Industry Insights

CISO Priorities in the Age of AI

AI is expanding the CISO role the same way the internet and the cloud did before it.

By Jeremiah Kung | Sep 23, 2026

TL;DR

AI is expanding the CISO role the same way the internet and the cloud did before it. My view is that security should be leading AI adoption inside the business, because we read risk more accurately than any other function. Priorities aren’t universal; they follow your own attack surface, and the call on whether AI spend is worth it stays with the business, not security — our job is making sure the controls hold. For the founders selling to us, early feedback matters more than the size of the contract.

—–

The CISO role has been expanding for years, and now AI is accelerating that expansion faster than any new tech innovation since the move to cloud. Every foundational technology follows a very similar path – something the business is curious about, to something it is quietly using everywhere, to the way work gets done. The internet completed that arc and the cloud completed it again. AI is still in the early stages now with all use cases yet to reveal themselves. This leaves security leaders with two questions that matter more than the rest: how our companies should be using it and how we are going to secure it.

The second question tends to get far more attention than it deserves relative to the first. Securing AI is necessary work and it deserves real time and budget, but the larger opportunity in this moment is for security to step outside its traditional lane and into business enablement. A well run Infosec program should understand the risk better than any other function in the company. That understanding is exactly what the business needs from us while it decides where AI exactly belongs.

Security should lead adoption

When times are scary, the instinct in our field is to stand at the gate and slow things down. There are situations where that instinct is exactly right; adoption of AI should not be one of them. The function that reads risk most accurately should be the function helping to direct how AI actually gets used across the business, and a security team that limits itself to approving or denying requests is spending its best judgment on the narrowest possible version of the job.

Taking that wider role means being present in conversations that have not always included security. A C-level security leader today sits with the business units and brings risk into those discussions alongside cost and timing. Speaking fluently across those functions is what gives Security a standing voice in decisions that are already being made.

How CISO priorities shift with your attack surface

There is no single AI playbook that works everywhere, and any framework presented that way should be treated with some suspicion. An organization working at government level operates under regulatory obligations that a consumer business will never encounter, and its attack surface is a fundamentally different shape as a result. The work truly begins with understanding your own risk before reaching for anyone else’s template. Adopting AI and putting it to real use is the right posture, together with a clear-eyed view of where it widens exposure. This is not something a vendor or external governing body can make on your behalf.

AI is a foundational shift, and cost belongs in the conversation

AI belongs in the same category as the internet and cloud –  a shift that eventually stops seeming remarkable because it has become universal. A change on that scale cannot be handled as something you bolt onto the existing stack, which is why cost needs to enter the security conversation early, while the architecture is still open and the decisions are still reversible.

There is a boundary worth stating clearly here. It is not the CISO’s job to tell the business whether AI is worth the money, and any security leader who claims that authority has misread the role. Our job is to make sure the controls hold and the risk is properly understood while the business makes its own decision. Partnering with the business is how that gets done, and it works considerably better than any attempt to route around them.

Controls and speed come before the platform question

The platform versus point solution conversation is coming and it will matter, but it is the second question rather than the first. What matters more immediately is defining which controls you need to keep in place, and understanding how quickly you can change them as the technology keeps moving underneath you.

Speed is the part that tends to get underestimated. A set of controls that fits this quarter may not fit the next one, so the capability that counts most is being able to adapt without losing your footing. Tool sprawl is a genuine concern, but early and innovative companies also tend to build as point solutions first. Consolidation will follow in time, so I would not let the sprawl concern crowd out the more urgent work of getting the right controls in place.

The security innovation worth watching sits in the AI identity layer, in the proxy / harness layer, and at the endpoint, where endpoint agents are back in fashion and in real demand. For now at least, these areas appear to cover most of the attack surface that AI use creates. Solving for the risks does not happen in a vacuum, partnering with vendors is key and there are a lot of early stage companies doing great work in the AI security space.

A note to the founders selling us

For the founders selling into companies, some of the standard advice will steer you wrong at this stage. Do not let price be the factor that drives your decisions with us. Being flexible is worth more to you right now than protecting margin, because the true long-term value really is feedback, this will drive your teams to build accordingly.

The space is moving quickly enough that the category you are selling into today may not exist a year from now, and the pivot that follows is often the correct move rather than a failure. This again makes the feedback more valuable to you than the contract, so do not let deal size set your direction. This does put real risk on the startup, which is why choosing the right early customers matters as much as anything else you decide in this period.

How you talk to us in those early conversations matters just as much. The warning that ״attacks now move at machine speed״ has become a fixture of the security pitch, and it is worth retiring. Every CISO you are selling to already understands how fast this technology moves, and hearing it delivered as a revelation makes the vendor sound like a used car salesman. It costs you credibility in the opening minutes, and that is difficult to recover inside the same meeting.

A note to my fellow CISOs

Stay technical. Keep building and keep understanding your own tools, because that command of the technology is still the ground everything else stands on. Being hands on to a decent degree will help tremendously. But also, put the same level of energy into learning how the business operates and who the people are behind it, since your strategy follows from that.

That context is earned in the room with everyone else. Honest feedback from your peers across the C-suite sharpens judgment in a way no dashboard can, and keeping a steady read on where the industry is heading is how you know whether your own stack is still strong. The technical core of the job has not changed. What has changed is the size of the role built around it.

The CISOs who do well through this period will hold onto their technical edge while stepping fully into the business, because the business is where the consequential decisions about AI are now being made.