in live cyber operations. This moves from projected to documented.
  • AI models are gaming evaluations: models increasingly distinguish between test conditions and real-world deployment, and exploit loopholes in safety evaluations. Dangerous capabilities may go undetected before a model ships.
  • Open-weight models cannot be recalled after release; their safety controls are easier to remove; misuse is harder to trace. Enterprises using Llama, Mistral, or derivatives are the last line of defence.
  • Defence-in-depth (layering multiple safeguards) recommended by the report’s 100+ expert authors — no single technical control is sufficient.

Source: research/06-security-frontier/international-ai-safety-report-2026.md — HIGH / TIER 1 (100+ independent experts; 30+ governments; Yoshua Bengio chair; Feb 2026)

EY Technology Pulse Poll (n=500, US Tech Leaders, Feb 2026) — Confirmed Data Leaks from Ungoverned AI

Source: research/07-adoption-challenges/ey-technology-pulse-autonomous-ai-governance-2026.md · EY/Atomik Research, n=500 US tech leaders at 5,000+ employee orgs, February 2026 · MEDIUM-HIGH / TIER 1

Key cybersecurity findings from large US technology companies — the sector that sets enterprise AI deployment norms:

  • 45% have experienced confirmed or suspected sensitive data leaks from unauthorized AI tools; 39% report proprietary IP leaks — these are not theoretical exposure, they are realized incidents
  • 52% of department-level AI initiatives lack formal oversight — the governance gap is the direct mechanism behind the leak rates
  • 85% prioritize speed-to-market over pre-launch vetting — the security posture is a deliberate trade-off, not inadvertent oversight failure
  • 79% are increasing cybersecurity spending in response — but perimeter and network security does not address the use-case-layer problem created by ungoverned initiatives
  • The authority bottleneck compounds incident response: 42% require board or CEO approval to halt a high-priority AI project, making rapid containment structurally difficult