Key findings:
AI adoption is now universal.
76.6% of organizations are actively using AI in development workflows, while another 20.4% are evaluating it (Futurum Research Survey, 2026).
Traditional security programs don’t fit.
They were built for human-driven SDLC, established review cycles, and known tools, not agent-driven creation, infrastructure change, and data access.
Ten concerns every CISO should understand.
Each framed as what leaders think is happening vs. what may actually be happening, with a recommended response.
The challenge isn’t AI adoption.
It’s visibility, governance, and control over how AI is building software.
If you can’t say which AI tools are building software across your organization, and what they can access, this guide is for you.
Most organizations aren’t struggling because teams are using AI; they’re struggling because existing security programs weren’t designed to govern AI-assisted software creation. The question is no longer “Are our teams using AI to build software?” It’s “Do we have visibility, governance, and control over how AI is building software across the organization?”
Inside the guide: the 10 concerns
- Shadow AI Development – teams experiment with unauthorized AI tools, extensions, agents, and cloud services outside approved governance. Response: extend security controls into AI-assisted workflows before production.
- AI-Generated Vulnerabilities at Scale – larger volumes of code increase the rate at which vulnerabilities enter the SDLC.
- Loss of Development Governance – AI-generated code bypasses traditional review, documentation, and architectural oversight. Response: adapt governance for AI-generated contributions.
- Excessive Agent Permissions – agents receive broad access across repos, cloud, ticketing, and collaboration platforms. Response: apply least-privilege and monitor granted permissions.
- Exposure of Sensitive Data Through Prompts – proprietary code, credentials, and customer data submitted to external AI systems. Response: prevent sensitive data from entering AI workflows.
- Unmanaged AI Infrastructure Changes – AI-generated scripts and automation introduce config changes at unprecedented speed. Response: validate AI-generated infrastructure changes before deployment.
- Agent-to-Agent Risk Propagation – multiple agents interact, creating chains of actions that are hard to monitor or audit. Response: centralized visibility into agent activity and dependencies.
- Limited Visibility into AI Risk – AI-generated code, workflows, and deployments stay invisible to existing tooling. Response: extend visibility across the AI-SDLC.
- Tooling Fragmentation – disconnected point solutions increase complexity while reducing visibility. Response: prioritize unified platforms.
- Governance Models That Cannot Scale – AI accelerates development beyond the capacity of manual review. Response: modernize governance to support AI-scale development.
By the numbers:
76.6% of organizations are actively using AI in development workflows.
20.4% more are evaluating implementation — making governance a board-level concern.
10 AI coding concerns every CISO should understand.
Source: Futurum Research Survey, 2026.


