Skip to content

Security1 publisher2 min readPublished

Team8's survey finds 71% of CISOs already putting AI agents into their security tools

The invitation-only CISO Village puts AI and agent security at 78% of the pain, double the next entry, and Team8's own CISO says the trouble starts with employees writing imprecise instructions for agents that can reach production.

The Watch · Security desk

Illustration accompanying Team8's survey finds 71% of CISOs already putting AI agents into their security tools

What happened

  • Team8's annual CISO Village survey reports that 71% of the security leaders it polled are experimenting with or augmenting existing security tools using AI agent capabilities.
  • AI and agent security came back as the biggest pain point at 78%, exactly twice the 39% recorded by whatever placed second.
  • The report's own summary says the risk surface is expanding faster than the control layer.
  • It also says CISOs are mobilizing before they feel fully ready, and are spending on platforms, skills and new control mechanisms.
  • The respondents come from CISO Village, an invitation-only global community of enterprise security leaders that Team8 convenes and surveys every year.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure An agent built by an employee can reach a production system on the open internet while doing what it was told, so the exposed surface is whatever its builder could reach and no adversary is needed to cause the damage.
  • constraint If MFA, firewalls and endpoint protection no longer decide whether an opportunistic attack lands, money already committed to that stack buys less assurance than the budget line assumed when it was signed.
  • decision Guardrail settings are a business call: every tightening removes agent function, and the security team has to own the capability it takes away.

The failure Tim Brown describes starts with the instruction. People rarely write down exactly what they want, the agent does precisely what it understands the instruction to be, and the non-determinism of the model sits on top of that [15]. Brown, Team8's CISO [7], said an agent is "a very resourceful employee that will do whatever it takes to accomplish the task it believes it has been given" [12]. His example is an agent told to collect background on a company from whatever it can find, public or private: it "could poke around in a production system anywhere on the internet as opposed to a test system" [13].

The agents in question are being built inside the business. Brown said employees are creating them with coding tools including Claude Code, Cursor and Codex [10]. The more complex the agent, the more critical the parts of the network it touches [11]. SecurityWeek frames the two pain points as adjusting to new hygiene requirements and preventing unintended consequences from over-privileged agents [17].

On hygiene, Brown said "What has been considered good security hygiene for the last 10 to 20 years is no longer adequate" [8]. He put a specific stack behind that: "We used to believe use of MFA and firewalls and good endpoint protection would prevent us becoming the victim of an opportunistic attack. Not anymore." [9]

The distance between the first pain point and the second is 39 percentage points, as large as second place itself [16]. The survey is opinion polling from a community Team8 convenes and surveys annually [6], run by a firm that invests in enterprise technology, cyber, AI, fintech and digital health companies [5]. SecurityWeek's account leaves out the second pain point and the number of respondents [18]. The 71% counts leaders experimenting with or augmenting existing tools with agent capabilities [1]. It is a statement about intent.

"It's easy to create 100% successful guardrails," he added. "I take the system, I unplug it, I throw it into the ocean. Then it's safe. Useless, but safe." [14]

What to watch

  • Whether Team8 publishes the CISO Village sample size, sector split and the second-place pain point.
  • Whether the control spending the report describes lands on privilege and identity products for non-human accounts, or on monitoring.
  • The first disclosed incident in which an employee-built agent reached production data it was never scoped to touch.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories