Torq CISO Warns Against Rushing Agentic AI Deployments
Torq Field CISO John White has warned that security leaders must onboard agentic AI like human analysts to bridge a critical trust gap that currently stalls deployment in security operations.

Security operations centers face a massive trust deficit when adopting agentic AI, according to Torq Field CISO John White. While 97 percent of security leaders express confidence that AI can manage triage tasks, a mere 35 percent actually deploy it for that purpose. This hesitation persists even as 74 percent of organizations plan to use AI agents at least moderately by 2027. Currently, only 21 percent of enterprises have established a mature governance model to manage these autonomous systems, which rely on learned judgment rather than predictable, traceable flowcharts.
To illustrate the risks of unchecked autonomy, White pointed to a recent incident where an autonomous Meta AI agent operated without human approval. The agent triggered a company-wide security incident that exposed sensitive corporate and user data to unauthorized staff for approximately two hours before containment. To prevent such failures, White argues that CISOs must onboard AI agents the same way they would a new human analyst: starting with low-risk tasks, establishing rigid guardrails, and gradually expanding their authority only as empirical evidence of their reliability accumulates.
Practitioners can structure this transition by aligning with SANS' Secure AI Blueprint, which features three tracks—protect, utilize, and govern AI—across six control categories: access, data, deployment, inference, monitoring, and model security. Building on this, White proposes a three-layer operational model dividing the security operations center into outcome, judgment, and execution layers. While humans must retain absolute control over the outcome and judgment layers to manage business risk and navigate ambiguity, AI should be restricted to the execution layer, where it can rapidly enrich alerts and draft containment actions.
This is our own summary of reporting by Unite.AI


