Last year, we took the stage at Forrester’s Security & Risk Forum to challenge the stories leadership teams were beginning to tell themselves about AI. That keynote became our new report, Resetting Security’s AI Narrative With Boards And Executives.

We wrote it because CISO clients keep coming to us with the same concern: The AI mandate is expanding faster than the budgets, expertise, and controls needed to make adoption secure, sustainable, and well governed.

Though currently true, CISOs won’t resolve that tension by arguing that AI agents fail too often. Economic incentives will continue to drive adoption even when technology falls short. Leading with an argument against a technology that boards and executives already want can also undermine CISOs’ credibility. Security leaders have to change the conversation from whether AI works to what the enterprise must invest in to make it trustworthy.

What To Know: AI’s Business Case Excludes Some Of Its Most Important Costs

Boards and executives see AI as a path to greater scale, productivity, and efficiency. But the business case often fails to account for the security, governance, and workforce investments required to enable and sustain those gains. Boards and executives need a more complete explanation as to how:

  • AI consumption creates security consequences. AI costs are becoming more complex and less predictable as organizations adopt new models, pricing structures, and agentic workflows. Uncontrolled consumption can also signal inefficient processes, malfunctioning agents, misuse, or compromise. Security leaders who fail to account for these costs may be forced to cut other parts of the security program to pay for AI.
  • Autonomy raises the stakes beyond traditional technology risk. As agents gain access to credentials, data, tools, and other agents, organizations must govern not only what those systems do but whether their actions remain aligned with human intent and enterprise policy.
  • Automation can weaken the cybersecurity talent pipeline. Security organizations face pressure to deliver the same efficiency gains expected elsewhere in the enterprise, including taking on more work without corresponding increases in headcount. Automating entry-level work may produce short-term savings, but it also removes opportunities for practitioners to develop the judgment and experience that autonomous systems will continue to require.

What To Do: Change The Conversation By Starting With Three Questions

Connect AI security to outcomes the business already values, including revenue protection, customer trust, regulatory exposure, workforce readiness, and sustainable growth. Three questions help shift the conversation from whether AI works to what the enterprise must provide for it to deliver sustainable value:

  • Who pays to secure enterprise AI adoption? Use this question to make AI security part of the enterprise’s AI investment, rather than a cost the security organization must absorb through trade-offs elsewhere.
  • Who governs the cost, intent, and behavior of autonomous systems? Use this question to establish shared accountability for AI, rather than allowing responsibility to fall by default to the CISO.
  • Who develops the experts these systems will continue to require? Use this question to ensure that near-term efficiency goals don’t undermine the cybersecurity skills and experience the enterprise will need over the long term.

The answers to the above don’t sit within the security org alone. They require board support, executive buy-in, and a shared understanding that secure enterprise AI adoption depends on more than AI itself. CISOs who can reframe the narrative will move beyond debating technology efficacy and help shape the investments, accountability, and workforce strategy that determine whether AI delivers sustainable value.

Forrester clients can read Resetting Security’s AI Narrative With Boards And Executives and schedule a guidance session or inquiry with us to discuss how to reset expectations with their own boards and executive teams.

For more on AI cost governance, securing intent, the CISO’s role in trust and assurance, and continuous practitioner upskilling, join us in Washington, DC on November 9–10 for Forrester’s Security & Risk Forum.

Share