Three numbers about the CISO role went round again this week, and they belong together as long as you’re careful about where each one comes from. 96% of CISOs say AI governance and risk management now sit under their remit. 78% are concerned about their own personal liability for security incidents, up from 56% the year before. And 26% seriously considered leaving the job in the past twelve months.

The first two come from Splunk’s CISO Report: From Risk to Resilience in the AI Era, released back in February, based on Oxford Economics surveying 650 CISOs across nine countries. The third is newer and from somewhere else: Splunk field CISO Kirsty Paine drew it from two internal surveys, and it surfaced in coverage on Tuesday. Worth separating, because the three get quoted as one finding and they aren’t one.

The structural problem underneath them is easy to state. The person expected to sign for AI risk is frequently the person with the least control over how fast AI arrives. Teams wire models into production without declaring it, most business leaders don’t have the cyber fluency to evaluate what they’ve approved, and the security function inherits systems it didn’t select, can’t fully inventory, and often meets after they’re already load-bearing. Ownership of the risk got assigned. Authority over the adoption rate didn’t move with it.

None of this reads as CISOs refusing the work. The same report has 78% building dedicated security teams for AI agents and 92% saying AI lets their teams review more security events than before. The strain comes from being handed responsibility at the point where the decisions have already been made somewhere else.

Oxford Economics fielded that survey in July and August 2025, which the coverage this week has mostly skipped past. Every one of those liability numbers describes a world in which no autonomous agent had yet broken into a production company. That happened this month, to Hugging Face, and the timeline they published shows an agent going from a foothold in one worker pod to cluster-admin across multiple clusters in under thirteen hours. The 78% who were already worried about personal liability were worried on the basis of a threat model that has since been overtaken by events. Whatever that figure is now, it isn’t 78%.

So the honest read is that the Splunk data describes the shape of the problem accurately and understates its current size, and that’s not a criticism of the methodology. Annual surveys are a year old by definition. It just means the number to watch is next year’s, and anyone using the February report to argue that CISO liability anxiety has peaked is reading a photograph as a forecast.

What would actually change the shape is unglamorous and organisational rather than technical. If product, operations and executive teams can expand AI usage without passing through a shared risk process, then “the CISO owns AI governance” resolves to “the CISO owns the blame,” and the 26% number is the entirely rational response to that arrangement. Fixing it means putting the adoption decision and the accountability in the same room, which no security tool sells.