New work does not always arrive with a new title

When people look for AI-driven labor-market change, they often search for new job titles. But organizations can change by keeping an old title while rewriting the problems and capabilities inside it. CISO is a useful example.

Deloitte’s 2026 Global Technology Leadership Study found that 49% of surveyed organizations reported a CISO role, up from 31% in 2023. More important than the count, Deloitte frames the role as moving from security gatekeeper toward enterprise risk orchestrator.

AI agents change the basic security question

Traditional identity and access management asks who can access what. Once AI agents act inside the enterprise, the question expands to who—or what—can access what, when, and on whose behalf.

If an agent can call tools, read data and act for a human, identity, authority, approval, audit trails and escalation become part of the security design. The CISO can therefore move beyond blocking attacks toward orchestrating owners and controls across functions.

AI governance and agentic-AI controls are already appearing inside a CISO organization

Temasek’s current AVP/VP, Cybersecurity (Governance Oversight) role reports to the CISO and explicitly covers AI security, AI governance, model governance, agentic AI controls and AI assurance alongside cybersecurity.

The title remains Cybersecurity and the reporting line remains CISO. But the capability boundary now includes governing autonomous agents and responsible AI adoption. This is a concrete case of the work moving underneath an established title.

A new Agent Assurance specialty can rewrite an old executive role

Temasek is also recruiting an Agent Assurance Engineer to empirically test and continuously monitor production AI-agent behavior, including tool permissions, behavioral specifications, escalation triggers and drift.

This does not mean the CISO personally performs every task. As specialist functions multiply, executive work can shift toward connecting risk owners, decision rights and controls across them.

BANSEOG VIEW | Treating the same title as the same job can break executive search

Title is an efficient filter in Executive Search. But if AI rewrites established executive roles, Title becomes a rougher proxy. Two CISOs can share the same label while one is strongest in SOC, IAM and incident response and another adds AI governance, agent authority, model risk and board-level risk communication.

The question shifts from “Has this person been a CISO?” to “What problems did this person actually own under that title, and have they already faced the problems the role will own next?” That is why Title → Capability → Decision Right → Business Problem can matter more.

The title may stay while the capability the company is buying changes

In a separate Deloitte survey of 3,235 IT and business leaders across 24 countries, only 21% reported mature agentic-AI governance, while 74% expected at least moderate AI-agent use by 2027. The larger the gap between deployment and governance, the more important the leadership question of who designs and owns authority and risk becomes.

Wipro and CrowdStrike’s September 9 launch of a CISO Command Center, framed as a shift from tool-driven security to an enterprise-wide risk-led operating model, is another signal in the same direction. These examples do not prove that every CISO role is changing in the same way, but they do show AI governance and agent assurance entering the boundary of security leadership in some large organizations.

Banseog View — The title stays. The job moves.

New AI work does not have to appear under a new title.

The same executive title can contain a different capability boundary and different decision rights.

Executive Search may need to read the Business Problems a leader actually owned, not only the title they held.

Primary sources and references

Deloitte surveys are weighted toward larger organizations, and Temasek roles are individual company examples. They show observable role-boundary signals, not proof of a universal CISO-market transition.