
Previously, the chief information security officer was mainly seen as the person in charge of firewalls, security policies, incident reports, and compliance checklists, but that perception no longer applies.
The threat environment has been altered by artificial intelligence, and as a result, the role of the CISO within the organisation has also changed. Security professionals now need to guard against AI-assisted attacks, oversee the organization’s own AI systems, ensure sensitive data is not misused, and help the business adopt new technology without introducing unacceptable risk.
The CISO has stopped standing at the edge of the business, waiting for something to go wrong, and now carries out his duties in the boardroom, within the product team, in the procurement process, and increasingly in the organization’s AI strategy.
Recent industry findings show how fast this change is happening. A 2026 Proofpoint study found that 78% of CISOs worldwide saw generative AI as a security risk, and 85% said ensuring the safe use of AI assistants, copilots, and automation would be a priority over the next two years. Meanwhile, 79% expected they could manage AI-related risks without increasing resources or expertise.
The main challenge is that CISOs must protect the organization from AI while also helping it use AI productively.
The CISO’s job has changed
For years, the CISO’s responsibilities were relatively familiar:
- Protect networks, endpoints, applications, and data.
- Lead security operations and incident response.
- Reduce the risk of ransomware, phishing, insider threats, and data breaches.
- Report security performance to top management.
- Support both regulatory compliance and business continuity.
These responsibilities remain important, but AI has added an extra layer of complexity.
Companies now offer public generative AI tools, internal copilots, machine-learning systems, autonomous agents, and AI-powered security products. Each of these systems can access sensitive information, connect to business applications, or make decisions at speeds humans can’t monitor manually.
As a result, the CISO must now ask questions such as:
- What kind of data can an AI assistant gain access to?
- Who approved that access?
- Can the system make confidential information available?
- Can an AI agent set up accounts, change the records, or send messages?
- What would occur if a model was manipulated?
- Can the organization explain how that automated decision was reached?
- Who should be held responsible in the case where an AI system causes harm?
They are not just technical issues since they also involve legal, operational, financial, ethical, and reputational risks.
That is the reason why the CISO’s role is expanding. Today, security leadership involves managing trust in AI-enabled business processes, not just preventing attacks at the network perimeter. According to Deloitte, the modern CISO’s role includes helping the organization identify AI risks across functions, address them, and step in when needed, rather than taking personal responsibility for every risk.
AI gives attackers a powerful advantage
The main concern right now is that AI will be used by people who pose threats.
Attackers have no need to come up with completely new kinds of crime in order to benefit from AI; they can use it to carry out known attacks more quickly, at a lower cost, in a more convincing way, and with greater ease of scaling.
More convincing social engineering
AI can produce highly personalized phishing emails, messages, and voice calls. A criminal can study publicly available information on a target, mimic the writing style of a senior executive, and make a believable request for money, credentials, or sensitive documents.
The situation is no longer just about spotting bad grammar or suspicious formatting; a carefully written message from an account that looks trustworthy can still be malicious.
Faster vulnerability discovery
AI tools can help by scanning code, identifying services, analyzing configuration errors, and deciding which targets to prioritize. Even if the basic techniques are not new, automation lets attackers apply them at scale and speed.
Automated reconnaissance
An AI-powered attack chain can gather information on employees, suppliers, cloud services, technologies, and exposed systems. It can then use that information to choose the most promising point of entry.
Adaptive malware
AI can help attackers alter payloads, avoid detection, and change tactics after observing the victim’s defences. This, in turn, puts pressure on security teams that still rely heavily on static rules and manually updated signatures.
Attacks on AI systems
AI systems can also be targets. The risks are:
- Prompt injection.
- Data poisoning.
- Model theft.
- Sensitive information leakage.
- Insecure plugins and integrations.
- Manipulation of autonomous agents.
- Abuse of model permissions.
- Actions that are hallucinated or unsafe.
Splunk’s 2026 CISO research found that 95% of surveyed security leaders considered the growing sophistication of threat actors their greatest risk, while nearly all reported responsibility for AI governance and risk management.
This for the CISO involves the attack surface now comprising not only the traditional infrastructure but also the intelligent systems connected to it.
The internal AI problem
The greatest risk posed by AI doesn’t have to come from a highly sophisticated external adversary; it could start with an employee trying to work more efficiently.
An employee pastes confidential customer information into a public chatbot. A developer uploads proprietary source code to an external AI service. The marketing team use an unauthorised tool to analyse internal reports. A finance employee asks an AI assistant to summarise a spreadsheet which contains personal or commercially sensitive data.
The actions need not be malicious; in fact, productivity targets might even encourage them. Yet they can still result in serious exposure.
The 2026 Proofpoint report found that 93% of Indian CISOs identified human risk as their organisation’s biggest cybersecurity vulnerability, up from 67% the previous year. It also reported that 92% of Indian CISOs were expected to manage AI-related risks without a proportional increase in resources or expertise.
This presents a difficult problem for leaders. Although a total ban on AI might reduce certain risks, it could also lead employees to use unauthorized tools secretly, and overly strict restrictions might push useful innovation outside the organization’s scope.
The better approach is controlled enablement:
- Approve particular AI tools for particular business purposes.
- State what information may and may not be entered.
- Apply data-loss prevention controls.
- Monitor how people access and use the system.
- Require human approval for high-impact actions.
- Provide secure internal alternatives.
- Instead of giving general warnings, train employees using realistic examples.
The CISO doesn’t want to prevent people from using AI; they want to ensure its use is visible, controlled, and appropriate to the sensitivity of the work.
AI agents create a new security challenge
Generative AI chatbots are just the starting point; the next big challenge will be AI agents.
Unlike a simple chatbot, an agent may be able to:
- Read internal documents.
- Search company databases.
- Create tickets.
- Send emails.
- Update customer records.
- Execute code.
- Initiate workflows.
- Purchase services.
- Engage with other software agents.
It alters the meaning of identity and access management.
In the past, security teams have been in charge of human users, service accounts, devices, and applications. Now, AI agents have created a rapidly growing number of non-human identities that can operate continuously and make decisions without direct human input.
Every agent needs:
- A clearly defined identity.
- Limited permissions.
- A named business owner.
- An approval process.
- Activity logging.
- Rate limits.
- Continuous monitoring.
- A rapid shutdown mechanism.
An AI agent ought not to be given wide-ranging access merely because it is convenient to set up; if an agent only needs to read a particular data set, it should not be allowed to alter the whole enterprise database.
Just as it does in the case of people, the principle of least privilege must also be applied to machines.
CISOs must also consider how agents communicate with each other. If one compromised agent can tell another to carry out a sensitive action, the organization could fall victim to a new type of automated attack chain.
That is the reason why AI governance must be linked with identity security, data governance, application security, and incident response.
From gatekeeper to business partner
The modern CISO must carry out two tasks simultaneously: reducing risk and promoting innovation.
Leadership therefore has to take a different approach. A security team which only replies with ‘no’ will eventually be circumvented, while one that says ‘yes’ without any safeguards may cause the organisation to suffer unacceptable harm.
A good CISO can explain risks in language appropriate to a business context.
Instead of saying:
The model is too open to prompt injection.
The CISO may need to explain:
A malicious instruction might lead the customer-service agent to reveal private records or carry out an unauthorised action.
Instead of reporting only the number of blocked attacks, the CISO should discuss:
- Which business processes are the most exposed?
- The speed at which the organisation can detect misuse.
- The amount of sensitive data that an AI system can access.
- Whether or not critical decisions have human oversight.
- The duration for which the organisation will be able to function if an AI service fails.
- If the suppliers satisfy the organisation’s security expectations.
That is also why communication skills are as important as technical expertise; the CISO has to work with the board, the chief executive, the legal team, the data protection officers, the product managers, the developers, the procurement teams, and the employees.
AI security cannot be the security department’s responsibility alone.
What should boards expect from the CISO?
AI security should not be regarded by the boards as merely a technical matter assigned completely to IT; rather, they should expect definite answers to a number of practical questions.
Which AI systems are currently in use?
The organization must maintain an inventory of approved tools, unofficial tools, AI features embedded in software, internal models, and autonomous agents.
What kind of data can they reach?
The board needs to know whether AI systems can access customer records, intellectual property, employee data, financial information, source code, or operational technology.
What kinds of decisions are they capable of making?
There is a big difference between an AI system that draws up a document and one that approves a payment, alters a production setting, or rejects a customer request.
What is the result when the system fails?
Any time an AI system is put into use, there must be a backup procedure in place. The organisation should know how to suspend, isolate or switch off the system.
How is performance monitored?
Correctness by itself is not sufficient; monitoring should also cover unusual access, data leakage, bias, harmful outputs, model drift, and changes in behaviour.
Who is accountable?
Each significant AI system must have a named owner. It is not acceptable to have ‘the algorithm made the decision’ as a governance model.
According to one of the Big4 analysis for 2026, the role of the CISO is less about personally taking responsibility for every AI risk and more about establishing accountability, visibility, and the ability to intervene throughout the organisation.
Building the AI-ready security function
A solid AI security programme doesn’t start by buying another tool; instead, it starts with clear foundations.
Establish an AI governance committee
The committee must include members from the security department, the IT department, the legal department, the privacy department, the risk area, compliance, human resources, procurement, and the business side. Its function is to establish acceptable use, approve high-risk systems, and resolve accountability issues.
Create an AI asset inventory
Document:
- AI models.
- Vendors and service providers.
- Data sources.
- Integrations.
- User groups.
- Permissions.
- Business owners.
- Retention and logging arrangements.
- Known limitations.
Classify AI use cases by risk
A system that summarizes public information is not the same as one that screens job applicants, supports medical decisions, or runs industrial equipment.
Risk classification should consider:
- Data sensitivity.
- Autonomy.
- Potential impact on individuals.
- External exposure.
- Business criticality.
- Reversibility of decisions.
Secure the data pipeline
The security of AI systems depends on the security of the data they receive, and organisations must protect training data, prompts, the documents retrieved, application programming interfaces, the outputs of the model, and the logs.
Controls must include encryption, access control, data minimization, validation, and monitoring for unauthorized changes.
Test before deployment
AI systems must undergo security testing that simulates how they will actually be used; testing should cover prompt injection, data exfiltration, malicious files, excessive permissions, unsafe tool calls, and attempts to get the system to ignore its instructions.
Keep a human in the loop
Human review is especially important when an AI system affects money, safety, employment, legal rights, customer access, or critical operations.
Human oversight should be substantial; someone who approves without sufficient time, context, or authority is not exercising real control.
The CISO’s new toolkit
The person in charge of information security in the age of artificial intelligence should have a wider range of skills.
Technical knowledge remains essential, but it must be combined with:
- AI and machine-learning fundamentals.
- Data governance.
- Identity and access management.
- Secure software development.
- Privacy and regulatory awareness.
- Third-party risk management.
- Responding to problems in AI systems.
- Business continuity planning.
- Executive communication.
- Crisis leadership.
Security teams also need to understand how AI can enhance defence.
AI can help analysts:
- Sort alerts.
- Identify unusual behaviour.
- Summarise incidents.
- Search threat intelligence.
- Find patterns in large data sets.
- Automate routine investigations.
- Recommend containment actions.
Automation should not be mistaken for accountability; even if a system quickly suggests an action, a competent analyst must know why that action is appropriate.
An effective way to operate is to combine “machine speed with human judgment”: let the AI handle routine and repetitive tasks, while humans retain authority for important decisions.
A practical checklist for CISOs
Security leaders should start by drawing up a targeted 90-day plan.
First 30 days
- List all AI tools that have been approved and those that have not been approved.
- Give the executive team an overview of the major AI-related risks.
- Define prohibited data categories.
- Review third-party AI contracts.
- Find the AI application scenarios and agents that present a high risk.
Days 31 to 60
- Assign AI systems to data sources and business processes.
- Review permissions and non-human identities.
- Check the most important systems for prompt injection and data leakage.
- Set up the logging and monitoring requirements.
- Draft a policy on employee AI use, including practical examples.
Days 61 to 90
- Hold an exercise about an AI-related incident.
- Set up an approval process for new AI deployments.
- Prepare a risk dashboard for senior leadership.
- Specify shutdown and recovery procedures.
- Align the AI security roadmap with the overall cyber-resilience strategy.
This method won’t eliminate risk; instead, it will give the organization visibility and a sense of control both of which are often lacking when AI adoption outpaces governance.
The New Front Line
The CISO has become one of the most important leadership roles in the AI economy, since security is now linked to almost every major business decision.
AI can boost productivity, speed up research, provide personalized services, and help defenders respond to threats. At the same time, it can expose sensitive data, magnify fraud, automate attacks, and lead to decisions no one fully understands.
The CISO is at that point where the two paths meet.
The most capable security leaders won’t be judged solely on the number of attacks they stop; instead, they will be assessed on whether the organization can confidently adopt AI, protect its data, recover from failure, and keep the trust of its customers, employees, regulators, and partners.
That means moving away from conventional perimeter defence toward constant supervision of people, data, models, agents, identities, and business processes.
The CISO is no longer just responsible for looking after the organisation’s systems; the role is now that of a guardian of digital trust, and in the age of AI, this makes the CISO as much a front-line business leader as a cybersecurity executive.




