On 25 June 2026, teissTalk host Jonathan Craven was joined by Satyam Rastogi, Director of Information Security & DevOps, BAMKO; Lisa Ventura, Chief Executive and Founder, AI and Cyber Security Association; and Paul Barbosa, V P & General Manager, Cloud Security & SASE, Check Point.
In a call for action, the leaders of the Five Eyes cyber security agencies have warned that frontier Al models are anticipated to exceed current industry expectations, fundamentally transforming both offensive and defensive cyber capabilities in months rather than years. They’ve urged business leaders to understand and assess risk, readiness and accountability, prioritise foundational cyber security practices and controls, empower cyber leaders with authority and resources, as well as stay actively engaged as threats and guidance evolve. To mitigate emerging risks that previously unknown and zero-day vulnerabilities pose, secure-by-design and secure-by-default must become standard practice and defence in depth must remain essential. To meet these new challenges, getting the basics right has become more important than ever. The gap between time-to-exploit and time-to-patch keeps growing, which cyber criminals are increasingly leveraging. AI is now impacting cyber security’s whole operating model. In Check Point’s survey, 77 per cent of respondents said they have changed their strategy due to AI but only 26 per cent felt that their architecture is ready and it only needs minor changes. This roughly 50 per cent readiness gap is unprecedented. The paradigm shift that Ai governance can be baselined against is the move to the cloud. In those days, one of the major concerns was shadow IT that was tackled by the cycle of visibility-policy-governance- and-control. However, currently, only about 5 per cent of organisations has visibility of AI usage. Visibility concerns are compounded by how solution providers embed agentic AI capabilities in almost each of their existing solutions.
The unique feature of this shift is that it puts the whole legacy architecture under pressure, not just certain parts of it. Infrastructure, for example, is stretched by API traffic that has exploded thanks to agentic AI. Although most of the problems are similar to what businesses experienced when migrating to the cloud, some accountability and governance issues are specific to AI – at the time of the survey, only 14 per cent of enterprises had a role uniquely accountable for AI governance. Bringing access control in line with agentic AI is especially important as agents – using one token for multiple transactions – can easily take advantage of the current regime. Putting a human in the loop can only be a temporary solution as humans’ attention will naturally flag after long incident-free periods. Also, the question arises how a human in the loop can work at machine speed.
Rather, the direction of travel seems to be a move to a more rigorous operating model. What can be expected is security built on multiple control planes with the control of first resort being non-human access control, the control of last resort being network and gateway controls with the classification, movement and encryption of data sitting in the middle. The new architecture must be built around the new paradigm. Now everything is going to execute at runtime, so when some anomaly is detected, it’s already far too late. That’s why focus should be on prevention in run time against what the existing architecture was designed for. Every product and every part of the architecture must now be geared or retrofitted to detect incidents at runtime. As agentic systems have already been deployed, governance has to play catch-up.
AI democratises cybercrime. Exploits will no longer require the knowledge of coding languages – prompts can be given to generative AI in natural human language. There will be versions of the current security systems – IM, DLP, EDR – designed specifically for AI. Fundamental protocols used to build applications are evolving too, where non-human identities render a whole class of authorisation protocols insufficient. As data poisoning increasingly presents a common threat, scrutinising the fidelity of data becomes central. Regulatory frameworks are also getting adapted to wide AI use. There is a Top 10 OWASP for AI and GDPR and NIST also offer a good baseline. If vendors, researchers and policy makers come together, they can create frameworks and ecosystems that are relevant and can serve as benchmarks. Some regulations – SOX, NIS and Dora – now mandate red team exercises or have restricted the use of gen AI models.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543