AI agents are rapidly changing how businesses operate, reshaping the cybersecurity landscape for users, and spreading risk across every level of the organization.

The appeal of deploying this technology is enormous. According to a recent Gartner report,enterprises are expected to more than double their spending on generative AI models and AI agents, investing an additional $6 billion in 2026. Some organizations say agentic systems are used forvery specific tasks, while others have already embedded AI into human decision-making processes and plan to run it without human intervention in most cases.

Over the past month, more powerful new models such as Anthropic's Mythos and OpenAI's Daybreak initiative have highlighted thelevel of accessthat agentic AI can obtain. Executives must guide their organizations to adopt new risk management models to adapt to the changing cybersecurity landscape in the agentic era.

According toa recent Okta report, more than half of executives said their organizations experienced an AI-related security incident or near miss last year. As cyber risks draw increasing attention, AI vendors themselves are also entering the enterpriseAI security managementspace.

Although many enterprises are quickly jumping on the agentic AI bandwagon, technology leaders are realizing that these systems present a complex mix of pros and cons for organizations, Gartner Senior Director Analyst Shiva Varma told CIO Dive. Agentic AI is changing the types and frequency of risks enterprises face and making security a shared responsibility across the organization.

"They don't solve all problems; they come with a lot of risk, and they are expensive to run," Varma said.

A new risk landscape

Agentic AI has moved beyond generating text, images, or code to making decisions and executing tasks, performing work traditionally done by human employees, said Aunshul Rege, cybersecurity professor at Temple University.

A typical agent might access the internet, query databases, or retrieve sensitive information across an enterprise's knowledge base. Because AI agents are given this autonomy, their permissions must be carefully considered, said Janet Worthington, senior analyst at Forrester.

Worthington said she has observed a trend of clients giving agents too much access in pursuit of productivity. Although enterprises have AI usage guidelines or policies for employees, agents are built to accomplish tasks, Worthington said, and they often do so at all costs. When enterprises embed agents into systems, they may learn to bypass security barriers or guardrails, even overcoming security-related roadblocks they encounter.

"Every time they take an action, they learn from it, so when they encounter a problem in the real world and are asked to do something, they go back, learn, and try a different way," Worthington said.

Humans do this too, she said. But agents don't "clock out," she added.

"If we don't start treating these agents as separate identities and constraining them, we will see more problems," Worthington said.

Cliff Steinhauer, director of information security and engagement at the National Cybersecurity Alliance, compared the rise of agentic AI to the cloud revolution a decade ago. Enterprises are moving from operating their own devices and processes to automation.

"When we adopt new tools, the amount of risk changes," Steinhauer said. "It's a new skill, and there's much more to manage than before."

Beyond overreaching agents, the technology also makes enterprises more vulnerable to malicious external attacks, Rege said, because human behavior and trust still play a significant role. Employees may begin to trust automated systems as much as they trust human colleagues.

"Many attacks succeed because they exploit people, workflows, and organizational protocols," Rege said.

Who is responsible for secure AI?

Historically, cybersecurity has been the responsibility of the CISO or IT department. But AI systems used across the organization are breaking down this structure, Rege said. The biggest challenge for technology executives is no longer control, but coordinating the organization's technology strategy,Deloitte recently found

HR departments may use AI for recruiting, finance may use agents for procurement or analysis, and legal teams may use AI for contracts. Security teams cannot manage all these decisions in isolation.

"I think what we're seeing is a shift toward shared responsibility," Rege said.

Technology leaders like CIOs may be responsible for deciding which AI models to use, while cybersecurity teams implement controls, Steinhauer said. HR and other people-focused teams may be responsible for enforcing policy violations.

"Keeping these teams aligned is very important," Steinhauer said.

The CISO role is also changing, Worthington said. The role is evolving into a trust and assurance authority within the organization, needing to consider AI outputs, whether those outputs are auditable, and how to explain results to the board.

Steinhauer said he has seen AI management roles added to the C-suite, such as chief AI officer.

"The problem with AI is that it can do many things but lacks context, so you need someone who understands the business and can understand the context of your business," Steinhauer said. "They can answer: 'Is this the output we expect from using AI?'"

Security and governance

The rollout of AI has been accompanied bya desire for governance, although many organizations struggle to determine which guiding principles should apply. But simply having governance policies does not mean security risks disappear, Rege said.

Executives should view governance as a set of rules for how human employees should use AI, Steinhauer said. This is where organizations should seek collaboration so all departments understand expectations.

"Governance raises questions like: Should we use this system? What decisions does it allow? Who is responsible if something goes wrong?" Rege said. "What level of human oversight is needed?"

Meanwhile, security strategies focus on protecting systems, data, and infrastructure from harm. It is closer to the traditional goals of cybersecurity teams.

Security, governance, and risk management should be reviewed cyclically, and policies may evolve as technology develops and organizations determine which tools are essential.

"Organizations should resist the temptation to view AI as magic or a disaster," Rege said. "A better approach is structured and risk-based."