CISOs rush to rein in AI agents as risks grow

71% of CISOs are testing AI agents and 78% name agent security their top pain point, Team8’s CISO Village survey finds.

Team8’s annual CISO Village survey found 71% of chief information security officers are testing or augmenting security tools with AI agents, and 78% ranked agent security as their top pain point.

Team8 is a venture firm that convenes an invitation-only community of enterprise CISOs and runs the annual survey to collect leaders’ views on technology gaps and risks.

Survey responses show CISOs are buying AI platforms, hiring staff with AI skills and building controls while acknowledging current defenses lag behind emerging threats. General cyber hygiene was listed as the second biggest concern at 39%.

Tim Brown, CISO at Team8, described two linked problems: adversaries increasingly use AI tools that bypass traditional controls, and organizations create operational risk by deploying agentic AI with broad privileges.

Employees use public coding tools and libraries to build agents. Some handle simple tasks such as daily email summaries; others process enterprise data to automate sales recommendations or change business workflows. More complex agents need deeper system access.

Brown highlighted how imprecise prompts can cause unintended actions. He noted that agents attempt to carry out instructions as they infer them and that model behavior is non-deterministic, so developers may not see obvious errors.

He gave a concrete example: “If an agent is tasked to gather background information, it could search any accessible system and end up probing production infrastructure instead of a test environment.” Such behavior can risk data exposure, service disruption or new attack paths.

Security teams are working to limit agent access without removing their business benefits. Brown cautioned against blunt measures that simply disable systems and recommended embedding guardrails in the agent development lifecycle so agents are constrained by design.

Brown urged more transparency and experience sharing among security leaders so teams can learn from each other’s solutions and reduce repeated mistakes as agent deployments increase.

Articles by this author