{"id":16239,"date":"2026-05-18T02:26:08","date_gmt":"2026-05-18T02:26:08","guid":{"rendered":"https:\/\/newestek.com\/?p=16239"},"modified":"2026-05-18T02:26:08","modified_gmt":"2026-05-18T02:26:08","slug":"ai-governance-in-cybersecurity-has-a-leadership-problem-not-a-technology-problem","status":"publish","type":"post","link":"https:\/\/newestek.com\/?p=16239","title":{"rendered":"AI Governance in Cybersecurity Has a Leadership Problem, Not a Technology Problem"},"content":{"rendered":"<div>\n<p style=\"text-align: justify;\"><em><strong>Enterprises are running AI risk programs that lack real accountability structures. This article, which expands on insights from a recent episode of\u00a0<\/strong><\/em><strong>The Cyber Circuit<\/strong><em><strong> podcast, examines what security leaders can do to prepare themselves for what comes next.<\/strong><\/em><\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\" style=\"text-align: justify;\">AI governance in enterprise cybersecurity is currently a collective fiction. Most organizations have the language of governance, some third-party risk questionnaires with an AI addendum, maybe a policy document, and a CISO who can credibly speak to the risk surface. What most do not have is an accountability structure that reflects how AI actually operates in 2026: autonomously, at speed, across non-human identity chains that traditional IAM and audit frameworks were never designed to assess.<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\" style=\"text-align: justify;\">This is the central argument that emerged from a recent episode of <a href=\"https:\/\/youtu.be\/oj4shm_-xpE?si=EtE0onbeg8CMjjWt\" target=\"_blank\" rel=\"noopener\"><em>The Cyber Circuit<\/em> podcast on Insight Jam<\/a>, featuring former CISO <a href=\"https:\/\/www.linkedin.com\/in\/manjumude\/\" target=\"_blank\" rel=\"noopener\">Manju Mude<\/a> and cybersecurity advisor <a href=\"https:\/\/www.linkedin.com\/in\/michaelimorgenstern\/\" target=\"_blank\" rel=\"noopener\">Michael Morgenstern<\/a>. The conversation is worth your time. But the conclusions it surfaces point to a broader structural problem that deserves sustained editorial attention.<\/p>\n<hr class=\"border-border-200 border-t-0.5 my-3 mx-1.5\">\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\" style=\"text-align: justify;\"><strong>FAQ Block<\/strong><\/p>\n<ul class=\"[li_&amp;]:mb-0 [li_&amp;]:mt-1 [li_&amp;]:gap-1 [&amp;:not(:last-child)_ul]:pb-1 [&amp;:not(:last-child)_ol]:pb-1 list-disc flex flex-col gap-1 pl-8 mb-3\" style=\"text-align: justify;\">\n<li class=\"font-claude-response-body whitespace-normal break-words pl-2\">The <a href=\"https:\/\/artificialintelligenceact.eu\/\" target=\"_blank\" rel=\"noopener\">EU AI Act<\/a> is currently the most substantive <a href=\"https:\/\/solutionsreview.com\/the-ai-compliance-trap-why-checklist-governance-wont-save-you-from-the-eu-ai-act\/\" target=\"_blank\" rel=\"noopener\">national or regional AI governance framework in effect<\/a>; the United States has no equivalent binding regulation as of mid-2026.<\/li>\n<li class=\"font-claude-response-body whitespace-normal break-words pl-2\"><a href=\"https:\/\/www.nist.gov\/itl\/ai-risk-management-framework\" target=\"_blank\" rel=\"noopener\">NIST\u2019s AI Risk Management Framework (AI RMF)<\/a> provides voluntary guidance but does not carry a compliance mandate.<\/li>\n<li class=\"font-claude-response-body whitespace-normal break-words pl-2\">Agentic AI systems, which can initiate multi-step autonomous workflows, are now commercially deployed across enterprise environments, fundamentally changing the scope of non-human identity risk.<\/li>\n<li class=\"font-claude-response-body whitespace-normal break-words pl-2\">Traditional IAM and audit frameworks were designed around human-in-the-loop workflows and do not cleanly map to autonomous-agent permission models.<\/li>\n<li class=\"font-claude-response-body whitespace-normal break-words pl-2\">Deepfake-enabled social engineering is increasingly targeting C-suite executives, which is a problem, considering <a href=\"https:\/\/www.nature.com\/articles\/s41598-025-94170-3\" target=\"_blank\" rel=\"noopener\">the majority of people struggle to identify AI deepfakes.<\/a><\/li>\n<\/ul>\n<hr class=\"border-border-200 border-t-0.5 my-3 mx-1.5\">\n<h3 class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\" style=\"text-align: justify;\"><strong>The Governance Gap Is a Policy Gap in Disguise<\/strong><\/h3>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\" style=\"text-align: justify;\">Enterprise <a href=\"https:\/\/solutionsreview.com\/data-management\/accelerate-with-confidence-building-a-strong-ai-governance-framework\/\" target=\"_blank\" rel=\"noopener\">AI governance<\/a> is not failing because CISOs are incompetent or boards are irresponsible. It is failing because governance frameworks have historically been downstream of regulation. HIPAA, PCI DSS, SOX, and SOC 2 all gave security and compliance teams something to point at. They structured board conversations, justified budget requests, and gave auditors a checklist. In the absence of equivalent federal AI regulation in the United States, enterprises are doing what they always do when external mandates disappear: they make up their own rules based on risk tolerance, and risk tolerance without external benchmarking trends conservative on the upside and permissive on the downside.<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\" style=\"text-align: justify;\">The result is that most AI governance programs are really just shadow IT discovery programs with extra vocabulary. Security teams are monitoring traffic, flagging API key exposure, and trying to figure out which of the dozens of AI tools their engineering org is running. That is necessary work. It is not governance.<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\" style=\"text-align: justify;\">Genuine AI governance requires ownership of decisions, accountability for outcomes, and a documented rationale for risk acceptance. Very few organizations have all three. Even fewer have a designated executive with the authority and mandate to enforce any of it.<\/p>\n<h3 class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\" style=\"text-align: justify;\"><strong>Agentic AI Breaks Every Assumption Insider Threat Programs Were Built On<\/strong><\/h3>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\" style=\"text-align: justify;\">The shift from chat-based AI interfaces to autonomous agents is arguably the most significant and underreported security transition of the past twelve months. Insider threat as a discipline was designed around a simple model: a credentialed human with access does something unauthorized. You audit the logs, trace the permission escalation, identify the actor, and remediate.<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\" style=\"text-align: justify;\">Agentic AI dissolves that model at every stage. When an engineer prompts an agent to \u201cget me everything you can on this topic and keep working until you have it,\u201d and that agent then traverses APIs, escalates permissions, and triggers downstream agents, the traditional accountability chain breaks. There is no single human decision that corresponds to each action. The engineer made one decision. The agent made thousands. Who answers to the regulator?<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\" style=\"text-align: justify;\">The honest answer right now is: nobody does, cleanly. The more useful answer is that this creates an urgent design requirement. Agentic AI deployments need explicit permission ceilings, audit logging at the agent-action level rather than just the session level, and human-approval gates for any action that touches external systems or privileged credentials. These controls exist in theory. Most organizations have not implemented them with the rigor that agentic scale demands.<\/p>\n<h3 class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\" style=\"text-align: justify;\"><strong>The Board Is Not Having the Right Conversation<\/strong><\/h3>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\" style=\"text-align: justify;\">One of the most clarifying observations from <a href=\"https:\/\/youtu.be\/oj4shm_-xpE?si=EtE0onbeg8CMjjWt\" target=\"_blank\" rel=\"noopener\"><em>The Cyber Circuit<\/em> discussion<\/a> is that board-level AI conversations in most enterprises occur within the strategy function, not the risk function. Boards are asking about AI-driven efficiency, workforce optimization, and competitive positioning. They are not asking their CISOs whether the organization has a documented framework for non-human identity governance or agent permission management.<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\" style=\"text-align: justify;\">This is not surprising. It mirrors almost exactly what happened with cloud adoption in the early 2010s, when the business case was obvious and the security infrastructure lagged by several years. The difference with AI is speed. Cloud adoption gave security teams years to build controls. The agentic AI transition is happening in quarters.<\/p>\n<p style=\"text-align: center;\"><iframe loading=\"lazy\" title=\"YouTube video player\" src=\"https:\/\/www.youtube.com\/embed\/oj4shm_-xpE?si=EtE0onbeg8CMjjWt\" width=\"560\" height=\"315\" frameborder=\"0\" allowfullscreen=\"allowfullscreen\"><\/iframe><\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\" style=\"text-align: justify;\">CISOs who are waiting for the board to surface AI risk as a priority are likely to wait too long. The more productive path is to tie AI risk directly to financial exposure, since risk language that connects to dollars moves faster in boardrooms than risk language that connects to threat scenarios. If a highly capable engineer is generating six figures in annual AI compute spend, that is already a budget and audit conversation, not just a security conversation. Security leaders who frame AI risk in those terms will receive a different reception than those who lead with attack-surface descriptions.<\/p>\n<h3 class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\" style=\"text-align: justify;\"><strong>What Auditors Are Not Ready For<\/strong><\/h3>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\" style=\"text-align: justify;\">Traditional compliance frameworks are encountering a structural problem with <a href=\"https:\/\/solutionsreview.com\/4-realities-of-ai-governance\/\" target=\"_blank\" rel=\"noopener\">AI governance<\/a> that has not yet been widely acknowledged: their assessment methodologies assume human workflows. The expectation that IAM controls will map to identifiable individual users with documented access requests, approvals, and revocations does not hold when the identity in question is an autonomous agent that provisioned its own credentials or inherited them from a parent agent.<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\" style=\"text-align: justify;\">Auditors working under SOC 2 Type II or similar frameworks are beginning to encounter this gap in live assessments, and the current default response is to treat AI tooling as a scoped exclusion or a management response rather than a material control gap. That posture is unlikely to survive the first significant AI-related breach that triggers regulatory scrutiny, at which point auditors and their frameworks will be under pressure to retrofit requirements that should have been designed proactively.<\/p>\n<h3 class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\" style=\"text-align: justify;\"><strong>What Security Leaders Should Actually Do<\/strong><\/h3>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\" style=\"text-align: justify;\">Waiting for external regulation is the wrong strategy for both the organization and the CISO\u2019s professional standing. The leaders who will have defensible programs when enforcement eventually arrives are the ones building internal accountability structures now. That means:<\/p>\n<ul>\n<li class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\" style=\"text-align: justify;\">Designating explicit AI program ownership at the executive level, separate from the CISO function but closely coordinated with it. A Chief AI Officer or equivalent role with risk accountability is not premature; it is overdue in organizations with serious AI deployment footprints.<\/li>\n<li class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\" style=\"text-align: justify;\">Building agent-specific access controls into AI infrastructure architecture, not as a retrofit. Agents should operate under least-privilege principles with explicit scope ceilings, time-bound permissions, and audit logging at the action level.<\/li>\n<li class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\" style=\"text-align: justify;\">Reframing internal AI risk communication in financial terms. Compute spend, productivity multipliers, and exposure scenarios that translate into dollar figures, as they move faster through budget and board cycles than attack surface descriptions.<\/li>\n<li class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\" style=\"text-align: justify;\">Treating every regulatory inquiry or AI-related incident as a governance design opportunity. The absence of external mandates does not eliminate the window for internal rule-setting; it expands it.<\/li>\n<\/ul>\n<h3 class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\" style=\"text-align: justify;\"><strong>The Coming Adolescence of AI, and Why It Should Motivate Urgency Now<\/strong><\/h3>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\" style=\"text-align: justify;\">The tools available in mid-2026 are already straining existing control frameworks. The tools likely to be available in 2027 will be materially more capable, more autonomous, and more deeply embedded in enterprise infrastructure. If the pattern of security-bolted-on-afterward holds, as it did with internet, cloud, and mobile, enterprises will probably spend the latter half of the decade trying to secure AI deployments that were never designed with security as a first-order requirement.<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\" style=\"text-align: justify;\">The window for proactive AI governance design is open right now, partly because regulation has not yet arrived and partly because the organizational chaos of rapid AI adoption has created space for security leaders to define terms before business units do. That window will not stay open indefinitely. The organizations that use it well will have a significant advantage when external mandates eventually close it.<\/p>\n<hr class=\"border-border-200 border-t-0.5 my-3 mx-1.5\">\n<p>The post <a href=\"https:\/\/solutionsreview.com\/identity-management\/ai-governance-in-cybersecurity-has-a-leadership-problem-not-a-technology-problem\/\">AI Governance in Cybersecurity Has a Leadership Problem, Not a Technology Problem<\/a> appeared first on <a href=\"https:\/\/solutionsreview.com\/identity-management\">Best Identity Access Management (IAM) Software, Tools, Vendors, Solutions, &amp; Services<\/a>.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Enterprises are running AI risk programs that lack real accountability structures. This article, which expands on insights from a recent episode of\u00a0The Cyber Circuit podcast, examines what security leaders can do to prepare themselves for what comes next. AI governance in enterprise cybersecurity is currently a collective fiction. Most organizations have the language of governance, some third-party risk questionnaires with an AI addendum, maybe a&#8230; <\/p>\n<p class=\"more\"><a class=\"more-link\" href=\"https:\/\/newestek.com\/?p=16239\">Read More<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[1],"tags":[],"class_list":["post-16239","post","type-post","status-publish","format-standard","hentry","category-uncategorized","is-cat-link-borders-light is-cat-link-rounded"],"_links":{"self":[{"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/posts\/16239","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=16239"}],"version-history":[{"count":0,"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/posts\/16239\/revisions"}],"wp:attachment":[{"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=16239"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=16239"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=16239"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}