
Forrester‘s analysts put AI at the center of four of their five top cybersecurity threats for 2026, and the common failure underneath them is weak AI governance. The report names near-autonomous nation-state attacks, shadow agents, an AI software supply chain, and agent identity gaps as the risks organizations need to plan for.
Four of Five 2026 Threats Run on AI
Forrester analyst Jitin Shabadu published the list on June 10, 2026, and only one entry, digital sovereignty across regions and tech stacks, sits outside the AI column. The other four all trace back to how fast enterprises are wiring AI models and agents into daily work.
The first threat is near-autonomous attacks from a nation-state. Cheap access to capable models lets state actors automate and scale exploitation. Forrester points to Anthropic’s report on China-linked actors using its Claude model for cyber-espionage, and to Google Threat Intelligence flagging attackers who misused Gemini. The second is agent threats: personal AI agents claw into enterprises through browser hooks and inbox access, then run as shadow operators. The third turns tools, models, and skills into a sprawling AI supply chain. The fourth pushes teams from legacy identity systems toward agent identity, provenance, and access controls built for software that acts on its own.
One AI Governance Gap Behind Four Threats
Forrester frames these as five separate forecasts, but four of them are not distinct problems, they are one AI governance gap wearing four masks. That gap is measurable: one recent survey found only 8% of tech leaders have strong AI governance in place. Nobody has a full inventory of the agents already running. Nobody can prove where the models and skills those agents pull in came from, and nobody gave the agents an identity that access controls can reason about. The risk shifted underneath most programs this year. It used to mean an AI-powered attack you brace for from the outside; now it means AI systems you deployed yourself, acting at machine speed beyond your visibility. Shadow AI is the tell. When an agent reads a mailbox and moves data faster than any human review can follow, the exposure is simple: no one is watching it work.
Inventory Agents Before the AI-BOM Question
The order matters, because you cannot govern or attest to what you have not counted first.
Inventory every AI agent and the access it holds – Map the browser hooks, inbox connections, and API scopes each one uses, then govern them through a dedicated platform, the shadow-operator problem Shabadu describes.
Stand up an AI supply chain playbook – Demand an AI bill of materials (AI-BOM) for the models, tools, and skills your agents consume. That manifest is what makes the supply chain Forrester warns about auditable.
Give agents their own identities – Move past legacy Identity and Access Management (IAM) to agent-specific identity and provenance, and inspect inbound API requests the way you would treat any non-human account with standing access.
Do that work and Forrester’s four AI problems stop reading as a 2026 forecast and start reading as an AI governance program a chief information security officer (CISO) can put in front of the board.
Join our LinkedIn group Information Security Community!











