The Unsung Heroes of the AI Paradigm Shift: CISOs

August 22, 2026


Welcome to a new edition of The Board: Distillation Aftershots (*).

This online version of The Board newsletter, written by Constellation's Chief Distiller and Board Advisor Esteban Kolsky, shares curious and interesting insights and data points distilled from enterprise technology to identify what’s notable. To subscribe and receive this in your inbox, click here.

I have been arguing for some time that cybersecurity would become one of the largest areas of enterprise technology investment. AI temporarily absorbed much of that budget and attention during 2025 and early 2026, but agentic AI has brought cybersecurity back into the center of the discussion. The recent incidents involving autonomous models escaping sandboxes give boards a better reason to understand, fund, and empower the people responsible for defending the enterprise: CISOs.

The recent Plain English podcast with Derek Thompson and former Meta security chief Alex Stamos provides a useful snapshot of what changed. Thompson and Stamos discuss several cases where advanced models exceeded expected security boundaries, including the OpenAI/Hugging Face incident in which models chained vulnerabilities, reached the public internet, and compromised external infrastructure while pursuing their assigned objective. Anthropic separately reviewed more than 141,000 cybersecurity evaluation runs and found three instances in which models reached real internet systems and gained unauthorized access.

I do not see these primarily as evidence that models are becoming uncontrollable. They expose weaknesses in containment, identity, access, observability, and intervention. In an enterprise environment with stronger controls, clearer tiers of autonomy, and a CISO empowered to monitor and act on deployments, including those that exceed agreed boundaries, much of this should have been contained earlier. If an agent cannot be reliably identified, its privileges exceed what was approved, or its actions cannot be observed or reversed, the CISO and its team should be able to stop deployment until the exposure is resolved or explicitly accepted.

That expands an existing CISO responsibility into a world of nonhuman actors operating at machine speed. The models have evolved quickly and unevenly, often with less attention to enterprise security than the market would like, but the enterprise still owns the environment in which those models operate. Governance defines what the system may do; cybersecurity makes those limits enforceable, and the CISO’s role was and should be combating unexpected incursions, no matter where they come from.

The broader threat extends beyond controlling internal agents. The same capabilities that allow models to discover vulnerabilities during legitimate testing will increasingly be available to attackers. BCG’s August 2026 CISO research found that 35% of organizations had experienced significant impact from AI-enabled attacks during the previous twelve months. The average organization reported three significant breaches and 25 sensitive-data incidents, while CEOs already rank cyber threats among their top three business risks.

This is why the CISO matters more to enterprise strategy without needing more visibility for its own sake. The best security organizations operate quietly. Their value is found in attacks that fail, vulnerabilities removed before exploitation, access denied appropriately, and incidents contained before they become material. That makes the role easy to underestimate because success often looks like nothing happened. The CISO is, in many ways, the defender of the unexpected: building enough control, containment, and resilience that threats the enterprise did not predict still fail to become material events.

AI makes that misunderstanding more dangerous. A July survey of more than 300 cybersecurity executives found that 81% were concerned their AI systems were insufficiently governed, while fewer than half knew all the agents operating on their networks or controlled those agents’ access to corporate data. Only 12% of US CISOs reported being fully aligned with leadership on how much AI risk the organization should accept.

Over the past several months, I have written about the move toward dynamic budgeting as annual technology plans become less useful in markets where capabilities and threats change materially between planning cycles. Cybersecurity is one of the clearest examples. A newly discovered vulnerability in a critical workflow, a significant increase in agent authority or access, evidence that a control has become ineffective, a major third-party weakness, a regulatory change, or a defensive capability that materially reduces risk should be able to trigger capital reallocation within agreed limits.

PwC’s 2026 Digital Trust Insights found that AI enablement of cyber capabilities is now the top priority for cyber-budget allocation, with 50% of respondents expecting cyber budgets to rise in 2026. In some sectors, that number is substantially higher, yet proactive security investment still trails reactive spending in many organizations. Dynamic budgeting is useful when it ties to changes in exposure rather than simply additional spending.

The same principle applies to authority. The CISO should have a defined right to pause AI or agentic deployments when established risk thresholds are exceeded. The CEO and board should set the boundaries and escalation rules in advance, while management and the CISO operate within them. Permanent cancellation remains a broader executive decision in most cases, but the security function needs the ability to prevent irreversible exposure while the issue is evaluated.

This connects directly to the governance discussion from the CEO’s AI Dashboard. Self-regulation and self-compliance become necessary when technology moves faster than external regulation. Enterprises need their own rules defining what agents can access, what they may do, when they must stop, how their activity is monitored, and who owns the outcome. Cybersecurity provides much of the enforcement mechanism for those rules.

AI also offers opportunities for defensive use. Recent work from OpenAI describes a narrowing “defender’s window” during which advanced models may allow defenders to discover and remediate vulnerabilities faster than attackers can exploit them. Whether that advantage lasts is uncertain, but the strategic implication is useful: enterprises should invest in the CISO’s ability to use AI for defense while strengthening controls around the AI they deploy.

When I began building the Board taxonomy in late 2024, cybersecurity was intended to be one of several major areas requiring more structured executive attention. AI eventually consumed much of that agenda. As AI moves beyond its inflection point and becomes part of the broader enterprise infrastructure, cyber needs to regain its independent strategic importance while remaining integrated with AI governance, infrastructure, data, and talent.

For boards and executives, the next step is to connect authority, funding, and strategy. Give the CISO enough authority to pause deployments that exceed agreed risk thresholds. Use dynamic budgeting to move capital when material exposure changes. Build agent governance and cybersecurity together so identity, access, observability, escalation, and accountability are part of the architecture. Revisit self-regulation as autonomous systems move ahead of formal rules and develop a talent model that preserves access to experienced security operators.

Experienced security operators understand attacker behavior, architecture weaknesses, exceptions, and the practical compromises that accumulate inside enterprise systems. The same workforce dynamics affecting other experienced operators apply here: many displaced or laid-off practitioners are not automatically returning to traditional corporate roles. Enterprises will need more flexible ways to retain access to this experience through contracted specialists, advisory arrangements, and targeted operating roles.

The CISO does not need to become the most visible executive in the enterprise. Boards and executive teams, however, need to understand much more clearly what CISOs are protecting, which capabilities they need, where their authority begins and ends, and which investments will allow them to keep operating quietly as the environment becomes more difficult.

Here are some reading resources:

  • Derek Thompson, Plain English, “It May Be Time to Freak Out About AI,” with Alex Stamos, August 14, 2026. Useful because it frames the recent agent-security incidents in practical terms and helps distinguish genuine new risk from familiar security failures appearing in a faster, more autonomous environment
  • OpenAI, “OpenAI and Hugging Face Partner to Address Security Incident During Model Evaluation,” July 21, 2026. Useful because it provides the primary-source account of how models chained vulnerabilities across environments and shows why containment, observability, and intervention controls need to improve as agent capabilities advance.
  • Anthropic, “Investigating Three Real-World Incidents in Our Cybersecurity Evaluations,” July 30, 2026. Useful because it documents real cases where models reached external systems during evaluation and reinforces the need to treat agent access, identity, and boundaries as operating controls rather than theoretical governance issues.
  • BCG, “How CEOs Should Manage Escalating Cybersecurity Risks in the Age of AI,” August 14, 2026. Useful because it quantifies the business impact of AI-enabled attacks and supports the argument that cyber belongs in CEO and board discussions about resilience, capital allocation, and long-term enterprise risk.
  • PwC, “2026 Global Digital Trust Insights.” Useful because it shows where cyber budgets are moving, especially toward AI-enabled defense, and supports the case for dynamic budgeting tied to changing exposure rather than fixed annual allocations.
  • BCG, “Building Enterprise AI Agents in Regulated Industries,” July 20, 2026. Useful because it connects agent deployment to shared control planes, auditability, autonomy limits, and human intervention, which supports the argument that governance and cybersecurity need to be designed together.
  • Cybersecurity Dive, “Shadow AI, Leadership Resistance Make AI Governance Tough for Worried CISOs,” July 30, 2026. Useful because the survey data highlights gaps in agent visibility, access control, and leadership alignment, reinforcing the need for clearer CISO authority and better board understanding of AI risk.
  • OpenAI, “The Defender’s Window,” August 17, 2026. Useful because it introduces the possibility that AI can temporarily improve the economics of defense by helping security teams discover and remediate vulnerabilities faster, supporting the case for investing in AI as a defensive capability as well as a new source of risk.

What’s your take? We are fostering a community of executives who want to discuss these issues in depth. This newsletter is but a part of it. We welcome your feedback and look forward to engaging in these conversations.

If you are interested in exploring the full report, discussing the Board’s offering further, or have any additional questions, please contact me at [email protected], and I will be happy to connect with you.

(*) A normal distillation process produces byproducts: primary, simple ones called foreshots, and secondary, more complex and nuanced ones called aftershots. This newsletter highlights remnants from the distillation process, the “cutting room floor” elements, and shares insights to complement the monthly report.