When an AI agent gets write access to a core system, somebody signs off on that. The real question is not whether AI and cybersecurity are connected. It is who at the company holds the authority to say yes or no when the two collide, and whether that person has ever sat in the same room as the people on the other side of the decision.
This article is grounded in current advisory work, not retrospective analysis. Mark Lynd is a 5x CEO/CIO/CISO with Thinkers360 Top 10 global rankings across Cybersecurity and Artificial Intelligence and was ranked #1 globally in Cybersecurity in 2023. He is currently Head of Executive Advisory and Strategy at Netsync, advising enterprise C-Suites and boards on the AI and cybersecurity questions moving fastest in 2026. The frameworks and patterns referenced here are from active engagements this quarter.
Who Actually Holds the Pen
Most companies still route AI decisions and cybersecurity decisions through different desks, and that split is not neutral. IANS Research and Artico Search's 2026 State of the CISO report found that 64 percent of CISOs still report into IT leadership, while 36 percent report to business leaders such as the CEO, COO, general counsel, or chief risk officer. That reporting line determines what a CISO can veto and what they can only flag. Meanwhile the AI buildout is happening in product, in operations, in the CFO's office, in whatever team got budget for an agent pilot first. Those two chains of command rarely intersect below the CEO.
The result is a governance gap that shows up as timing, not ideology. Gartner's 2025 Board of Directors research found that 86 percent of organizations are piloting or deploying AI, but only 18 percent of boards are actively using AI tools themselves. Boards that have not touched the technology are being asked to approve budget for it and to accept the risk it creates, without a shared vocabulary for what "risk" even means in an agentic system. A board that understands ransomware does not automatically understand what happens when an autonomous agent misreads a prompt and moves money, deletes records, or grants itself a permission nobody meant to give it.
The mechanism forcing this is not philosophical. It is identity sprawl. CyberArk's 2025 identity security research found that machine identities now outnumber human identities by more than 80 to 1 inside the average enterprise, and every AI agent, every service account, every automated pipeline adds more of them. Each one is a decision point. Who approved its scope. Who reviews its access quarterly. Who owns the consequence when it is compromised or simply wrong. In most org charts today, the honest answer is nobody in particular, because the identity was created by a product team moving fast and inherited by a security team that found out after the fact.
This is not a small accounting problem that a quarterly audit will catch up on eventually. Identity sprawl compounds. A single agentic workflow can spin up sub-agents, each with its own service credential, to handle parallel tasks, and those sub-agents can persist long after the project that created them has been shelved. Security teams built their access review cadence for a world where a new employee account was a rare, deliberate event. They were not built for a world where a developer can generate forty new non-human identities before lunch. The organizations that treat this as an IT hygiene issue rather than a leadership decision are the ones that will find out the hard way which of those forty identities still had standing access a year later.
Here is what that looks like on the ground. A regional bank's operations team stands up an AI agent to triage customer service tickets and, to save an integration step, gives it read-write access to the core account management system rather than a scoped API. Product ships it in six weeks because it cuts average handling time. Nobody in security reviewed the access grant, because the request came through the IT service desk as a routine account provisioning ticket, not as an AI deployment. Three months later the agent, following a prompt injection buried in a customer email, issues an unauthorized refund pattern before anyone notices the drift. The postmortem finds no single villain. It finds a decision that nobody with the authority to say no ever actually saw.
The Case for Keeping Them Separate
The strongest objection to treating this as one decision surface is that AI and cybersecurity are genuinely different disciplines, and collapsing them risks producing generalists who are shallow in both. A CISO trained in identity and access management, incident response, and regulatory frameworks is not automatically qualified to evaluate model drift, training data provenance, or whether a large language model is hallucinating with confidence. Forcing every AI decision through a security lens can also slow legitimate experimentation to a crawl, and companies that over-govern AI adoption early tend to lose the internal champions who would otherwise drive safe, well-scoped use. There is real evidence for functional specialization elsewhere in the enterprise. Finance and legal stayed separate for good reason even though both touch risk.
That argument holds for expertise. It does not hold for decision rights. Nobody is proposing that the CISO personally evaluate model architecture, any more than the CFO personally audits every vendor contract. The point is narrower and more urgent. Whoever approves an AI system's access to production data, financial systems, or customer-facing actions needs security review as a gate before deployment, not as a discovery process after an incident. That is a workflow question, not a staffing question. You do not need one person who is expert in both. You need one point where the two chains of authority are required to meet before anything ships.
There is also a real cost to getting this wrong in the other direction. A security function that inserts itself into every AI decision as a blocking approval step, rather than a fast, scoped review, will train the rest of the company to route around it. That is the actual failure mode in most large organizations today, not recklessness but avoidance, where product teams learn that the fastest path to shipping is to describe an AI feature in terms that do not trigger a security review at all. A decision-rights model that is too slow produces the same blind spot as one that does not exist, just with better documentation of how it happened.
What Leadership and the Board Should Ask This Week
The fix is not a new title. It is a forcing function. Every AI system that touches production data, customer accounts, or financial workflows should have a named human who is accountable if it goes wrong, and that name should not be discoverable only in a postmortem. Leadership and the board should be asking, specifically, which AI systems currently in production or pilot have production data access without a documented security review. They should ask who has the authority to pause an AI agent's access without waiting for a committee to convene. They should ask whether the security team has visibility into every AI-driven service account, or only the ones that were provisioned through the normal IT process. They should ask when the board itself last reviewed an actual AI incident, not a vendor's slide deck about AI risk in the abstract.
None of these questions require the board to become technical. They require the board to insist that the org chart reflect where the risk actually lives, not where it was convenient to file it two years ago. A useful test is to ask the CISO and the executive sponsoring the company's biggest AI initiative to describe, independently, who has final authority to stop an AI deployment. If the two answers do not match, the decision right does not actually exist, no matter what the org chart says.
Companies that answer these questions now, while the identity sprawl is still countable, will spend far less fixing it later than the ones who wait for an agent to answer the question for them.
The intersection of AI and cybersecurity is not a trend line on a slide. It is a specific desk, in a specific org chart, that either exists or does not, and most companies still have not built it.