Four of Five 2026 Threats Are Governance Failures. That Is an Org Chart Problem.
By Jean-Hugues Migeon
Ninety-six percent of CISOs now own AI governance. Eight percent of technology leaders say their organisation actually has strong AI governance in place. The two figures come from different surveys and they are not strictly comparable, but the distance between them describes the year accurately: the job has been assigned almost everywhere, and almost nowhere has it been built.
Forrester published its top five cybersecurity threats for 2026 in June, and Cybersecurity Insiders made the useful observation about it this week. Four of the five entries are AI stories: near-autonomous attacks from nation states using cheap access to capable models, personal AI agents that reach into the enterprise through browser hooks and inbox access and then operate unsupervised, a sprawling supply chain of models, tools and skills that nobody has a manifest for, and identity systems that were never designed for software that acts on its own. Only the fifth entry, digital sovereignty across regions and technology stacks, sits outside the AI column.
Read that list as a threat forecast and it looks like an argument for more detection spending. Read it as a set of questions and it turns into something else. Which agents are running in your organisation right now, and what access does each one hold? Where did the models and skills those agents pull in come from, and can you show it? Which non-human account performed that action, and under whose authority? Three of the four AI entries are not attack innovations at all. They are the consequences of not being able to answer basic questions of record about systems the organisation deployed itself. The nation state entry is a real external threat, but the reason it lands is that the defender cannot see their own estate clearly enough to defend it at machine speed.
That shift matters more than the ranking. AI risk used to mean an attack arriving from outside with AI behind it. It increasingly means AI you bought, wired in and forgot to register, moving data faster than any human review cycle can follow. An agent reading a mailbox is not an intrusion. It is a deployment, approved by somebody, documented by nobody.
Which brings up the second number, and the more uncomfortable one. Splunk's CISO Report, drawn from 650 global security leaders, found that 96% of CISOs now own AI governance and risk management across the enterprise, that 78% fear personal liability for a breach they will have to answer for to a regulator or a board, up from just over half a year earlier, and that 26% seriously considered leaving the job in the past twelve months. The same report finds most of those leaders genuinely like AI on their own consoles: 92% say it lets their teams review more security events. The burnout is not coming from the tooling. It is coming from the shape of the mandate.
Because what happened at most organisations was not the creation of an AI governance function. It was a line added to an existing job description. AI governance landed on the CISO because the CISO was the nearest executive who already owned something adjacent and could not credibly refuse. The accountability transferred cleanly. The authority did not. Security is now answerable for AI systems it does not choose, does not fund, frequently does not know about, and cannot decline, in an organisation where 85% of business leaders lack basic cybersecurity fluency. Ask a risk committee who signed off on the agent that has standing access to the finance mailbox and you will usually get a name from marketing or operations, if you get a name at all.
So the practical conclusion from Forrester's list is not a control recommendation. It is an organisational one. AI governance needs to be a named function with its own responsibility matrix, not an annex to the security remit. Business owners decide to deploy and therefore own the risk of deploying. Security owns the controls. Privacy owns the lawful basis. Procurement owns what enters through vendors. Internal audit tests the whole thing. Somebody, and it needs to be one identifiable somebody, owns the register that ties those roles to each actual system in use and keeps it current. Without that last role, the other four are arguing about an estate none of them can enumerate.
Counting comes before attesting, and it is the step organisations skip because it is unglamorous. You cannot demand an AI bill of materials from a vendor for a system you have not recorded. You cannot give an agent its own identity and provenance trail if the agent was never declared. You cannot report AI risk to a board in a form the board can act on if the underlying inventory is a spreadsheet somebody maintains between other duties. This is the layer Anove built insAIght to operate: a register of AI systems and agents where each entry carries a named owner, the obligations that attach to it, and the evidence trail behind those obligations, so that the answer to a supervisor's question is a record rather than a reconstruction. The AI supply chain problem in Forrester's list is the same problem NIST addressed for conventional systems in SP 800-18 Rev. 2, arriving faster and with less documentation.
Board reporting is the part that converts personal liability into defensible accountability. A policy proves intent. A dated record of what was deployed, who approved it, which controls applied and what was found when it was tested proves governance. The first one does not help an executive facing a regulator. The second one does, and it also survives the executive.
That is the sharpest advice in the Splunk coverage, and it deserves to be read less cynically than it sounds. Build the programme so that it holds up after your tenure ends, because the audience for the record may be a regulator, or law enforcement, or your successor. Right now, for a quarter of security chiefs, the audience is a hiring manager. Any board still treating AI governance as a line item on someone else's job description should notice that the people holding the liability have already started planning around it.
Learn more
- insAIght, Anove's platform for keeping an owner-attributed register of AI systems and the evidence behind their controls.
- ExplAIn, for a quick read on how a specific AI tool behaves before it becomes something you have to account for.
- NIST SP 800-18 Rev. 2: Supply Chain Risk Moves to the Heart of System Planning, on why the manifest question came first for conventional systems.
- Cybersecurity Insiders, Four of Forrester's Top Five 2026 Threats Are AI Governance Failures and A Quarter of CISOs Considered Quitting as AI Governance Landed on Them, both 28 July 2026.
If AI governance has landed on your desk without the register, the ownership map or the evidence trail that would make it defensible, that is the conversation we have most often. Book a demo and we will walk through what a governance record looks like when it is built to be tested.