Back to News
Market Impact: 0.3

Who owns AI risk at work? Business and tech leaders can’t agree, PwC survey finds

Source: ZDNET

Artificial IntelligenceCybersecurity & Data PrivacyManagement & GovernanceRegulation & LegislationTechnology & Innovation
Who owns AI risk at work? Business and tech leaders can’t agree, PwC survey finds

PwC's Digital Trust Insights 2027 survey of roughly 4,000 business and technology leaders in 71 countries found no consensus on accountability for agentic AI security: 29% assign it to CIOs/CTOs, 26% to dedicated AI leaders, 17% to CISOs, and 11% say responsibility is unclear. While 33% of organizations have hired dedicated AI roles and 47% put cybersecurity on board agendas, unclear governance and identity controls for AI agents create growing enterprise security and compliance risks. The report points to demand for AI-specific governance, agent identity management, and potentially new chief AI security officer roles.

Analysis

The investable implication is a gradual shift in AI spend from model experimentation toward identity, privilege management, auditability, and workflow controls. This favors platforms already embedded in enterprise access-management stacks—OKTA, CyberArk (CYBR), Microsoft (MSFT), and SailPoint (SAIL)—but the revenue capture will depend on whether agent credentials become a separately priced control plane rather than a feature bundled into broader security suites. MSFT is structurally best positioned to bundle agent governance into Entra, pressuring pure-play pricing; CYBR has the clearest premium monetization path where agents receive privileged access to production systems.

For OKTA, this is strategically positive but not yet a near-term earnings catalyst: customers will demand proof that agent identities expand paid identity volumes or attach incremental governance modules, rather than merely increase support and security costs. Over the next 1-3 months, watch enterprise security-budget commentary and product announcements around non-human identity management; over 6-18 months, a material rise in agent-related breaches or regulatory enforcement would accelerate procurement and favor vendors with auditable policy enforcement. Citigroup (C) has no direct equity read-through: governance ambiguity is an industry-wide operational-risk issue, not a differentiated earnings driver absent a disclosed incident or remediation program.

Consensus may overestimate the need for a new executive category and underestimate procurement inertia. Large enterprises usually respond to new control requirements by extending existing IAM, SIEM, and cloud-security vendors, which argues against treating this as a greenfield software category. The contrarian risk to cyber longs is that enterprises slow autonomous-agent deployment until accountability frameworks mature, delaying the expected seat, credential, and workload-volume uplift despite strong AI experimentation headlines.

AllMind Terminal

AI-powered research, real-time alerts, and portfolio analytics for institutional investors.

Request Trial

Market Sentiment

Overall Sentiment

mildly negative

Sentiment Score

-0.20

Ticker Sentiment

OKTA0.10

Key Decisions for Investors

  • Maintain a 6-12 month relative-value preference for long CYBR versus short a broad software basket such as IGV: privileged-access controls are more likely to command incremental budget than generic AI-governance features. Reassess if CYBR reports slowing net-new subscription growth or indicates agent security is being bundled without incremental pricing.
  • Keep OKTA on an event-driven watchlist rather than initiate solely on this theme. Upgrade to a tactical long only if management quantifies non-human or agent identity as a paid expansion driver at earnings or an investor event; the key falsifier is continued flat-to-down net retention or evidence that Entra bundle economics are driving competitive discounting.
  • Favor MSFT as the lower-risk large-cap beneficiary for 6-18 months, since Entra can make identity controls a prerequisite for broader Copilot and agent deployments. The risk/reward is more defensive than pure-play cyber: upside comes from security-suite attach, while downside is limited if agent adoption is deferred.
  • Do not position in C from this signal. Set an alert for a disclosed AI-control failure, regulatory consent-order language, or a material technology-risk reserve; only then would remediation spending, legal exposure, and reputational costs create a bank-specific trade setup.

More News

From AllMind Research

Browse all research