Analysts say AI is changing CISO risk management into decision governance
At Black Hat USA, theCUBE Research analysts argued that AI is expanding CISO oversight into business decisions, amid uneven enterprise controls.
By Dominic Okoye · Staff Writer
· 3 min read
CISO AI risk management was the focus of a Black Hat USA 2026 discussion in which theCUBE Research analysts Krista Case and Jon Oltsik argued that AI is pushing security leaders toward oversight of business decisions and automated actions. Their view is an emerging analyst interpretation, rather than evidence of an industry-wide change, but Gartner’s reported figures point to the governance gap: 79% of organizations say employee AI-tool use is outside acceptable-use policy, while 53% have deployed custom-built AI agents.
Case, theCUBE Research’s cyber resilience and security practice lead, said CISOs must connect legal, compliance, engineering, IT and business teams as companies decide where and how to use AI. The change is less about assigning the CISO unilateral authority over every AI deployment than about making security leadership part of the decisions that define acceptable risk.
How is AI changing CISO risk management?
Traditional security work centers on protecting systems, data and applications, then detecting and responding to compromise. Case’s April analysis says AI adds a separate governance problem when systems influence decisions or take actions across business processes. An erroneous output can affect operations, customers, compliance obligations, legal exposure and financial results, depending on the use case.
The analysis identifies three related risks: decision risk when AI affects an outcome; autonomous-execution risk when a system acts without human intervention; and systemic impact when AI is embedded across functions. It argues that the faster a system can act, the less time teams may have to spot and contain a problem. These are theCUBE Research’s analytical claims, not independently established measures of AI incidents.
Gartner reported in May that only 20% of cybersecurity teams described their GenAI use cases as highly beneficial. Its published excerpt does not provide methodology for those figures, so they should be read as Gartner findings rather than a definitive market census. Still, the combination of unsanctioned employee use and internally built agents gives CISOs a practical reason to seek a clearer view of AI activity.
Governance starts with decision rights and visibility
The immediate work is to inventory AI applications and use cases, including unapproved ones, then define risk boundaries early in a project. Gartner recommends mapping both risk and opportunity across AI initiatives and leading cross-team risk management. Case’s analysis similarly calls for validating outputs before they trigger action, monitoring AI behavior and applying controls that can detect and respond when problems appear.
For operators, a useful operating model is to document four questions for each use case: what decision or action the system can influence; what data, tools, permissions and third parties it uses; what validation and monitoring apply before and after action; and which business, security, legal, compliance and technical leaders can accept remaining risk. That framework is a synthesis of the analysts’ and Gartner’s guidance, not a prescribed standard.
It also changes the CISO skill mix described by Case: AI-risk literacy, awareness of the data and context behind outputs, and the ability to express technical exposure in business and financial terms. Security teams can support adoption with guardrails, but the evidence available here is largely analyst and consultancy guidance, not regulatory rules or broad enterprise-disclosure data.
AI may therefore make the CISO less of a final checkpoint and more of a participant in how risk decisions are structured. Whether companies actually give security leaders the authority, staffing and cross-functional access to do that remains unresolved.
This story draws on original reporting from SiliconANGLE.