If you are booking an agentic AI security keynote speaker, book the one who has run security for a company that put agents into production, not the one who has only demoed them on a stage. Agentic AI is not a slide about the future. It is software with credentials, acting on its own, inside your network, right now. The speaker who can help your board is the one who has already watched an agent do something nobody approved and had to clean it up. That is a different person than a futurist with a good deck.

I am a 5x CIO and CISO. I have sat in the seat where the agent has the access, the access has a blast radius, and the person who granted it is out of the building. That seat is why the agentic AI talks I give go where boards actually need them to go, into the identity, the permissions, and the accountability nobody wants to own.

Why agentic AI is a security problem, not just an AI problem

A chatbot answers. An agent acts. That one word is the whole shift. When AI only produces text, the worst case is a bad answer. When AI holds credentials and takes actions, the worst case is a bad action with your name on it.

Gartner projects that 40% of enterprise applications will include task-specific AI agents by the end of 2026, up from less than 5% in 2025. That is an eightfold jump in a single year, one of the fastest technology shifts enterprise software has seen. Most of those agents are being wired in faster than anyone is securing them.

Here is the part boards miss. An agent is a new kind of user. It has an identity, it holds permissions, and it can be tricked. But it never sleeps, it acts in milliseconds, and it does not pause to ask whether a request smells wrong. You have spent years hardening how humans get access. Agents just walked in through a door you have not built a lock for yet.

The number your board should hear first

Gartner predicts that by 2028, 25% of enterprise breaches will be traced back to AI agent abuse, from both outside attackers and malicious insiders. One in four. Not from some exotic new malware, but from the agents companies are deploying this year to move faster.

That is the whole talk in one sentence. The tools you are adopting for speed are becoming the attack surface. And most organizations cannot yet see what their agents can reach, which is exactly the gap an attacker needs.

A good agentic AI security keynote makes a few more real numbers concrete.

  • Gartner expects 25% of enterprise generative AI applications to suffer at least five minor security incidents per year by 2028. Small, frequent, and cumulative, not rare.
  • Gartner also predicts that AI-related issues will drive 50% of cybersecurity incident response efforts by 2028. Half of your IR work, tied to AI.
  • IBM's 2025 Cost of a Data Breach report puts the global average breach at $4.44 million. The agent that gets hijacked does not lower that number.

Numbers like these are not there to scare a room. They are there to move a budget conversation from "someday" to "this fiscal year."

What a real agentic AI security talk covers

Most AI keynotes sell wonder. The audience leaves excited and no better protected. A useful agentic AI security keynote does the opposite. It leaves the room with a short list of questions they can ask their own teams on Monday.

The talks I give tend to land on the same hard spots, because they are the ones that break in real deployments.

Identity for non-humans

Every agent needs an identity, a scope, and an owner, the same as an employee. Most have a shared key and no owner. That is the first thing an attacker looks for.

Standing access versus just-in-time

An agent with broad, always-on permissions is a bigger target than any single employee. When it gets hijacked, the blast radius is everything it could touch.

Prompt injection as a real attack, not a demo

Feed an agent a malicious instruction hidden in a document or a webpage, and it may follow it. This is not theoretical. It is one of the most common ways agents get turned.

The accountability gap

When an agent takes a harmful action, who owns it. If the answer is a shrug, the board just learned where the risk lives.

Guardian agents and oversight

Gartner expects that by 2028, 40% of CIOs will demand guardian agents that watch and contain what other agents do. Oversight of the machines is becoming its own control.

The tell of a speaker who has done the work

You can spot the difference in the first ten minutes. A theory speaker talks about what agents will be able to do. A practitioner talks about what they have already seen go wrong, and what stopped it.

Ask a candidate one question. Have you had to revoke an agent's access during an incident, and what did you learn. The futurist will pivot to a trend. The operator will tell you a story with a specific decision in it, because they have lived it. Book the second one.

The reason is simple. Boards are past the "what is agentic AI" phase. They need the person who can tell them what to secure, in what order, before the auditor or the attacker asks the same question. That comes from the seat, not the stage.

Why the operator seat is the whole difference

I have built and secured environments where agents and automation had real reach into real systems. I have made the call on what an automated process is allowed to touch, and I have watched what happens when that call is wrong. That is why I do not speak about agentic AI as a marvel. I speak about it as a control problem with a deadline.

It is also why I wrote Cyber War: One Scenario, a book that walks through a critical-infrastructure attack the way it actually unfolds, decision by decision, hour by hour. Agentic AI makes that scenario faster and harder, because now some of the actors in it are not people. The book and the keynote do the same job. They put a leadership team inside the event before it happens, so the event is not the first time they have thought it through.

The question to leave your board with

Stop asking whether agentic AI is coming. It is already inside most enterprises, holding credentials and taking actions. Start asking a harder question. If one of our agents was turned against us tonight, would we see it, could we stop it, and who owns the cleanup. If the room cannot answer that, you do not have an AI strategy problem. You have a security problem wearing an AI costume, and it is time to book the person who can name it out loud.

If you want that conversation for your board, event, or leadership offsite, that is the keynote I give. See agentic AI keynote topics and book me to speak. For the deeper read on how these attacks actually unfold, see Cyber War: One Scenario.