What Analysts Are Debating About AI Security in 2026, and Where They Converge

In brief, from Mission Brief, the opening session of AI Webinar Week:
- Industry analysts are split on where AI security should start: governance programs or runtime controls. Practitioners who have watched this movie before say both.
- Where analysts converge: AI security is rooted in data security. Forrester published its first Wave for sensitive data discovery and classification, and IDC frames the goal as data quality plus data security equals data trust.
- Agentic AI breaks the identity model enterprises run today. Authorization, behavior, and intent are the next control points to build.
What a time traveler would call a breach
Imagine explaining to a CISO from five years ago that you installed software on your network that can assume the identity of any employee, access any of your data stores, and send information anywhere on the internet. They would assume you had been breached. Now imagine telling them you did it on purpose, in the name of productivity.
That is the position every enterprise adopting AI finds itself in today. The technology moved in faster than the security models built to contain it, and the people whose job is to make sense of markets, the industry analysts, are still working out what to tell practitioners. In the opening session of AI Webinar Week, Cyera's Rick Holland, Data and AI Security Officer and former Forrester analyst, and Christy Hart Smith, Director of Global Analyst Relations, compared what they are hearing from customers and analysts. The picture that emerged is worth paying attention to, both for where the experts disagree and for where they have converged.
The debate: governance first or runtime first
Talk to enough analysts right now and you will hear two opposing schools of thought. One warns that the vast majority of AI projects will fail without a strong governance program in place. The other argues that AI is moving too fast for governance to keep up, and that runtime controls need to go in immediately, since runtime is where risk is greatest.
There is history behind both positions. Most security disciplines start by putting controls in at runtime because that is where the risk sits, and the controls gradually move earlier into design time because fixing problems there is cheaper and easier. Application security followed exactly that path.
The practitioner answer is that this is a false choice. As Rick put it: "You've got to do stuff at the start while you're building and designing these systems, but then you also have to do something when things are getting executed." Security has been here before, in the swings between prevention and detection and response. Prevention shrinks the funnel so detection and response has less to catch. Design-time governance and runtime protection work the same way. They are two halves of one program, not competing philosophies.
The convergence: AI security is rooted in data security
Where analysts do agree, the agreement is striking. Forrester published its first-ever Wave evaluation of sensitive data discovery and classification solutions, and the reason it exists at all is telling: practitioners kept coming back with the same questions about how to get started with AI and succeed with it. When enough practitioners ask an analyst the same question, research follows. (Cyera was named a Leader in that evaluation, with the top score in the strategy category.) At IDC's Directions conference, the same conclusion was framed as an equation: data quality plus data security equals data trust.
The logic holds no matter where a control lives. Whether you enforce at design time or at runtime, the control depends on knowing what the data is, who has access to it, and whether that access is appropriate. This is the layer the market calls data security posture management, or DSPM: continuous discovery and classification of sensitive data, mapped to the humans, applications, and AI that can reach it. It is also why categories the industry had written off are getting a second look. DLP became a word nobody wanted to say because DLP programs were brittle and hard to derive value from, and the reason was fragmentation: policies scattered across technology silos with no consistent, high-fidelity understanding of the underlying data. Fix the data understanding, and the policy layer starts to work.
The advice built on that foundation has changed too. As recently as a few months ago, analysts were telling clients to run any AI experiment just to learn. What clients hear now is different: choose a high-value project, ideally the one with the biggest impact on the organization, and do it well. The stakes explain the shift. Data was not historically treated as a business differentiator. With AI, its importance to the business has risen sharply, and so has the scrutiny on security, data, and AI leaders. The business outcome is no longer employees asking a chatbot questions, since agents are doing the work, and AI has become a career opportunity for executives who can enable it and a risk for those who cannot.
The next frontier: agents, authorization, and intent
The hardest problems discussed in the session sit just ahead, in agentic AI. Agents are not traditional non-human identities. You cannot manage one the way you manage a service account or an SSH key, and the industry has struggled to secure even those. Agents spin up to do a task, live for seconds, and disappear. A quarterly access review doesn't answer that, which means the identity and access management playbook most enterprises run today was never designed for the entities now operating within them.
They also inherit everything the enterprise never cleaned up. Organizations are digital hoarders, full of stale identities and permissions like unopened boxes carried from house to house for years. No human ever had time to look inside them all. Agents will, at a scale no person could match, because finding what they need wherever they have access is exactly what they are built to do.
That is why authorization is the next big step. Today, the AI security conversation centers on data access, but agents will not just read data inappropriately, they will take actions. And securing actions requires a discipline security teams are only beginning to build: understanding agent behavior and beyond behavior, intent. One anecdote from the session made the point vividly. A test suite ran an agent through identical setups, and most passed, but one failed. Debugging the failure meant debugging not the code but the agent's reasoning. The passing agents had simply improvised a way in. The question security teams will have to answer is shifting from what happened to why is access needed for this agent, and why did it do what it did.
What to do with the next 12 months
The session closed on pragmatic ground, with five moves a security leader can start this quarter:
- Fold AI into the governance model you already run. Don't build a parallel structure from scratch. Insert AI into your existing risk and governance processes, then stand up a dedicated AI subcommittee as your expertise matures.
- Give employees a sanctioned way to build. Too many people are locked down, and your competitors are already enabling this kind of skunk works with tools like Claude Code and Notion AI. Set up a deliberate, harnessed, secured environment for it, because every employee can now ship a vulnerable application. Left unmanaged, vibe coding becomes a significant insider threat risk, accidental rather than malicious.
- Get the data fundamentals in order. Classify your data, write policy, and define the boundaries of acceptable use. Every AI governance decision and every runtime control you deploy later depends on this layer working.
- Pick the highest-value use case and commit to it. Don't experiment blindly. Find the use case with the biggest value, dedicate real resources to it, build the adoption plan, and account for the actual costs of running AI. There is no infinite capacity to absorb everything being created, so look for what delivers the highest value in the shortest time.
- Start quantum readiness now. Post-quantum will arrive the way AI did, slowly and then all at once. NIST's draft transition guidance, NIST IR 8547, deprecates today's quantum-vulnerable algorithms after 2030 and disallows them after 2035, and replacing cryptography is a cross-functional, multi-year effort.
What got us here will not get us there. The foundation, though, is familiar: know your data, know who and what can access it, and know why.
Watch the full webinar on demand here to see how Cyera's AI security platform pairs DSPM with Agent Guardian to discover shadow agents, enforce intent-based guardrails, and secure the data that fuels AI.


.png)
