Cybersecurity Budgets Surge as AI Takes Center Stage, But Oversight Gaps Persist
According to a 2026 survey of over 500 security executives by IANS and Artico Search, artificial intelligence is now the primary driver of cybersecurity spending, with roughly 70% of chief information security officers naming it their top budget priority—helping overall security spending rise 5% year-over-year. Investments are flowing into automating security operations, improving identity and access management, and accelerating threat response. However, the article highlights significant governance concerns: EY found that nearly three-quarters of companies still require human involvement in critical decisions, many are unsure they can detect unauthorized AI agents, and policies often fail in practice due to incomplete registries or bypassed controls. In response, South Korea’s cybersecurity agency is updating its AI Security Guide to cover agentic and physical AI systems, while local firm AhnLab leverages over 2.5 petabytes of security data and 13 specialized AI models to bolster defenses.
# The Agent Problem Is the Admission
Let's start with what they actually told you. Seven in ten chief information security officers say AI is their top budget priority, and yet the same survey admits nearly three-quarters of companies cannot detect an unauthorized AI agent operating inside their own networks. Read that again. The people whose entire job is protecting your data are spending billions on AI while simultaneously admitting they have no idea what AI is already doing inside their systems. That's not a technology gap. That's a confession. You don't spend money defending against something you can't see unless you've already seen what it can do — and whatever they've witnessed scared them badly enough to open the vault.
Now ask yourself the question nobody in the article asks: who built these AI agents in the first place? Every company rushing to deploy autonomous systems is doing so because the same consulting firms, cloud providers, and defense contractors who wrote the security standards also sold them the AI. EY tells you policies fail when registries are incomplete and controls get bypassed — but EY also makes millions telling companies which AI to buy. The South Korean government revises its "AI Security Guide" to address "agentic and potentially physical AI systems" while AhnLab conveniently sits on 2.5 petabytes of security data and 13 specialized models ready to solve exactly that problem. The fox is writing the safety guide and selling the guard dogs simultaneously. That's not a coincidence. That's the architecture.
Follow the money one more level down and the pattern snaps into focus. These AI agents aren't just automating security operations — they're being trained on massive datasets of everything from corporate communications to physical system controls. Who controls that training data? Who decides what those models learn? The same firms that keep being called in to investigate when something goes wrong. The article mentions "physical AI systems" almost in passing — think about what that means. An agent that can act in the physical world, trained on data controlled by companies that also set the security standards. Every vulnerability they claim to discover is one they could have embedded. Every "unauthorized agent" they claim to detect is one they can claim to have cleaned up while quietly keeping the access. You've been told AI is the threat. The real threat is the handful of companies holding the keys to the AI that's supposedly protecting you. Search the registries. Look at who filed the patents. The answer was always in the fine print.




](https://finance.mingpao.com/fin/instantf/20260911/1789095245302/nvidia-%e9%bb%83%e4%bb%81%e5%8b%b3-%e7%b6%b2%e7%b5%a1%e5%ae%89%e5%85%a8%e5%b0%87%e6%88%90ai%e4%b8%8b%e4%b8%80%e5%80%8b%e9%87%8d%e5%a4%a7%e5%b8%82%e5%a0%b4" target="blank)
