Zero Risk Isn't the Job: A CISO's Guide to Agentic AI
A guide for CISOs on managing agentic AI risks and ensuring security governance.
Security leaders are increasingly pressured to approve agentic AI use cases that have emerged recently. The role of a CISO is not to achieve zero risk but to make agentic risks visible and bounded, allowing for deliberate management of risks. This article outlines a framework for evaluating security risks associated with agents and discusses the governance of internal risks.