The enterprise contradiction: adopt AI faster, secure it later
Key takeaways
- Employees are told, sometimes in their performance reviews, to adopt AI as fast as possible in the domain they understand least, and that behavior is the fastest-growing attack surface.
- Organizations split into a hell-no camp that blocks agents and a cart-before-the-horse camp that already runs them without visibility; there is no comfortable middle.
- Agentic tooling does not create the data-governance problem; it surfaces the one the organization already had.
- Most security leaders want to say yes to the business, so sell enablement, not gatekeeping.
- Security is a cost center and AI is a rare chance for a CISO to be seen enabling revenue; sell them that identity.
Table of contents
Somewhere in a large enterprise right now, an employee is being told to adopt AI faster. Not encouraged. Told. In some organizations the instruction has reached performance reviews: find ways to use AI in your work, and be measured on it. The same employee has near-zero training in how these systems fail, what they can access, or what happens when an agent acts on their behalf in a system they barely understand.
Multiply that by every department, and you get the defining contradiction of the enterprise right now. The behavior the organization is actively incentivizing is also its fastest-growing attack surface. Adoption is mandated from the top. Security is asked to catch up from behind. Nobody has resolved the tension, because the tension is structural: the business case for AI is measured in quarters, and the risk is discovered in incidents.
If you are building an agentic-security company, this contradiction is not background noise. It is your market. Every buyer you will ever talk to is living inside it.
Shadow agents and the vanishing perimeter#
The scale of the problem is easy to underestimate because most of it is invisible by definition. In some organizations, shadow agents already outnumber sanctioned ones. An employee connects an assistant to their inbox. A team wires an agent into the CRM to draft follow-ups. None of it goes through procurement, because none of it feels like buying software.
And the supply side is accelerating the drift. Every SaaS vendor is quietly becoming an agent vendor. The tools an enterprise already licensed are shipping agentic features into production environments, which means an organization's agent population grows without anyone making a single new purchasing decision. The perimeter did not move. It dissolved.
Here is the point a board advisor made in our research that reframes the whole category: agentic tooling does not create the data-governance problem. It surfaces the one the organization already had. The permissions were always too broad. The data was always over-shared. Agents simply move fast enough, and touch enough systems, to turn a chronic condition into an acute one.
Agents are not the disease. They are the diagnostic.
Two camps, no middle path#
Hanah-Marie Darley and Henry Comfort, the founders of Geordie, describe the market as split into two camps. Unpacking it with early adopters, Darley told us on our podcast, "they essentially found themselves in two camps: those who couldn't adopt because the risks were too big, or those who did adopt and then realised the risks were too big. There was no middle path." The first is the hell-no camp: security blocks agents outright, and the organization forfeits the productivity the board is demanding. The second is the cart-before-the-horse camp: agents are already in production with no visibility, and the reckoning is scheduled for them, in the form of an audit or a cyber-insurance renewal that asks questions nobody can answer.
What there is not, in their telling, is a comfortable middle path. The pressure to adopt does not pause while security designs a policy. An organization is either refusing the future or running it unsupervised.
The detail that matters most for founders is this: most security leaders want to say yes to the business. The hell-no posture is not conviction. It is the only move available to a leader who cannot see what the agents are doing. Give that leader visibility and the posture changes, because the posture was never the goal. It was a symptom of blindness.
Geordie's founders reach for a story from the industrial revolution to make the point. Mining machinery went deeper than ever before and released an invisible, flammable gas. The response that worked was not closing the mines. It was the Geordie lamp. "It gave line of sight into this new risk that you otherwise couldn't see with your own eyes," Darley told us, "so that you could deal with the risk and then continue to power innovation." AI agents are the same moment. "They're operating across systems, within code, all over the place. And so we ultimately turn the lights on." The gas is already in the tunnel. The question is whether anyone can see it.
See it in action.
The CISO wants to be the AI champion#
Now look at the same contradiction from the buyer's chair, because this is where most agentic-security pitches go wrong.
Security is a cost center. It has always been a cost center. Nobody attributes revenue to the breach that did not happen, and the CISO's budget conversation is a permanent exercise in justifying insurance. Then AI arrives, and for the first time in most CISOs' careers, there is a boardroom topic where security can be seen enabling revenue rather than taxing it. The CISO who helps the business adopt AI safely is not a gatekeeper. They are a champion of the thing the CEO cares about most this year.
That is a rare identity upgrade, and it is on offer exactly once.
A CISO in our research put it with an analogy worth keeping. The answer to road deaths was never banning cars. It was making cars safer, and making the safe path the easy path, so that nobody had a reason to route around the rules. Seatbelts, crumple zones, motorways. The transport did not slow down. The dying did.
The lesson for security leaders is direct: if the safe path is slower than the shadow path, the shadow path wins, every time, in every organization. The job is not to say no. It is to make yes survivable.
Sell enablement, not gatekeeping#
For founders, the pitch implication falls straight out of the psychology. Most agentic-security messaging is fear-led: the threats are multiplying, the agents are unaccountable, be afraid, buy control. Fear-led messaging casts the CISO as a gatekeeper, and the gatekeeper identity is precisely the one they are trying to escape.
The pitch that lands sells the other identity. You are not offering a way to stop the business. You are offering the line of sight that lets the CISO say yes, with evidence, faster than their peers. The product is control, but the story is permission. When we worked with Geordie on their brand, their archetype work moved them deliberately away from fear-led messaging toward empowerment. Comfort described the shift on our podcast as "focusing on empowerment of customers in a really specific way", and that repositioning is inseparable from how the company now reads: not the alarm in the mine, but the lamp.
There is a second-order benefit. Enablement stories travel upward. A fear story stops at the security team, because fear is the security team's job. An enablement story gets forwarded to the CIO and the board, because it speaks to the thing they are already being measured on. In a bottom-up market, a story that survives being forwarded is a distribution channel.
Sell the CISO the identity of the enabler, and the control comes along for free.
The market will not wait for a resolution#
The contradiction at the top of this piece is not going to resolve itself politely. Adoption mandates are strengthening, agent populations are compounding through the SaaS supply chain, and the audit and insurance cycle is about to start asking pointed questions of the cart-before-the-horse camp. The founders building for this moment are selling into a buyer who is pressured, exposed, and looking for the vendor who understands that they want to say yes.
Which raises the harder problem. Understanding the contradiction gets you into the conversation, but nearly every agentic-security vendor now opens with some version of the same story, and we have written separately about how to stand out in agentic security when everyone is agentic. And whatever story you choose still has to survive contact with a buyer whose stack is already overflowing, which is why it pays to remember that CISOs don't want more tools. They want fewer, with better line of sight.
The enterprises figured out the hard way that the answer was never banning cars. The vendors who win this market will be the ones who showed up selling headlights.

Phill Keaney-Bolland
Co-founder and Designer, Yaya
Co-founder and designer at Yaya, and host of the Cult Products podcast. Fifteen years designing products, brands and UX across multiple industries before narrowing to cybersecurity, and lectures on design at Imperial. Works with cybersecurity founders on positioning, strategy and the website that has to carry a launch, across identity, cloud security, AI agents and software supply chain, including Twine out of stealth and Geordie AI, which won the RSA Innovation Sandbox in 2026.