Join our Newsletter — 33% off our NHI Course

The NHI & Agentic AI Summit – The CISO Imperative – IDV 2026

Session 3: The CISO Imperative — Quantifying NHI & Agentic AI Risk for the Board | Non-Human & Agentic AI Identity Summit @ Identiverse 2026

Speakers: Ross Sherman, Sr. Director Agentic AI, SailPoint | Renee Guttmann, Founder, CISOHive | Troy Wilkinson, Founder, Kyber Technology

In this session from the Non-Human & Agentic AI Identity Summit at Identiverse 2026, three experienced security leaders tackle the problem that sits behind every NHI conversation: how do you get a board to act on a risk they can’t see, touch, or measure?

Ross Sherman frames the stakes at the outset. For two decades, identity risk was knowable — named accounts, clear credentials, access logs. That model is breaking down. Agentic AI systems operate with autonomy, no named user, and no traditional forensic trail. Most boards don’t yet understand this shift, and CISOs who are waiting for a breach or regulatory pressure to educate them are already behind.

Troy Wilkinson opens on why NHI and agentic AI risk is so difficult to surface in a boardroom context. The lack of visibility into service accounts and machine identities was already his biggest concern as a CISO a decade ago. Now, AI agents are exploding that problem by orders of magnitude — workforces of tens of thousands to millions of non-human users that organisations can’t see, control, or govern. His answer to the translation problem: drop the technical language entirely. Boards want fiduciary clarity — what is the probability of loss, what does it cost to fix it, and what does it cost to ignore it. The FAIR model gives CISOs a framework to put actual dollars against NHI risk, making the conversation one of risk acceptance or transfer rather than technology investment.

Renee Guttmann — who has served as CISO at Coca-Cola, Time Warner, Royal Caribbean, and Campbell Soup — takes the CFO question head on. Her approach is to anchor the conversation in what is already provably true: NHIs outnumber human identities by as much as 144 to one, 80% of attacks on identity have leveraged non-human identity, and 68% of organisations — according to CSA research — cannot distinguish whether an action was taken by a human or an AI agent. She also points to the fact that 31% of AI agents are currently operating on human credentials. These aren’t hypotheticals. Attacks attributable to NHI failures have already happened. The materiality question isn’t whether the risk is real — it’s whether your organisation is prepared when it lands.

Guttmann’s most practical contribution is pointing CISOs to the National Association of Corporate Directors (NACD) Cyber Risk Oversight document — a resource she describes as having saved her repeatedly. In its fifth edition, published this year, it includes a dedicated section on AI governance with 25 board-level discussion questions, one of which asks directly how organisations are managing AI agent identity. The value: when a CISO walks into a boardroom and references a framework that 25,000 of the board’s own peers are trained on, they stop being the IT person explaining a technical problem and start being a peer speaking the same governance language.

On the question of why now rather than later, Guttmann’s argument is straightforward: the time to establish guardrails and governance frameworks is before agentic AI becomes embedded in mission-critical systems, not after. There is also a cost to inaction beyond the breach scenario — organisations without foundational identity standards are already burning time and resource on unstructured, uncoordinated decisions about how to deploy AI. Setting a direction, even an imperfect one, eliminates that cost and creates something you can evolve.

Troy Wilkinson adds a practical path for CISOs who need to move without waiting for board approval: use discretionary budget, design partnerships with emerging vendors, or run controlled experiments through an innovation lab within the identity team. The goal is to begin discovery, build internal champions across departments, and demonstrate early wins that make the board conversation easier.

Renee closes by identifying the immediate priorities: elevate the identity team’s standing within the organisation, build engineers who can speak developer language rather than just order-takers processing provisioning requests, own the identity strategy at the CISO level, establish clear accountability frameworks across the organisation, and — as a non-negotiable starting point — complete discovery. Knowing what agents exist, who owns them, what they’re connected to, and what they have access to is table stakes. Auditors already expect it. The tools exist. The organisations that can’t answer these questions have no foundation to build anything on.

The session closes with Lalit Choda asking the panel who should own AI governance within an organisation. The consensus: not a single named officer, but a cross-functional governance committee with stakeholders from across the business, reporting into the board’s audit committee. AI governance is a shared responsibility — and security leaders need to stop admiring the problem and start building the foundation.