Key Takeaways
- A majority of CISOs (81 %) are concerned that their AI systems lack proper governance, highlighting a widespread anxiety about AI‑related risk.
- Less than half of surveyed organizations know all the AI agents operating on their networks (47 %) or control those agents’ access to corporate data (46 %).
- Shadow AI is pervasive: 68 % of CISOs report observing unauthorized AI use, creating visibility gaps that complicate defense efforts.
- Controls around authorized AI tools are weak; many firms rely on shared credentials, highly permissioned accounts, or let agent‑creating teams self‑manage, with only 25 % using a dedicated access framework.
- Leadership misalignment exacerbates the problem—fewer than one‑third of CISOs feel fully aligned with CEOs and boards on acceptable AI risk, and in the U.S. the figure drops to 12 %.
- Executives often view AI security controls as impediments to growth rather than enablers, with fewer than half of CISOs believing their boards see AI security as a business benefit.
- CISOs remain deeply worried about offensive AI use: 57 % globally (84 % in the U.S.) are extremely or very concerned about AI‑driven breaches, especially AI‑enhanced phishing, malicious agents, and deep‑fake authentication bypasses.
- The insights derive from Okta’s survey of 306 CISOs and cybersecurity leaders across the U.S., U.K., Japan, Germany, Canada, and France.
Overview of AI Agent Risks
The rapid proliferation of AI agents—software entities that can autonomously perform tasks, make decisions, and interact with data—has introduced a new layer of complexity to corporate cybersecurity. While these agents promise efficiency gains, they also expand the attack surface because they often operate with privileged access to sensitive systems and data. Okta’s recent report underscores that many organizations have not yet instituted the governance structures needed to manage this risk effectively. The disconnect between the potential benefits of AI and the current state of oversight leaves companies vulnerable to both accidental misuse and deliberate exploitation by threat actors.
Survey Findings on Visibility and Control
Only 47 % of the companies Okta surveyed claimed to have a complete inventory of the AI agents present on their networks, and an even smaller share—46 %—said they actively control those agents’ access to corporate data. This lack of visibility creates blind spots where unauthorized or poorly configured agents can operate undetected, potentially exfiltrating information, altering configurations, or serving as footholds for further intrusions. Without a clear map of where AI agents reside and what permissions they hold, security teams struggle to apply the principle of least privilege or to detect anomalous behavior indicative of compromise.
The Challenge of Shadow AI
Shadow AI—unsanctioned or undisclosed use of AI tools by employees—emerges as a particularly acute problem. In the survey, 68 % of CISOs reported observing at least some instances of unauthorized AI adoption. Workers, eager to leverage productivity‑boosting assistants or generative models, frequently bypass formal procurement and security review processes. This grassroots proliferation leads to a fragmented ecosystem where security teams cannot enforce consistent policies, monitor data flows, or ensure that the tools adhere to organizational security baselines. The resulting visibility gap not only heightens risk but also hampers incident response, as investigators may be unaware of the AI components involved in an event.
Weak Controls Around Authorized AI
Even when AI agents are officially sanctioned, many organizations fail to enforce stringent controls. Roughly one‑fifth of respondents reported allowing AI agents to access network resources via shared credentials or highly permissioned, agent‑specific accounts—both practices that dilute accountability and make it difficult to trace actions back to a specific user or process. A similar proportion said they permitted the teams that created the AI agents to manage those agents independently, effectively decentralizing oversight. Only one‑quarter of respondents indicated they managed AI agents through a dedicated access framework, such as a privileged access management (PAM) solution tailored to non‑human identities. These findings suggest that current controls often resemble ad‑hoc arrangements rather than systematic, policy‑driven governance.
Leadership Alignment and Risk Appetite
A critical factor influencing AI governance is the alignment between security leaders and executive leadership. Fewer than one‑third of CISOs told Okta they felt “fully aligned” with their CEOs and boards regarding the appropriate level of risk to accept with AI initiatives. In the United States, this alignment drops dramatically to just 12 %. When security and business leaders diverge on risk tolerance, security teams may find their recommendations overridden or under‑resourced, leaving gaps that threat actors can exploit. The misalignment often stems from differing perceptions of AI’s value: while security sees controls as necessary safeguards, many executives view them as potential brakes on innovation and speed to market.
Executive Perceptions of Security as an Enabler
Compounding the alignment issue, less than half of the surveyed CISOs believe that their boards regard AI security as a business enabler. Instead, many executives appear to treat security controls as impediments that could slow down AI‑driven projects or increase operational costs. This mindset can lead to underinvestment in governance tools, insufficient staffing for AI risk management, and a reluctance to implement measures such as continuous monitoring, automated policy enforcement, or rigorous vendor assessments. Reframing AI security as a catalyst for trust, compliance, and sustainable innovation is essential to garner the executive support needed for effective governance.
Concerns About Offensive AI Use
Defensive worries are mirrored by acute apprehension about how adversaries might weaponize AI. More than half (57 %) of global security leaders, and a striking 84 % of U.S. respondents, said they were extremely or very worried about AI‑driven breaches. The top fears cited include AI‑enhanced phishing campaigns that leverage generative language models to craft convincing lures, malicious AI agents designed to infiltrate networks and exfiltrate data, and deep‑fake technologies capable of bypassing authentication mechanisms such as voice or facial recognition. These offensive capabilities increase the sophistication and success rate of attacks, demanding that defenses evolve in tandem—through AI‑aware threat detection, behavioral analytics, and robust identity verification methods.
Methodology and Scope of the Report
Okta’s insights are derived from a survey of 306 CISOs and other cybersecurity executives across six countries: the United States, the United Kingdom, Japan, Germany, Canada, and France. The respondents represent a mix of industries and organization sizes, providing a broad view of how AI governance challenges manifest in different regulatory and cultural contexts. By capturing both quantitative metrics (e.g., percentages of companies with certain controls) and qualitative concerns (e.g., fear of AI‑enhanced phishing), the report offers a comprehensive snapshot of the current state of AI agent risk management and highlights areas where urgent improvement is needed.
Conclusion and Path Forward
The data paint a clear picture: while AI agents hold transformative potential, many enterprises are lagging in the governance, visibility, and controls required to secure them. To close these gaps, organizations should adopt a multi‑pronged strategy that includes comprehensive asset inventories for AI agents, centralized identity and access management tailored to non‑human identities, continuous monitoring for anomalous AI behavior, and ongoing education to curb shadow AI. Equally important is fostering alignment between security leaders and executive stakeholders, positioning AI security not as a hindrance but as a foundational element that enables responsible, sustainable innovation. By addressing these challenges head‑on, businesses can harness the advantages of AI while mitigating the attendant risks.