News
Forrester Warns: AI Agents Will Become CISOs' Top Concern in 2026

Forrester analyst Jitin Shabadu named AI agents one of the top five cybersecurity threats for 2026 - 80 percent of companies already report risky behavior from deployed agents, and 63 percent have no oversight policy in place.
Contents
Research firm Forrester has published its list of the top five cybersecurity threats for 2026, ranking AI agents operating inside companies without security team oversight in second place. According to analyst Jitin Shabadu, personal AI agents that gain access to employees' browsers and inboxes are turning into so-called shadow operators, acting outside company policy and visibility.
Shadow operators in the corporate network
Forrester describes a mechanism in which AI agents installed by individual employees, often without the IT department's knowledge, gain access to company email, browsers and internal systems. These tools operate at machine speed, executing dozens of decisions and actions per second, while remaining outside the traditional audit and access control mechanisms that protect standard company software.
Personal AI agents entering companies through browser and inbox access are creating shadow operators that act outside security oversight - Forrester, Top Cybersecurity Threats In 2026 report
The result is a situation where the chief information security officer (CISO) bears responsibility for incidents caused by tools their team never had any real control over. Forrester stresses that the problem isn't limited to malicious external attacks, but stems above all from organizations themselves deploying autonomous systems without adequate safeguards.
Five threats on Forrester's list
Besides AI agents, the report lists four other risk areas for 2026: near-autonomous attacks carried out by nation-state-linked actors, an expanding AI-based software supply chain, challenges in managing agent identity and access, and technological fragmentation stemming from individual countries' digital sovereignty initiatives.
On the first point, Forrester cites specific cases, including Anthropic's disclosure that a China-linked group used Claude to conduct cyberespionage, and abuse of the Gemini model by attackers confirmed by Google's Threat Intelligence Group. This shows that language models are already being exploited on both sides, as an attack tool and as a source of new risk inside organizations.
The cost for businesses
The statistics cited in the report show the scale of the problem. Nearly two-thirds of organizations have no formal policy on AI agents, and among companies that have already suffered an AI-related incident, as many as 97 percent had no adequate access controls in place. Forrester states plainly that the question is no longer whether a publicly disclosed breach caused by an agentic AI deployment will occur, but which organization will be the first to suffer one.
The firm also predicts a concrete personal consequence: such an incident will lead to the firing of the employee or manager responsible for the deployment. This shift in emphasis from the classic external hacker to internal organizational negligence changes how security departments should treat agentic projects, not as an add-on to existing infrastructure, but as a separate risk category requiring its own safeguards.
What analysts recommend
Forrester recommends four concrete steps for CISOs: a full inventory of all agents operating within the organization, enforcing policies that require governance at the platform vendor level, implementing continuous agent testing, and applying the principle of least privilege, meaning agents get access only to the resources needed for a specific task. The firm also recommends moving from classic identity and access management (IAM) toward solutions built specifically for AI agents, covering their provenance, permissions and activity history.
For Polish companies just beginning to deploy agentic AI tools in customer service, sales or data analysis, the report signals that oversight of such systems needs to be addressed alongside deployment itself, not after the fact. The AI policy gaps Forrester describes affect the vast majority of organizations globally, while Poland's regulatory market is only now preparing for this as the EU's AI Act provisions come into force.

