CISOs Build AI Security Guardrails Without Blocking Innovation
According to TechTarget, 97% of organizations that suffered an AI-related breach lacked proper AI access controls, per IBM's Cost of a Data Breach Report 2025, even as McKinsey found 88% of organizations now use AI in at least one business function, up from 78% a year earlier. IBM also found shadow AI use added roughly $670,000 to the average cost of an AI-linked breach. For CISOs, the practical guidance is to establish governance before technical controls: appoint a single accountable owner, build an AI risk register, and align to frameworks like NIST's AI Risk Management Framework and ISO/IEC 42001:2023, then layer in zero-trust access, data-loss prevention, and continuous monitoring for AI agents and copilots.
The two numbers in this story sit next to each other for a reason: AI adoption inside enterprises jumped 10 percentage points in a year, and the breaches that followed trace almost entirely to a preventable gap, missing access controls, not novel attack techniques. For teams already running AI in production, the practical takeaway is to fund AI-agent identity and access management first, not last.
What happened
According to a TechTarget analysis by vCISO Matthew Smith (published June 11, 2026), McKinsey's State of AI: Global Survey 2025 found 88% of organizations now use AI in at least one business function, up from 78% a year earlier. IBM's Cost of a Data Breach Report 2025 found that 13% of organizations experienced a breach involving AI models or applications, and 97% of those breached organizations lacked proper AI access controls. IBM separately reported that shadow AI, unsanctioned employee use of AI tools, added roughly $670,000 to the average cost of a breach.
Security context
The article frames the fix as governance-first: appoint a single role accountable for AI oversight, build a risk register that tracks AI benefits and threats together, and write AI-specific policies for acceptable use, data handling, and training. It points to NIST's AI Risk Management Framework, ISO/IEC 42001:2023, and NIST Special Publication 800-221A, which organizes controls into a Govern function (roles, policy, benchmarking) and a Manage function (risk identification, response, monitoring). Technical guardrails layer on top: data-loss prevention on AI interfaces, zero-trust and time-bounded access for AI agents, input validation against prompt injection, and SIEM-correlated monitoring of agent activity.
For practitioners
The article's own checklist is concrete: appoint an AI governance lead, build the risk register, classify the data AI systems can access and enforce DLP, apply zero-trust identity to every agent and copilot, and audit third-party AI components for supply-chain risk. It cites exposed admin interfaces and leaked API keys in the OpenClaw agent ecosystem as a cautionary example of what happens without that scrutiny. Common pitfalls it flags: treating AI security as a one-time project, granting agents broad permissions for convenience, and waiting for a breach or a regulation to force the issue.
What to watch
Compliance deadlines add pressure to act: the EU AI Act's requirements for high-risk systems, New York City's Local Law 144, and the California Privacy Rights Act all apply to automated decision-making. Watch for uptake of AI-specific access-control and observability tooling, and whether future breach data narrows the 97% access-control gap as governance frameworks like NIST AI RMF and ISO/IEC 42001:2023 see wider adoption.
Key Points
- 1IBM's 2025 breach report found 97% of organizations with an AI-related breach lacked proper AI access controls despite surging adoption.
- 2Shadow AI and ungoverned agent permissions, not new attack techniques, drove most of the reported AI-related security incidents.
- 3Practitioners should prioritize zero-trust access and frameworks like NIST's AI RMF before scaling further AI deployments.
Scoring Rationale
Practical, well-evidenced CISO guidance grounded in named primary data (McKinsey's State of AI 2025 survey and IBM's Cost of a Data Breach Report 2025) via a substantive TechTarget analysis; useful for practitioners but a synthesis/how-to piece rather than new research, keeping it in the solid-not-major band.
Sources
Public references used for this report.
Practice interview problems based on real data
1,625 SQL & Python problems across 15 industry datasets — the exact type of data you work with.
Try 250 free problems

