Vanta Executive Warns AI Security Adoption Is Outpacing Governance
A TechRadar article by Vanta's senior governance executive warns that security teams are adopting AI agents faster than they can govern them, risking more security theatre. It urges continuous oversight, scoped agent identity and human approval for high-impact actions.
The article cites industry research showing that more than half of UK security leaders believe AI-driven threats are advancing faster than their teams can respond, while 80% are already using or planning to use AI agents as part of their security strategy. According to the author, that gap between adoption and assurance is where the next incident lives.
Despite the availability of compliance automation tooling, the article says most compliance work is still done by hand. UK organizations report spending around 12 weeks each year on compliance tasks and a further nine weeks on vendor reviews, time that is diverted from meaningful risk reduction.
Governance has not kept pace with AI adoption, according to the article. Closing the gap starts with visibility, including a complete inventory of AI systems deployed on purpose, model APIs engineers call, AI embedded in SaaS stacks, third-party agents, MCP servers and shadow AI. The article applies the same discipline to identity: every agent is a new actor in the environment and should have its own identity, access scoped to its job and no shared service account with broad permissions.
Before deploying an AI agent, teams should decide what it can access, what data it can see, where a person needs to approve an action and how that action could be rolled back, the article says. High-impact actions such as changing user access, deleting data or moving money should always retain meaningful human oversight. Controls should continue after deployment through runtime measures such as least-privilege access, just-in-time permissions, segmentation, circuit breakers and automated containment.
The article says rising regulatory pressure, from the Cyber Security and Resilience Bill to the FCA's operational resilience rules, has intensified the security theatre problem. More than half of UK security leaders say they now spend more time proving security than improving it, and many describe current frameworks as little more than security theatre.
AI can reduce burnout and improve productivity for overstretched teams, but the article warns that if compliance remains static and checklist-driven, AI risks accelerating the wrong outcomes: faster evidence collection, more controls to maintain and greater administrative burden without a corresponding improvement in resilience. The fix is not more automation but a different target, the article says: compliance should be a byproduct of security that actually works, not the finish line.