CXOInsights by CXOCIETY
PodChats for FutureCISO: Accountability without control – a CISO’s sovereignty dilemma
Sep 27, 2026
Season 7
CXOCIETY | FutureCIO FutureCFO FutureIoT
Asia’s 2027 security landscape is defined by a “governance over hype” reckoning. IDC projects regional security spending will hit US$39.5 billion in 2026, while noting only 7% of APeJ enterprises feel highly prepared in GRC skills.
As Gartner forecasts 40% of enterprises will demote AI agents by 2027 due to governance gaps surfacing only in production, CISOs face a dual mandate: deploy agents at machine speed while proving verifiable, auditable control to fragmented regulators.
Fastly CISO Marshall Erwin joins us on this episode of PodChats for FutureCISO to tackle the pressing issue of managing accountability in the age of AI as viewed from the perspective of the CISO.
1. High level view of Fastly.
2. Do enterprises in Asia have a comprehensive, real-time inventory of all AI agent identities and their permitted data access?
3. From a CISO perspective, are current threat models updated to include agents as active actors, not just tools?
4. How are enterprises demonstrating to regulators across multiple jurisdictions that their AI guardrails and data flows are governed with verifiable, auditable evidence, moving beyond policy to operational proof?
5. Have enterprises mapped every sector-specific data localisation requirement (beyond the general PDP laws) that applies to business in Asia? (global context)
6. Are current public and private cloud architectures designed for the necessary data residency and portability?
7. In your view is zero-trust architecture sufficiently mature to act as the control plane for AI, effectively preventing a compromised agent or partner from causing a cascading regional incident by eliminating lateral movement?
8. How are enterprises operationalising digital sovereignty, ensuring that our reliance on global cloud providers does not compromise our technical and operational control, especially in the event of a geopolitical or regulatory shift?
9. Advise on Accountability without control – a CISO’s sovereignty dilemma