gobernanza de agentes de IA
Analysis

AI Agents and the New Role of the CISO: Who Is Accountable When the System Acts on Its Own?

Mariona Campmany CMO
23 September, 2026 8 min

The CISO’s role has changed more in the past two years than in the decade before it. And a good part of that change still isn’t written into any org chart.

Gartner puts it in two numbers: 39% of CISOs say their CIO is trying to shift cyber risk ownership onto them, and 34% say they’re pressured to downplay it in their reporting. Translated into day-to-day operations: in more than a third of organizations, risk is either reported lower than it actually is, or it’s reported and then nobody signs off on it. That friction isn’t a personality clash between two people, it’s the symptom of a mandate that’s shifting from approving projects to sanctioning decisions that no human is making in the moment they happen.

Regulation (EU) 2024/1689 places biometric identification among high-risk systems, with human oversight obligations that come into force this year, 2026. From that point on, someone has to be able to show who was watching over a decision a system made on its own, with no person looking at the exact moment it happened. That someone is the CISO.

The CISO’s new role: from approving beforehand to sanctioning after the fact 

The classic mandate operated at a single fixed point: the approval committee. That point still exists, but it’s stopped being where most of the real risk actually gets decided.

Gartner documents how organizations are redesigning their cybersecurity teams around business outcomes — like digital trust or resilience — rather than around technical silos split by tool. Translated into the CISO’s day-to-day, their value is no longer measured by how many deployments they blocked, but by how much evidence they can produce when someone asks what happened. They stop being the guardian of a perimeter and start answering for the whole cycle, from the permission that was granted to the proof that someone reviewed it.

That shift depends on who owns the risk for each asset.

Ownership of a digital asset — and the risk that comes with it — belongs to whoever operates it within the organization. The CISO doesn’t own that risk. Their job is to assess it, flag it, and put that assessment in writing, backed by real authority, not an informal thumbs-up in a chat channel.

And that only holds up with two things in writing: a statute of responsibilities signed off by leadership, and job descriptions that reflect that assignment.

Governing agents that act without asking

When the one executing is a person, the decision gets made at the moment of approval. When the one executing is an AI agent, the decision was already made earlier, when permissions were granted. And it gets made again later, when reviewing the evidence that agent left behind.

Between those two moments there’s a gap. There, while the agent acts on instructions that no one is negotiating in real time, the risk lives in a kind of purgatory: nobody is watching it, but it hasn’t stopped running either. That forces governance to be thought of in phases, and positions the CISO as the designer of those phases, not the approver of a single file. There are four of them, and each one answers a different question.

Phase Question it answers Concrete control Evidence it leaves behind
1. Inventory Which agents do we have, and what do they access? Catalog of systems and use cases, classified by risk level. Registry with an assigned owner for each entry.
2. Mandate Who is accountable, and with what authority? AI council with a named lead and written scope, backed by leadership. Founding charter and updated job descriptions.
3. Execution How does policy translate into control? Permissions scoped per agent, with verification of who acts on each sensitive operation. Decision trail, approved exceptions, and their expiration.
4. Oversight How does it hold up beyond the pilot? Post-deployment behavior monitoring and documented human review. Control metrics reviewed on a fixed schedule.

The phase that tends to get overlooked most is the mandate: an AI council backed by leadership, with a named lead and a written scope. That council decides which agents exist, within what limits, and under what review. Without that named lead, accountability gets spread across so many people that, in practice, it belongs to no one. And without that phase in place, the other three have nothing to stand on.

The committee that neither the CIO nor the CISO should chair 

Every governance council eventually runs into cases the policy doesn’t fully cover: a one-off exception, a call on whether a certain risk is acceptable, a case where following the rule to the letter would block something the business genuinely needs. For those cases, it’s worth having a separate committee, with neutral chairing and written procedures for exceptions, escalation, and reconciliation.

It’s usually made up of the CIO, the CISO, and whoever represents business risk, but none of them chairs it. That way the decision stays centered on the risk itself, not on who carries the most weight in the room. And what actually sustains this day to day isn’t the committee’s monthly meeting — it’s an ongoing dialogue between the areas involved that turns shared responsibility into concrete decisions before a specific case stalls out.

The inventory phase, the first of the four, is already failing today in most organizations, and it has a name: shadow AI. It isn’t an isolated incident — it’s the norm in any organization where the business adopts AI tools faster than the inventory that’s supposed to track them. There’s no control over what data goes in, or over who sees it afterward.

And banning it rarely works. It just pushes the use even further out of sight. The real alternative is to take inventory of what’s actually being used and define what use is acceptable, even if that’s less satisfying than a memo that says no.

What the AI Act requires of those who verify identity

The European framework asks three things of anyone operating biometric identification systems:

  • Take inventory of the systems and classify them by risk level.
  • Document human oversight over the decisions they make.
  • Be transparent whenever AI is involved.

Biometric systems fall into the high-risk category, with the reinforced obligations that come with it.

The full breakdown of the articles, with their deadlines and exceptions, is covered in this report on the European AI Regulation. What matters here is simpler: the law no longer leaves human oversight as an optional best practice. It turns it into an obligation with a deadline.

Using AI to monitor what AI sets in motion

The oversight the law requires isn’t satisfied just at the moment a deployment gets approved. It has to hold up while the agent is acting, in that gap we already talked about, where risk keeps running with nobody watching it.

If agents execute transactions with no human intervention in the moment, control shifts. It no longer lives in prior approval — it lives in the transaction’s behavior while it’s happening. Catching a deviation after the agent has already acted still has value, but it arrives too late to prevent the damage.

Continuous monitoring, powered by AI, watches that behavior in real time and triggers human review the moment something strays from the expected pattern. That’s the concrete way of sustaining, day to day, what the Regulation asks for on paper.

Verifying that whoever is acting is who they say they are 

There’s another front, separate from the four phases. AI-generated impersonation adds one more layer. It’s no longer enough to decide what an organization’s own agent is allowed to do — you also have to verify that whoever is interacting on the other side is who they say they are. Deepfakes in verification processes and injection attacks, which feed a fabricated image directly into the capture flow without ever going through the camera, are already part of the threat landscape in financial services. We cover this in more depth in this analysis on cybersecurity threats in banking and fintech. And that landscape isn’t going to wait for governance structures to catch up.

Everything covered so far — the agent inventory, the neutrally-chaired committee, behavior monitoring — depends on one prior condition: knowing, beyond doubt, whether what’s on the other side of an operation is a person, an authorized agent, or an impersonation attempt. Without that, there’s no evidence to audit. And without evidence to audit, none of the previous layers hold up. That’s governance on paper, not governance in production.

And it doesn’t distinguish between verifying a human customer and verifying that an authorized agent is, in fact, who it claims to be. It’s the same identity layer, applied continuously to interactions that used to be taken for granted.

At bottom, that’s what holds up the CISO’s new role. Not approving every decision before it happens, but being able to show there was control over it afterward. Brought back to the question that opened this article: when the system acts on its own, someone has to be able to say who was watching it. That someone is no longer whoever signs off beforehand. It’s whoever can prove, afterward, that they were watching.

The set of decisions, permissions, and evidence that determine what an agent is allowed to execute, with what data, under what oversight, and who is accountable when it fails.

It’s taken on by whoever owns the asset or the process. The CISO assesses, recommends, and sanctions. For exceptions the policy doesn’t cover, a neutrally-chaired committee decides, without either party running it.

Inventory of systems, classification by risk, reinforced obligations for high-risk systems (biometric systems fall into that category), documented human oversight, and transparency about AI involvement.

By combining analysis of the captured signal, liveness detection, and control of the capture channel, to rule out that the image was injected rather than actually captured.

The introduction of a fabricated image or video directly into the capture flow, bypassing the camera. It attacks the channel, not the recognition algorithm.

Ready to protect your users?

Discover how Facephi's biometric technology can safeguard your identity verification process.

Facephi Facephi Identity Platform Onboarding Authentication UX Consultancy Facephi Builder Facephi Central Services Fraud Intelligence Platform Identity Fabric KYB Platform Teseo Identity Wallet IDV Suite Cuentas Mula Behavioural Biometrics Linkedin YouTube X Facebook
Secret Link