A Team8 survey of its invitation-only “CISO Village” found that 71% of chief information security officers are experimenting with, or augmenting existing security tools with, AI-agent capabilities. The survey identifies AI and agent security as respondents’ biggest pain point, cited by 78%—twice the level of the next concern, at 39%.
It also concludes that the risk surface is expanding faster than organisations’ control layer, although CISOs are investing in platforms, skills and new controls despite not feeling fully prepared.
Speaking to SecurityWeek, Team8 CISO Tim Brown said security leaders face two related challenges: adapting long-standing cyber-hygiene assumptions to attacks increasingly assisted by AI, and controlling risks introduced by agentic AI without undermining its business value. Employees can create agents using widely available coding tools such as Claude Code, Cursor and Codex, ranging from email summarisation to systems that analyse enterprise data and recommend sales priorities.
More complex agents may access critical network resources, while imprecise instructions and AI’s non-deterministic behaviour can produce unintended actions.
Brown warned that an agent may behave like a highly resourceful employee, pursuing what it believes is its task across public and private systems, potentially reaching production environments rather than test systems. He recommended embedding guardrails during development to restrict where agents can go and what they can do, while avoiding controls so strict that the agents become useless.
He also called for greater transparency and experience-sharing among security leaders, so organisations do not have to solve the same problems independently.