preloader
Resources

Damage limitation mode engaged: How CISOs are managing agentic AI, one control at a time

RANT Roundtable September 2026

In Partnership With

There was a time when insider threats moved at the speed of humans. When they were centred around relatively predictable individuals. And attribution and intent were fairly easy to discern. Unfortunately for CISOs, that era is fast receding. The one that comes to replace it will be more chaotic, more complex and potentially more dangerous.

Today, AI agents dominate discussion of insider risk. They’re unpredictable, resourceful and move at machine speed. Just witness the growing roll call of sandbox escapes and rogue attacks by frontier AI systems. If left unmanaged, the technology could open the door to significant financial, reputational and regulatory risks.

So what’s the answer? To find out more, Mimecast recently brought together a bunch of harried cybersecurity leaders for another fascinating RANT roundtable.

“What we don’t know is the real challenge. Our ability to understand and visualise the data, have orchestration around data in motion, and know which humans are tethered to which agents,” argued Mimecast SVP EMEA, James Morgan. “Where is the balance between security and productivity? We want to make sure security teams don’t continue to have that reputation of blocking everything.”

The bane of our lives

It was pretty clear from the outset of the discussion that there are no easy answers. One CISO described agentic AI as “the bane of my life”. Another admitted: “we’re in damage limitation mode”. A third said: “I’ve given up trying to pretend I know what’s going on.” Yet another attendee noted how difficult it is to “convey risk to stakeholders” when IT is often one step behind the business in understanding the scale of adoption across the enterprise.

Several CISOs round the table bemoaned this lack of visibility. How can security leaders be expected to manage the risks associated with agentic AI when they don’t even know the size of the problem? One government security boss estimated that there may be as many as one agent per employee, across a department of 18,000 workers.

“My concern is we’re allowing it to create policy,” he said. “Would we be able to switch it off? We are watching from a distance as the world allows this thing to get out of control.”

The risk is far from theoretical. One CISO explained that his team is already seeing advanced prompt injection attacks where threat actors are hiding malicious instructions in emails read by agents. Part of the risk stems from “permissions given to agents irresponsibly”, he argued. But it’s also down to attacker sophistication.

“You think you have guardrails in place, but a clever chain of prompting can circumvent them,” he warned. “The prompts can be constructed in such a way that they create a narrative, spinning a story to the AI that works.”

A message to vendors: step up or get lost

Threat actors should therefore take some of the blame for agentic AI risk. But the most ire on the night was reserved for the vendor community. Security leaders were particularly displeased at third-party SaaS products with AI baked in.

“We have SaaS tools that look innocuous, but then vendors introduce AI capabilities we weren’t aware of,” said one. “You do your risk assessment but then it’s added at a later date.”

The message was loud and clear: vendors must be more transparent about the AI they build into products, and pure-play AI makers must take on more responsibility for the security of their offerings.

“They need to apply guardrails out of the box,” said one CISO. “I get that they want to push the envelope [with features]. But they’re effectively asking us to create guardrails. There needs to be a joint level of responsibility.”

Another argued: “They often say ‘we don’t switch anything on by default because we don’t know your organisation. Well, they need to reconsider what is the default.”

Many were frustrated at the lack of industry regulation and accountability for frontier model makers. “There’s a big elephant in the room,” said one. “The guys who created the models haven’t created the guardrails.” However, a peer sitting opposite admitted that the tech is moving so fast that it’s almost impossible for regulators to keep up.

Just one more thing

Ever the optimist, Mimecast CMO, Adenike Cosgrove, asked the assembled cybersecurity leaders to name a single action they’re taking to secure AI.

Some said they have AI champions in their organisation that help to disseminate knowledge and best practice internally. Another claimed she has blocked all shadow deployments “so we know exactly how many agents we have”. A third said his team has put in place governance frameworks to slow down adoption and “arrest the proliferation of AI so we can address it”.

However, governance looks different to different CISOs and in different contexts. Another attendee on the night said they use DLP and allowlisting to manage risks related to LLM-powered chatbots. But that for the agents used by development teams it’s about focusing on permissions. And for third-party SaaS they use procurement as a way to move governance and risk management upstream.

“You should be tracking usage rather than the tools themselves,” he said. “If use changes, it needs to go back through the approval process.”

Yet another CISO said she’s putting more effort into explaining to the company the “what and why” of AI so business users better understand the risks. “Awareness and education is sometimes overlooked, but it’s so important,” she argued.

Rotting our brains and corrupting our youth

The night ended with a lengthy detour into whether AI is slowly eroding our attention span and critical thinking skills. Millennials squared off against Gen Z-ers. But bubbling under the surface was a tension familiar to most CISOs: if an organisation becomes too dependent on a specific technology, it is more exposed to potential failure, compromise or disruption.

“What happens when AI is no longer a choice but is fully integrated everywhere?” asked one CISO. “We’re already there,” replied another fatalistically.

It was left to Cosgrove to round off the discussion on a more positive note by explaining how vendors can help.

“Someone has to enable an agent, put data into an LLM, or leverage a SaaS app,” she said. “We can tell you who’s doing what with AI, and how data is flowing through it.”

That’s as good a foundation for effective governance as any, as we enter a new era of agentic risk.

Mimecast secures humans, data & AI to protect your work. To learn more, head to www.workprotected.com