CSAIChaptersEventsBlog
Publication Tag

AI Security Through the CISO Lens

Insights from the AI Storm Summit Series

Released: 07/28/2026

AI Security Through the CISO Lens
Frontier artificial intelligence capabilities are majorly restructuring the economics of cyber offense and defense. In response to these industry-wide upheavals, CSA hosted three AI Storm Summits in Washington, D.C., San Francisco, and New York.

Pulling from those discussions, this paper captures how security leaders are responding to AI-generated exploits and attack automation. It examines why traditional vulnerability management processes, identity and access frameworks, third-party risk programs, and governance models are struggling to keep pace. It explores the shift from periodic assessments to continuous AI-assisted vulnerability management. This shift includes the need to detect, validate, and remediate findings at machine speed without sacrificing meaningful human accountability.

Readers will also learn how agentic AI governance, harness architecture, workforce transformation, operational resilience, and resource constraints are shaping CISO cybersecurity strategies. The findings reflect qualitative practitioner perspectives, highlighting areas of agreement, persistent tension, and genuine uncertainty across the security community.

Key Takeaways:
  • How AI is accelerating vulnerability discovery and exploitation
  • Why CVE, CVSS, and other existing vulnerability frameworks may be inadequate
  • How to approach agent inventory, identity, least privilege, and lifecycle management
  • Why governance and remediation infrastructure must operate at machine speed
  • How AI is reshaping third-party risk, security teams, and board communication
  • Where human oversight remains essential in AI-assisted security operations

Download this Resource

Prefer to access this resource without an account? Download it now.


Best For IconBest For:
  • CISOs and CSOs
  • Security and risk executives
  • Enterprise security architects
  • AI governance professionals

RISING TO THE CHALLENGE

An introduction by Rich Mogull, Chief Analyst, CSA

It’s hard to briefly summarize both the changes AI is bringing to the world, and our response as a security community. AI is clearly both deeply disruptive in ways we can only partially characterize, with aspects that are simultaneously overhyped. As the professionals charged with managing the risk of technology for our organizations and society, we are tasked with cutting to the core and figuring out how to safely enable AI in the midst of mass enterprise adoption, while defending against AI-powered threats.

It’s the kind of challenge none of us can meet alone. And it’s bringing our community together like I have never seen in my 25-year career.

This paper is the summary from three in-person CISO summits that drew hundreds of attendees. These weren’t conferences; everyone walking in the door was expected to be an active participant. To share their knowledge, express their concerns, and help drive the security of and from AI forward. We had representatives from the biggest banks and small educational institutions. From retail to healthcare. From various levels of various governments.

This document is our best attempt to pull together the key themes and findings. It’s based on hand-notes, which no matter how well done always have gaps, especially as we broke out into different working groups and couldn’t capture every discussion.

The overriding sentiment of all the events is that AI presents real challenges and opportunities. That it will force a re-orientation of our security programs and technologies that will be challenging in the short-term as the technology favors attackers more for now but will likely eventually favor defenders. Today we are dealing with AI-generated exploits, AI-driven attacks, and our own AI infrastructure as targets. But in the future, we don’t know when AI will materially harden our software and hardware and dramatically reduce the number of vulnerabilities in shipped code. It will autonomously monitor our infrastructure and call in the human responders when needed. It will help harden and continuously assess our infrastructure.

These meetings were a start, not a finish, and are now directly feeding into the research of the Cloud Security Alliance, RSAC, SANS, FIRST, and other organizations. We are just starting to see the power when we all come together and exchange knowledge instead of working in our own little silos. We don’t know exactly what the future holds, but by coming together we can start to collectively see the shape of things, and better defend our individual organizations and society as a whole.

EXECUTIVE SUMMARY

Frontier artificial intelligence (AI) capabilities have introduced a qualitative shift in the cybersecurity threat landscape. Security leaders describe this not as incremental change but as a fundamental restructuring of the economics of offense and defense. Over the course of three AI Storm Summits held in San Francisco (May 2026), New York (June 2026), and Washington, D.C. (June 2026), security leaders gathered to share observations, challenge long-held assumptions, and examine what this new environment demands of organizations and the profession.

Several themes recurred consistently across all three events:

  • AI-enabled vulnerability and exploit discovery will break existing governance and remediation processes.
  • AI-enabled attack automation will challenge many current security defenses, often due to completeness and scalability complexities.
  • Agentic AI systems are entering enterprise environments faster than identity, access control, and oversight frameworks can accommodate.
  • The dominant vulnerability scoring and tracking systems, including Common Vulnerabilities and Exposures (CVE), the Common Vulnerability Scoring System (CVSS), and the Known Exploited Vulnerabilities (KEV) catalog, were believed to be inadequate for the new environment.

The three summits surfaced meaningful differences in emphasis. The San Francisco summit concentrated on operational implementation, presenting detailed approaches to AI-driven security operations at machine speed. The New York summit placed greater weight on governance and organizational transformation, including how to communicate urgency to boards and evolve team incentive structures. The Washington, D.C. summit broadened the scope to include structured research into attacker automation, the implications for operational technology (OT) and industrial control system (ICS) environments, and the strategic architecture of agentic systems.

The discussions suggest that security leadership is navigating a period of compressed decision-making in which established frameworks, vendor relationships, and organizational models are under simultaneous pressure. The most important collective implication is that organizations must develop the ability to detect and remediate at a pace that exceeds current human-governed process cycles, without sacrificing meaningful human accountability over the systems doing that work.

INTRODUCTION

This paper synthesizes discussions from three AI Storm Summits conducted under the Chatham House Rule in San Francisco (May 2026), New York (June 2026), and Washington, D.C. (June 2026). In accordance with that rule, the observations documented here reflect the substance of the discussions without attribution to individual participants, their employers, or their organizations.

The three summits convened security leaders to examine how frontier AI capabilities are reshaping the threat landscape and what this requires of security programs, governance models, and the profession. The discussions were qualitative in nature, reflecting practitioner experience and judgment rather than a formal or statistically representative survey. Findings should be understood as informed perspectives from engaged security professionals, not as quantified claims about industry-wide practices.

This paper focuses on themes that recurred across events, distinctions that were meaningful within individual summits, and strategic implications that emerge from the combined discussions. It also identifies areas where the discussions point toward needs for additional research, guidance, and collaboration within CSA and the broader industry.

COMMON THEMES ACROSS THE THREE SUMMITS

The vulnerability and exploit discovery lifecycle has fundamentally accelerated

Across all three summits, participants described a qualitative change in the speed and scale at which vulnerabilities can be discovered and exploited. The core observation was consistent: AI-enabled tools can now identify critical vulnerabilities in codebases and deliver exploits at a rate that renders traditional remediation cycles obsolete. Where organizations once operated on quarterly penetration testing cycles with multi-day service-level objectives for critical findings, leading-edge participants described building systems capable of identifying, validating, and remediating the highest-priority findings within hours.

This acceleration carries a specific implication that recurred across every event: discovery is no longer the primary constraint. The bottleneck has shifted to triage, governance, and remediation infrastructure. Participants noted that organizations flooded with AI-generated findings face the risk of false-positive fatigue if findings are not rigorously validated before reaching engineering teams. Several organizations described implementing multi-stage validation pipelines that require confirmed exploitability before any finding is escalated. The challenge of managing this volume, including the governance processes, vendor contracts, and change management systems designed for a slower-moving environment, was described as an ongoing and unsolved problem across all three events.

Existing vulnerability frameworks are no longer adequate

The CVE system, CVSS scoring, and the KEV catalog were examined critically at all three summits. Participants described these systems as designed for a threat environment that no longer exists and as failing to capture the context needed for modern prioritization decisions. The CVE system, established in 1999, was noted as not designed with AI-generated vulnerabilities or the current pace of discovery in scope. CVSS scores were characterized as providing an inadequate basis for prioritization because they do not account for exploitability in the specific context of an organization’s environment: factors such as reachability, chainability, blast radius, and compensating controls.

A more fundamental concern also emerged: the volume of vulnerabilities now being discovered may exceed the CVE system’s capacity to process and enrich findings in a timely or complete manner. Participants observed that many vulnerabilities identified through AI-assisted analysis are not being assigned CVE identifiers or are not being enriched with the information needed to act on them. Broad agreement existed across the three events that new taxonomies and metrics are needed, though no consensus emerged on what they should look like. Proposals discussed across the summits included context-enriched prioritization frameworks that incorporate reachability and chainability, greater use of the Exploit Prediction Scoring System (EPSS), and the development of metrics organized around security posture and remediation velocity rather than raw finding counts.

Agentic AI systems require new governance, identity and access frameworks

The deployment of AI agents in enterprise environments, including agents that execute code, access data, and interact with other systems, was discussed at all three summits as a rapidly emerging governance challenge. The central difficulty is that existing identity and access management (IAM) frameworks were designed for human users and do not map cleanly onto agents that may act autonomously, operate at scale, spawn sub-agents, and interact with production systems.

Participants across all three events identified inventory as a foundational requirement: organizations need to know what agents exist, who created them, what data and systems they can access, and what actions they are authorized to take. Discussions examined how to apply least-privilege principles to agents and how to govern agents created by employees outside of formal technology functions, a category sometimes described as citizen developers. The question of how to classify agents, whether as assets, as extensions of the humans who created them, or as a distinct category requiring new governance models, was raised across all three events without resolution.

The Washington, D.C. summit examined agent identity in the greatest technical depth, with discussions covering the potential role of standards such as SPIFFE and SPIRE (open standards for workload identity in distributed systems) for issuing cryptographic identity to agents, the need for continuous authentication and behavioral monitoring of agents across their lifecycle, and the operational challenge of decommissioning agents that are no longer needed.

Third-party risk management must evolve for an AI-dependent environment

Third-party risk management (TPRM) was a recurring topic at all three summits. The shared observation was that existing TPRM approaches, built around periodic assessments, audit reports, and contractual representations, do not provide the continuous, real-time assurance that an AI-dependent operational environment requires.

Participants described the limitations in current tools: trust centers and self-assessments were characterized as designed primarily for the selling organization rather than the assessing organization, and as providing insufficient visibility into how vendors handle AI-specific risks. At the San Francisco summit, participants presented approaches using AI-assisted TPRM that aggregate public signals, financial indicators, and structured audit inputs. At the New York summit, breakout discussions focused on shared dependencies among third parties and the operational resilience implications when a critical vendor fails or is compromised. At the Washington, D.C. summit, participants examined the contractual dimensions of AI vendor relationships, including what new provisions organizations may need to address concerns such as digital sovereignty, zero-data-retention agreements, and model change management.

Harness architecture is as important as model selection

A concept that appeared prominently across all three summits is that the “harness,” the scaffolding, orchestration logic, prompts, rules, and integration patterns that govern how AI models are applied to security tasks, matters as much as the underlying model. Participants consistently challenged the assumption that access to Mythos-level models was required for expert-level vulnerability and exploit discovery. Older models and even open-weight models are sufficient with a proper harness design that determines whether outputs are trustworthy, whether findings are actionable, and whether the system can scale responsibly.

This framing carried practical implications. Organizations that have built effective AI-assisted security operations described investing substantial effort in harness design: defining scope deliberately, matching model selection to specific task requirements, building validation pipelines, and establishing feedback loops to reduce false positives over time. Interest in sharing harness architectures was strong across all three events, and participants raised the possibility of community resources or clearinghouses for this kind of knowledge. At the same time, the Washington, D.C. summit examined the tension between broad sharing and the risk of giving adversaries visibility into defensive architectures, a question the community has not yet resolved.

The workforce and organizational model are being restructured

All three summits addressed the implications of AI for security teams and for the broader technology workforce. The consistent observation was that AI tools are already changing who performs security work and how it is done. Skills that previously required specialized development backgrounds are becoming accessible to a broader population; tasks that previously required human analysts are being performed by agents; and the volume of work that security teams are expected to manage is increasing at a pace that outstrips traditional hiring and training cycles.

Participants described the challenge of building teams that can think in terms of agent design and oversight rather than manual execution. Breakout discussions at the San Francisco summit examined organizational structures appropriate for a world where AI agents effectively expand team capacity. The New York summit raised concerns about misaligned incentives within security organizations and the need for new metrics that measure velocity and capability rather than activity. The Washington, D.C. summit surfaced concrete examples of efficiency gains from deployed AI agents and noted that the transition requires sustained attention to workforce resilience and the risk of burnout.

The human-in-the-loop question

A question that surfaced explicitly at all three summits, and that remained open at each, is precisely when and how human judgment should be required in AI-assisted security operations. The shorthand used across events, governance in the loop versus human in the loop, captures a real tension: fully automated systems can operate at the speed required by the threat environment, but meaningful human accountability is necessary to catch errors, manage liability, and maintain trust. Participants generally agreed that some decisions require human review, particularly those involving action in production environments or high-consequence remediation. No consensus emerged on where exactly those boundaries should be drawn, and the discussion suggested that the answer will differ by organization, context, and risk tolerance.

Resource-constrained organizations face distinct challenges

Not all organizations have the same depth and availability of security resources, yet the AI-related risks affect all organizations equally. Less resourced organizations (those living “below the Security Poverty Line”) need sector-specific guidance and cost and resource-effective strategies to address the AI Storm.
Specific industries were well-represented at the summits, including education, healthcare, small/mid financial institutions, and especially utilities and other organizations with extensive operational technology (OT) networks that face extreme risks due to the extreme difficulties they face with rapid patching and reliance on older, fragile technologies.

EVENT-SPECIFIC THEMES AND DISTINCTIONS

San Francisco (May 2026)

The San Francisco summit was the first in the series and oriented more toward operational practice than the subsequent events. Its most distinctive contribution was a detailed examination of how to build AI-driven security operations that function at machine speed while maintaining appropriate human oversight. Participants described specific architectural patterns for continuous scanning, multi-stage validation pipelines to manage false positives, and the governance adjustments required to permit automated remediation at pace.

This summit also placed substantial emphasis on infrastructure prerequisites for AI-enabled security operations. Scaling AI-assisted security requires investment in compute, data residency management, and sanctioned environments for exploit validation. Many organizations do not yet have this infrastructure in place. Model safety filters were identified as a practical obstacle to legitimate security research work, and participants described ongoing negotiations with vendors to enable offensive security use cases without compromising data-retention commitments. The concept of an “absorption rate metric” (findings resolved relative to findings created) was introduced as a way to assess whether remediation capacity is keeping pace with discovery.

The San Francisco summit also produced an extensive discussion of the changing role of open-source software in this environment, including the possibility that the volume of AI-discovered vulnerabilities could accelerate consolidation of open-source projects and increase commercialization pressure on currently volunteer-maintained codebases.

New York (June 2026)

The New York summit placed greater emphasis on organizational and governance dimensions than the other events. Board communication was discussed in considerable depth, with participants sharing experiences of how to translate the urgency of the current environment into language that resonates with executive leadership and enables resource decisions. The challenge of moving from technical credibility to demonstrable business impact was identified as a significant and common friction point.

This summit also produced the most sustained discussion of how security team structures and incentive models need to evolve. Participants examined misalignments between current incentive structures and the behaviors needed to adapt rapidly to AI-enabled operations. The concept of moving from information sharing to knowledge sharing, from communicating indicators to transferring reproducible expertise, was introduced at this event and carried forward into the Washington, D.C. discussions.

The New York summit featured the most developed treatment of operational resilience in the context of AI dependency. Participants discussed the implications of widespread organizational reliance on AI infrastructure providers and the need for structured exercises that test an organization’s ability to disconnect from and reconnect to those providers. Questions raised included how to define an AI-related incident, what minimum viable operations look like when AI systems are unavailable, and how to ensure that critical business functions can continue if an AI vendor is disrupted.

Washington, D.C. (June 2026)

The Washington, D.C. summit was the most technically detailed of the three events. A presentation on hyperscale autonomous vulnerability discovery, drawing on competitive AI security research, illustrated the current state of the art in AI-assisted bug finding and established a reference point for what adversaries may be capable of at scale in the near future. A separate presentation described an enterprise AI security auditor built on a multi-phase, provability-gated architecture, demonstrating that high-precision AI-assisted vulnerability discovery with very low false-positive rates is operationally achievable.

This summit produced the most extensive discussion of implications for communities outside the technology-native enterprise. A breakout session examined what the new threat environment means for organizations operating OT/ICS infrastructure, sectors that cannot patch or upgrade on modern timescales and where the consequences of compromise extend to physical safety and public services. Participants observed that attackers no longer need prior OT/ICS expertise to pose a credible threat to these environments because AI systems can acquire and apply relevant domain knowledge. The summit returned to the concept of the “have-nots,” smaller organizations, public sector entities, and resource-constrained industries that lack the capacity to deploy sophisticated AI-assisted defenses and may depend on guidance and shared resources from larger organizations and industry groups.

The Washington, D.C. breakout on attacker automation and defender response examined the fundamental asymmetry between attacker and defender search problems and asked how organizations should structure defenses when the mathematical complexity favors the attacker. Proposals discussed included aggressive exposure reduction, deception technology, and the need for security boundaries rather than relying solely on patching and vulnerability management.

AREAS OF AGREEMENT, TENSION, AND UNCERTAINTY

Broad Agreement

Participants across all three summits agreed that the threat environment has changed in ways that make existing frameworks, processes, and governance models inadequate. There was consistent agreement that organizations should be actively scanning their codebases and attack surfaces using AI-assisted tools, that harness architecture is a meaningful differentiator in outcomes, and that human oversight remains necessary even as AI systems take on a greater share of operational work. The need for community-level knowledge sharing, moving beyond sharing threat indicators to sharing reproducible expertise and architectural patterns, was expressed consistently across all three events.

Persistent Tensions

The most significant tension across the summits was between the speed at which AI-assisted security operations can and should operate and the governance structures that exist to ensure accountability and reduce risk. Participants described environments where the pace of AI-enabled threat activity outstrips human-governed approval and change management processes. The appropriate resolution of this tension - which decisions should be automated, which should require human review, and what governance structures should surround autonomous action - remained unresolved across all three events.

A related tension concerned the distribution of capability. Participants repeatedly noted that frontier AI tools provide significant defensive advantages to organizations that can afford and deploy them, while smaller and resource-constrained organizations face the same elevated threat environment without equivalent defensive resources. This dynamic was described as creating or widening a security capability gap with implications for critical infrastructure, regulated industries, and the broader digital ecosystem.

Areas of Genuine Uncertainty

Several topics were raised across the summits without resolution. These include: how to design replacement or supplementary frameworks for CVE and CVSS that capture context adequately; what governance structures are appropriate for AI agents acting in production environments; how to assign and enforce accountability when agents cause harm; and whether the open-source software ecosystem can sustain the current pace of vulnerability discovery and remediation without structural changes to project maintenance and resourcing.

IMPLICATIONS FOR CISOs AND SECURITY LEADERS

The combined discussions indicate that security leaders face a set of compounding challenges that cannot be addressed through incremental adjustments to existing programs. Several strategic implications emerge from the three summits.

The discussions suggest that organizations should treat AI-assisted vulnerability discovery as a continuous operational capability rather than a periodic assessment activity. The transition from scheduled penetration testing to continuous AI-driven scanning changes what a baseline security posture looks like and what metrics are meaningful for measuring it.

A recurring implication is that governance and remediation infrastructure must be redesigned for the pace of AI-enabled operations. Approval chains, vendor contracts, and change management processes designed for weekly or monthly cadences are not compatible with the remediation timelines that the current threat environment may require. For CISOs, this may require investment in pre-authorized response playbooks and renegotiated vendor service-level agreements before a crisis makes those renegotiations time-pressured.

The identity and access management challenge associated with AI agents may require attention before agent deployment reaches enterprise scale. The discussions indicate that waiting until agents are widespread before establishing inventory, classification, and governance frameworks creates significant risk exposure. Least-privilege principles, continuous monitoring, and formal lifecycle management should be applied to agents from the outset of deployment.

The combined findings indicate that third-party risk programs will need to incorporate AI-specific criteria into vendor assessment and contracting. Organizations are beginning to examine what contractual protections they need around AI vendor relationships, including provisions related to data handling, service continuity, rate limits, and model change management. For CISOs, this may require working with legal, procurement, and executive teams to develop AI-specific vendor requirements before they become standard in the market.

Participants at all three summits noted that board and executive communication requires new vocabulary. The challenge is not only explaining technical risk but translating the change in the threat environment into business terms, such as financial exposure, operational continuity risk, and competitive implications, that enable executive decision-making. The discussions suggest that CISOs who can connect AI-driven security investment to concrete business outcomes are more effective at gaining the resources and authority needed to respond adequately.

OPPORTUNITIES FOR CSA AND THE INDUSTRY

Several needs emerged from the combined summit discussions that point toward potential areas of work for CSA and the broader security community.

Participants explicitly raised the need for new vulnerability classification frameworks that move beyond CVE and CVSS to incorporate context, reachability, chainability, and compensating controls. This is an area where CSA, working with other standards bodies and industry groups, could contribute research, facilitate consensus, and develop practical guidance that practitioners can apply. Existing CSA frameworks such as the Cloud Controls Matrix (CCM) offer a foundation for mapping contextual risk factors to control domains.

The concept of a shared harness resource, a venue where organizations can contribute and access AI security harness architectures, was raised at multiple summits as something the community wants but does not yet have. CSA may be positioned to facilitate this kind of knowledge commons, with appropriate governance to address concerns about adversarial access and to protect contributing organizations’ interests. This would extend the knowledge-sharing function that bodies such as CSA, the Center for Internet Security (CIS), and OWASP have historically provided for security controls and configuration guidance.

Guidance designed for resource-constrained organizations, smaller enterprises, public sector entities, healthcare, utilities, and OT/ICS operators was identified as a gap across multiple events. Participants noted that existing AI security guidance tends to assume capabilities and resources that many organizations do not have, and that content needs to be adapted for different audience contexts, not merely simplified. CSA AI safety research and the AI Security Maturity Model (AISMM) represent starting points for this kind of tiered guidance development.
The governance of AI agents in enterprise environments is an area where clear frameworks, taxonomies, and control guidance are largely absent. Practitioners are developing ad hoc approaches while waiting for more structured guidance to emerge. CSA could contribute by developing material for agent classification, identity, lifecycle management, and audit that draws on the emerging experience of early adopters and maps to existing CSA control frameworks.

Finally, the summits pointed to a need for shared metrics and benchmarks. Existing security metrics are not well suited to measuring the performance of AI-assisted security operations or to communicating posture to executive leadership in terms that resonate. Research into what meaningful metrics look like in this environment, and how to translate them for board-level communication, would address a need articulated consistently across all three events.

CONCLUSION

The three AI Storm Summits reveal a security leadership community that recognizes it is navigating a period of fundamental change and is working, often without established playbooks, to adapt its programs, teams, and governance structures to a new environment. The most important shared finding is that the economics of vulnerability discovery and exploitation have shifted in ways that require organizations to develop AI-assisted detection and remediation capabilities and to redesign the governance structures that surround them.

The summits also reveal meaningful variation in how organizations are experiencing this change. Some are building sophisticated AI-driven security operations with continuous scanning, automated remediation pipelines, and emerging agent governance frameworks. Others are in earlier stages of adoption, facing resource constraints, legacy infrastructure, or regulatory environments that slow their progress. This variation matters for how CSA and the industry approach guidance and community support: effective responses to the current environment will need to address a wide range of organizational contexts, not only those at the frontier.

Participants across all three summits consistently characterized the next one to two years as a critical window for establishing the practices, frameworks, and governance structures that will determine whether organizations can operate securely in an AI-enabled threat environment. The security profession has navigated qualitative shifts before. The task now is building the shared knowledge and institutional capacity to do so again, before the window narrows.

ABOUT THIS PAPER

This paper was prepared by the Cloud Security Alliance based on discussions from three AI Storm Summits conducted in May and June 2026. All discussions were conducted under the Chatham House Rule. No participant, organization, or affiliation is identified in this document. The findings represent qualitative practitioner perspectives and should not be interpreted as a formal survey or as representing the views of any specific organization. 

Explore More of CSA

Research & Best Practices

Stay informed about the latest best practices, reports, and solutions in cloud security with CSA research.

Upcoming Events & Conferences

Stay connected with the cloud security community by attending local events, workshops, and global CSA conferences. Engage with industry leaders, gain new insights, and build valuable professional relationships—both virtually and in person.

Training & Certificates

Join the countless professionals who have selected CSA for their training and certification needs.

Industry News

Stay informed with the latest in cloud security news - visit our blog to keep your competitive edge sharp.