Malik Haidar stands at the forefront of the modern cybersecurity landscape, bringing decades of experience in shielding multinational corporations from high-stakes digital incursions. As we navigate 2026, his work has increasingly focused on the friction between rapid technological adoption and the slower, more deliberate pace of corporate governance. Malik’s unique perspective blends deep technical intelligence with a pragmatic business-first approach, allowing him to see the vulnerabilities that others often overlook in the rush to automate. In our discussion, we explore the widening gap between the AI policies companies have on paper and the reality of how these tools are actually functioning within their networks. We delve into the specific challenges posed by agentic AI—systems capable of independent action—and the urgent need for leadership to move beyond passive registries toward active, real-time oversight to prevent material failures that threaten financial and reputational stability.
Many organizations have established formal AI policies, yet they continue to struggle with identifying unauthorized tools or “shadow” AI agents operating on their networks. From your perspective, why is there such a significant gap between policy creation and technical visibility?
The reality on the ground is that formal governance and operational effectiveness are often two very different things. In recent surveys, we see that while nearly 58% of organizations are inventorying the models they use, these registries are frequently incomplete or out of date because the pace of adoption is just too fast. About four in 10 organizations admit they lack visibility into all the AI tools on their networks, and even more concerning, roughly one-quarter of firms say they cannot detect unauthorized AI agents operating internally at all. Policies are often bypassed under pressure to perform, and if your security team doesn’t have the tools to see a model being used in real time, that policy is essentially just a piece of paper. We are seeing a situation where a registry that is incomplete or a control that cannot detect use in the moment creates a massive security vacuum, leaving the front door wide open for risks that the board believes are being managed.
Agentic AI represents a shift from tools that simply generate text to systems that can execute tasks autonomously. How does this change the risk profile for a corporation, and why are current governance frameworks failing to keep up?
Agentic AI is a completely different beast because governance designed for AI outputs—like checking a chatbot’s answer for accuracy—is simply not sufficient for AI actions. When a system can operate across business processes, interact with data, or execute tasks without a human in the loop, the potential for a cascade of failures increases exponentially. Currently, nearly six in 10 respondents at organizations using these tools feel that no single group actually oversees these agents once they are deployed. Furthermore, 40% of organizations report that accountability for overseeing these autonomous agents is completely undefined. Without clear ownership, these systems call tools and call APIs in the background, and if something goes wrong, the organization is left wondering who was responsible for a decision that a human didn’t even see happen.
With nearly three-quarters of firms requiring humans to be in the loop for major decisions, it seems like companies are trying to maintain control. Why are we still seeing such a high rate of AI-related incidents despite these safeguards?
It is encouraging to see that 75% of firms require human intervention and 71% have implemented mandatory risk management training, but these numbers hide a much darker reality. Despite these efforts, nearly nine in 10 organizations have experienced some form of AI-related problem over the past year. The issue is that high-level training doesn’t always translate to the technical ability to interrupt an autonomous process before it fails. About 58% of companies use external frameworks like those from NIST, but they are applying them to static models rather than dynamic agents. When you have systems interacting with live data and making micro-decisions every second, a human “in the loop” can quickly become an overwhelmed human who is just rubber-stamping processes they don’t fully understand, leading to the material disruptions we are seeing today.
The financial and reputational stakes for AI failure appear to be reaching a breaking point. What does a “materially negative impact” actually look like for a modern enterprise when these systems fail?
We are no longer talking about theoretical risks; we are seeing practical, damaging failures where more than one-third of surveyed organizations have experienced an incident that caused significant harm. This includes tangible data loss, where sensitive corporate intelligence is leaked, and direct financial damage resulting from disrupted operations. Beyond the balance sheet, there is the devastating impact on brand reputation that occurs when an organization cannot explain how an automated decision was made. If a high-profile failure happens and the leadership cannot point to which control failed or who was accountable, it creates a crisis of confidence with shareholders and customers alike. It is the inability to provide evidence after the fact that turns a technical glitch into a full-blown reputational catastrophe.
What is your forecast for AI governance?
I expect we will see a radical shift where companies move away from simply asking if a control has been designed and start focusing entirely on whether that control can actually identify and interrupt autonomous activity in real time. We are heading toward a period where “explainability” becomes the most valuable asset in the enterprise, as organizations realize they must be able to provide a clear audit trail for every action an agentic system takes. Within the next few years, the 40% of companies currently lacking visibility will either close that gap with sophisticated monitoring tools or face such severe material failures that they will be forced to retreat from autonomous integration altogether. The winners will be the ones who treat AI oversight not as a compliance check-box, but as a core component of their active defense strategy, ensuring that every autonomous action can be evidenced, explained, and—if necessary—stopped instantly.

