By March 2027, the credential theft attacks landing on a CISO's desk will move at a different speed than the ones from last year. Gartner has predicted that AI agents will cut the average time it takes to exploit a stolen account credential in half by 2027. That single forecast, made in March 2025, tells you almost everything about how the next eighteen months reshape the job. The threat side is automating faster than most defense programs are staffing for it.
This article is grounded in current advisory work, not retrospective analysis. Mark Lynd is a 5x CEO/CIO/CISO with Thinkers360 Top 10 global rankings across Cybersecurity and Artificial Intelligence and was ranked #1 globally in Cybersecurity in 2023. He is currently Head of Executive Advisory and Strategy at Netsync, advising enterprise C-Suites and boards on the AI and cybersecurity questions moving fastest in 2026. The frameworks and patterns referenced here are from active engagements this quarter.
The Job Is Splitting Into Two Jobs
For twenty years, the CISO's core function was consistent even as the tools changed. Defend the perimeter, then the identity layer, then the cloud workload. The job stayed anchored to one question. Who is trying to get in, and how do we stop them.
Agentic AI adds a second question that has nothing to do with intrusion. What is the software we already deployed authorized to decide on its own, and who is checking its decisions. Gartner's April 2026 forecast put a number on how fast this second question is becoming urgent. The firm predicts 25% of enterprise generative AI applications will experience at least five minor security incidents per year by 2028, up from 9% in 2025. It also predicts 15% will suffer at least one major incident annually by 2029, up from 3% in 2025. Gartner analyst Aaron Lord tied much of this to the Model Context Protocol, the connective layer letting agents call tools and data sources, noting it was built for interoperability and ease of use first, so security gaps show up as agents get wired into more systems.
Put those two Gartner forecasts together and the shape of the next eighteen months gets clear. Attackers get faster tools for old attacks like credential theft. Defenders get a new category of internal risk from agents that were never attackers at all, just under-supervised.
There is a third piece to this, and it shows up in how identity vendors and analysts are talking about non-human identities. Every agent that gets deployed needs credentials, API keys, service accounts, and permissions to do its job, and those machine identities are multiplying far faster than the human identities security teams are used to governing. A large bank might have tens of thousands of employee accounts and, within eighteen months of adopting agentic workflows at scale, an order of magnitude more machine identities tied to agents, scripts, and automated pipelines. Most identity governance programs were built to review human access on a quarterly or annual cadence. Nobody has a mature process for reviewing what ten thousand agents are individually authorized to do, and that gap is exactly where the next round of incidents Gartner is forecasting will originate.
The Delegation Boundary
The concept that matters here is not "AI security" as a product category. It is what I call the delegation boundary, the explicit line an organization draws between decisions an agent can make on its own and decisions that require a human to confirm before anything executes.
Most enterprises deploying agents today have not drawn this line on purpose. It gets set by default, by whatever the vendor's out-of-box permission scope allows, or by whichever engineer configured the integration fastest. That is the gap agentic AI is opening in the CISO's job. Access management used to be about which humans could reach which systems. Now it is about which autonomous processes can take which actions, at what dollar value, against what data, without a person in the loop. That is an identity and authorization problem before it is a threat-detection problem, and most security organizations are still staffed and tooled for the old version of the question.
Drawing that line on purpose means someone has to inventory every agent in production, document what it can decide unsupervised, and revisit that authority every time the agent's integrations change, not just when it is first deployed. Most organizations I work with have an inventory of their major AI deployments. Very few have an inventory of the specific decisions those deployments are authorized to make without a human in the loop, which is a different and harder document to keep current.
Consider a mid-size insurer that deploys an agent to triage and auto-approve small claims. The team sets the authority threshold at $2,500, reasoning that anything above that already required a human adjuster. Six months in, a vendor integration change lets the claims agent chain a document-verification tool with a payout tool without the intermediate human check that existed in the original design. Nobody removed a control on purpose. The delegation boundary just moved because two systems got connected in a way the original threat model never anticipated. That is the failure mode agentic AI introduces, and it looks nothing like a traditional intrusion. No credential was stolen. No perimeter was breached. The system did exactly what it was built to do, at a scope nobody signed off on.
The Strongest Case Against This Timeline
The fair counterargument deserves full weight, because it comes from the same source as the alarming numbers. Gartner also predicts that more than 40% of agentic AI projects will be canceled by the end of 2027, citing rising costs, unclear business value, and inadequate risk controls. And Gartner's own 2026 Hype Cycle for Security Operations places AI SOC agents at the peak of inflated expectations, the point in the cycle where a technology's near-term impact is typically overstated before it corrects downward.
Taken together, that is a real argument that this eighteen-month forecast overreaches. If four in ten agentic projects die before they reach production scale, the CISO's job may not be restructured by autonomous agents so much as it is restructured by the return to boring, well-scoped automation after an expensive round of pilots gets shelved. Boards approved agentic AI budgets in 2025 expecting broad autonomy. Many of those budgets will fund something narrower and more supervised than what was pitched.
I think both things are true at once, and that is the honest read. The projects that get canceled were mostly never going to carry meaningful decision authority. The identity and access architecture problem is real regardless of how many pilots survive, because the agents that do reach production, the claims triage systems, the code-deployment agents, the customer-facing support agents, are exactly the ones making consequential decisions with the least mature governance around them. Cancellation rates tell you about vendor spend. They do not tell you whether the delegation boundary on your surviving deployments is drawn correctly.
What Leadership Should Ask Monday Morning
For leadership and the board, the next eighteen months come down to a short list of concrete questions, not a strategy deck.
Which of our deployed AI agents can take an action with financial, legal, or safety consequences without a human confirming it first, and who approved that threshold.
When two systems get integrated, who is responsible for re-testing whether the combination created a new authority the original design did not intend.
Does our incident response plan distinguish between an agent that was compromised by an attacker and an agent that behaved exactly as built but at a scope nobody authorized.
What percentage of our agentic AI budget is going toward projects with a defined decision boundary versus projects still running on default vendor permissions.
How many machine identities tied to AI agents exist in our environment right now, and when was the last time anyone reviewed what each one is actually permitted to do.
The CISO who answers those questions cleanly in eighteen months will not be the one who bought the most AI security tooling. It will be the one who could always tell leadership and the board exactly what every deployed agent was allowed to decide, and why.
The attackers are not waiting for your governance committee to finish its next meeting.