Alarming Insights from Okta’s Global CISO Insights 2026 Survey
In a recent survey conducted by Okta, 306 Chief Information Security Officers (CISOs) were queried regarding their confidence in the artificial intelligence systems operating within their organizations.
A staggering 81 percent expressed substantial concerns. This issue, however, transcends mere trepidation—many security executives are unable to perceive or govern these AI entities for which they are ostensibly responsible. This predicament morphs AI governance from a mere control issue to a pressing visibility challenge.
- Okta’s investigation encompassed 306 CISOs and cybersecurity leaders across six distinct markets; 81 percent are apprehensive that their AI agents operate without sufficient oversight.
- Merely 47 percent reported the ability to identify every agent, while 46 percent asserted they can control the connections these agents forge.
- A mere 12 percent of US CISOs indicated a strong alignment with their boards on the risks associated with AI, revealing a significant authority gap.
Confessions of CISOs Regarding Their AI Agents
The responses to a fundamental query posed to the CISOs reveal a troubling reality: over half could not furnish a comprehensive accounting of their AI agents’ locations.
Only 47 percent acknowledged they can identify each agent present within their infrastructure. Even fewer—46 percent—possess control over what these agents can access, and merely 45 percent can authorize their actions.
Okta fashioned its report around three pivotal questions that every security team ought to address: where are my agents situated, what connections do they possess, and what actions are permissible? Alarmingly, the majority of respondents could not answer any of these inquiries with assuredness.
The phenomenon of Shadow AI significantly contributes to this oversight. Approximately 68 percent of CISOs noted the existence of unauthorized AI implementations, as personnel introduce tools without the necessary approvals or security assessments.
Where sanctioned agents are permitted, the boundaries remain nebulous. About 20 percent of organizations allow these agents access to network resources via shared credentials or excessively permissive service accounts.
Furthermore, only one-quarter of respondents manage their agents within a dedicated access framework, a recurring shortfall highlighted across various AI governance inquiries for 2026.
Beyond agent management, 57 percent of these leaders express considerable apprehensions regarding potential AI-induced breaches, with anxiety levels rising to 84 percent in the United States.
The Impediments to AI Governance: A 12% Boardroom Discrepancy
Initially, the report may appear to reflect a maturity challenge: catalog the agents, enforce stricter access protocols, and bridge the existing gaps.
While this interpretation aligns with Okta’s focus on identity governance, it fails to capture the essential underlying issue—authority rather than merely tools.
Only 31 percent of CISOs feel fully supported by their CEOs and boards in determining the acceptable levels of AI-associated risks; this figure plummets to 12 percent within the US context.
Fewer than half of the participants believe their boards perceive AI security as a facilitator of business growth rather than a hindrance.
This alignment gap represents a fundamental risk. A security team can procure an access framework, but it cannot single-handedly impede the deployment of AI systems championed by the CEO for enhanced productivity.
When 81 percent of security leaders harbor concerns regarding ungoverned access, contrasted with boards who maintain an aggressive push for innovation, accountability has indeed outpaced authority.
This pervasive pressure is reflected across sectors: recent discussions highlighted that many CISOs are contemplating exiting their roles due to the overwhelming governance burdens.
Strategies for Security Teams to Rectify the AI Agent Visibility Deficiency
The sequence in which these strategies are applied is paramount. In governance, one cannot manage what is undiscovered, nor can one secure board endorsement without presenting a comprehensive inventory.
Commence an inventory sprint utilizing Okta’s three essential queries: Mobilize your identity and platform teams to ascertain the locations of each agent, their connections, and their accessible data. Currently, only 47 percent of your counterparts can adequately respond to the first question.
Eliminate shared-credential access before onboarding additional agents: Approximately 20 percent of organizations still permit agents to access systems via communal credentials or overly permissive service accounts.
Assign distinct scoped identities to each agent, ensuring adherence to the specialized access frameworks that only one in four organizations currently implement.
Leverage the dismal 12 percent alignment figure in your next board engagement: Establish a clear appetite for AI-related risks prior to the deployment of new agents.
Reframe security as an enabler that facilitates the strategic rollout under the oversight agreed upon by the board.

CISOs who find themselves unable to pinpoint the locations of their agents are far from alone; a substantial 81 percent of survey respondents share this concern.
The path forward necessitates an inventory and a board directive to act decisively, with this quarter pivotal for transforming AI governance from mere anxiety into actionable initiatives.
Source link: Cybersecurity-insiders.com.






