You spent a career making this enterprise safe. Identities scoped, data classified, endpoints watched. It worked because software did what it was told and nothing more. Then you gave it an agent: it reasons, it chooses its own next step, it calls tools on your behalf at machine speed, and it reads its instructions from whatever data lands in front of it.
You already feel the gap. Forrester asked 1,528 AI decision-makers what concerns them most about AI: security and risk led everything at 40 percent, and what tied for second says more, the readiness of their own people and the fear that models behave unpredictably, at 22 percent each. Leaders are not worried about the tools. They are worried about whether anyone is ready.
What 1,528 leaders fear most
Unpredictable outputsThe gap0%
Financial & competitive0%
Base: 1,528 AI decision-makers who have concerns about AI usage. Source: Forrester's State of AI Survey, 2025.
Every control you built your career on checks permission. Not one of them checks intent. So ask the three-in-the-morning question: when an agent acts against you, will you know it was the agent, can you say what it did, can you stop it? Today no one on your team is trained to close that gap. Three sentences from real incident rooms show what it costs.
“The agent had read access. Somehow it wrote to production.”
No permission was exceeded. The escalation lived in the composition of two allowed steps, which a permission model cannot see. Two in five leaders now expect exactly this kind of AI-driven insider incident.
Reskill Identity Security: the rung, the plays, the gate →
None of this lands on clean ground. “We approved 5 AI tools. We found 47.” “An employee pasted our M&A terms into a public AI tool.” “AI services are adding capabilities faster than we can evaluate for risk.” That is the fuel; the agents are the fire. And the newest failure needs no attacker at all: a model invents something fluently, an agent turns it into an action. Security asks who got in. Safety asks what the system did to the people it touched, even when nobody got in. That question has no owner on your org chart.
The harm map: harm, owner, control, tier →
So the only question that matters lands on your desk: how does the business keep moving while your people learn to see autonomous action, attribute it, and stop it the moment intent and execution diverge? Standing still is not on the table.
The answer is not another product, and it is not a warning that AI takes your seat. It is a discipline your own people own: see autonomous action, attribute it to a real identity, gate it before it runs. The people who already sit in the incident room are the best equipped to master it, and reskilling keeps the authority with them. The map below is the syllabus: every threat named in plain English, the one fitted control that answers it, and the function that reskills to own it. Start where you are.
Source: Proofpoint, State of AI Security 2025, a survey of 275 enterprise security and business leaders. Figures are what respondents expect, not measured outcomes.