Skip to content
By CISO

The CISO's 2027 Budget Memo: What to Fund, What to Cut, What to Defend When AI Agents Hit Production

AI agents are reaching production while security budgets grow 4%. How to use The CISO Desk benchmark cards, tool overlap analyzer and templates to write a 2027 memo that funds agent security by reallocation, with a copyable template.

The CISO's 2027 Budget Memo: What to Fund, What to Cut, What to Defend When AI Agents Hit Production, by Deepak Gupta on guptadeepak.com

AI agents are moving into production during the budget year you are planning now, and most security budgets are not growing to cover them. Gartner's 2026 CIO survey found 17% of CIOs had already deployed AI agents and another 42% planned to within a year. The same season, security budget growth slowed to 4%. This post shows how to use The CISO Desk to write a 2027 memo that funds agent security by moving money rather than asking for it.

Verified as of 25 September 2026 against the sources linked inline.

I founded LoginRadius in 2013 and scaled it past a billion identities, so the identity lines in this memo are the ones I know best. Everything else here comes from sources you can hand to a CFO.

What is happening: agents arrive, budgets flatten

Two numbers define the 2027 planning cycle. The first is adoption. Gartner's 2026 CIO and Technology Executive Survey, fielded in June 2025, found 17% of CIOs had already deployed AI agents and 42% more planned to within twelve months. Gartner's own report is paywalled, so that link is Opsin's summary of Gartner's February 2026 Market Guide for Guardian Agents.

Read that as a calendar, not a trend. Together that is 59% of surveyed CIOs with agents live or planned within a year. For many of them, fiscal 2027 will be the first full budget year with agents in production. An AI agent here means software that takes actions on its own, using credentials and permissions a person granted it. Every one of those agents is a new identity your program has to account for.

The second number is money. The IANS Research and Artico Search budget benchmark of 587 CISOs found average security budget growth slowed to 4%, down from 8% and the lowest in five years. Security fell from 11.9% to 10.9% of IT spend. More than half of respondents reported flat or shrinking budgets.

Meanwhile the vendors selling to you expect a much bigger year. Gartner forecast worldwide information security spending rising about 12.5% to roughly $240 billion in 2026, in its July 2025 forecast. The CISO Desk card on market growth against buyer budget growth puts the two side by side: the market grows at roughly three times the rate of the average buyer's budget.

Why it matters to you

The gap means agent security will not arrive as new money for most programs. It has to come out of money you already spend. That changes what the memo is for. A request that only adds lines will be read against a 4% growth year and trimmed. A request that shows where the money comes from reads as management.

Agents also expose a governance gap that already exists. CyberArk's research, recorded on the Desk's machine identity benchmark card, found 88% of respondents define a privileged user as human only. Yet 42% of machine identities hold privileged or sensitive access. An agent with production access lands in exactly that blind spot.

The shadow version of the problem is already present. A BlackFog and Sapio survey of 2,000 UK and US employees, summarized on the shadow AI benchmark card, found 49% use AI tools their employer has not sanctioned. You cannot govern agents you cannot list, and half the workforce is already ahead of the approved toolset.

The attack data does not let you drop the basics to pay for any of this. Verizon's 2026 Data Breach Investigations Report found 31% of breaches started with vulnerability exploitation, now the leading entry point. It also found third parties involved in 48% of breaches, with supply chain breaches up 60% year over year. The money for agents has to come from overlap, not from the controls attackers are still using.

What The CISO Desk shows

The CISO Desk is a reference site for security leaders, built around decision briefs, benchmark cards, browser tools and templates. It is the part of this portal written for the person who signs the budget. The pieces that matter for a 2027 memo are the benchmarks, two decision briefs, one tool and one template.

How it is sourced

Each benchmark card holds one statistic with a named source, a link, a sample size and a hand-verification date. Every card also states what the figure does not mean. Vendor-funded research carries a visible label, as the Wiz, CyberArk and BlackFog cards do. The methodology page lists the build gates: a statistic whose source has not been re-verified within 90 days blocks the page from publishing.

That matters in a budget meeting. A CFO who questions a number can follow it in one click to its origin. Each card also carries a board line and a blank comparator, such as "Our own ratio is", so you can place your internal figure next to the external one.

Three findings worth taking into the memo

Budget follows dated events, not arguments. The brief on what triggers a security budget line names five triggers: a failed audit, a blocked deal, an incident, a regulatory deadline and a contract expiry. Its verdict is direct. A request tied to none of them is a reallocation, and it should be framed that way.

An agent is an entitlement with an owner. The brief on orphaned agents explains why offboarding misses agents. Offboarding disables the accounts a person logs into. An agent is a separate identity that keeps acting after its creator leaves. The fix it proposes is a policy, not a product: require a named owner and an expiry date when each agent is created.

Sprawl is where the money sits. Wiz's 2026 CISO Budget Benchmark, carried as a card on the Desk, found 58% of organizations run more than 25 security tools. Close to half of the 300-plus leaders surveyed said cloud complexity and tool sprawl constrain their program. The card is careful about one limit: consolidation does not automatically save money, and it can move cost into one larger line.

How to use it to build the memo

The memo has three columns. Fund is the new spend agents require. Cut is the spend you retire to pay for it. Defend is what must not be trimmed to make the numbers work. Work through the Desk in this order.

  1. Frame the request. Read the budget trigger brief and decide which trigger you hold. If you hold none of the first four, your trigger is contract expiry, and the memo is a reallocation request built around renewal dates.
  2. Size the agent problem. Use the questions in the orphaned agents brief. List every credential created by a human but not used by one, and name an owner and an end date for each. The entries you cannot fill in are your orphans, and their count is the evidence for the Fund column.
  3. Test revocation before you price it. Pick one pilot agent and time how long it takes to revoke every token it holds. I set out a drill for this in the AI agent kill switch test. The measured time becomes your baseline, and the Fund line pays for the gap to your target.
  4. Find the overlap. Enter your stack in the security tool overlap analyzer. It runs entirely in your browser and makes no network calls. It flags any function claimed by three or more tools as a consolidation candidate, and gives a rough redundant-spend estimate that its own methodology says to treat as a starting point, not a commitment.
  5. Turn overlap into dated savings. Move the candidates into the security tool overlap register, a free CSV with cost, renewal date, notice period and named owner per row. Add a column for renewal date minus notice period and sort by it. A tool whose notice date has already passed cannot fund anything this cycle.
  6. Anchor every number to a card. Pull the board line from each benchmark you cite and fill in the comparator with your own figure. Put the sourced external number and your internal number in the same sentence.

For the Fund lines themselves, the Agent Security Map's CISO checklist for AI agent security gives the vendor questions for inventory, agent identity, kill switch and audit trail. Before you buy a standalone product, check whether your identity provider now covers the same control. Identity platforms have been acquiring agent-security startups this year, as I covered in why the identity giants bought AI agent security.

The memo: copy it, then replace the brackets

Write it for a CFO and CEO who will read it in five minutes. Delete any line you cannot evidence internally, because one unsupported line weakens the rest.

To: [CFO], [CEO]
From: [CISO]
Re: FY2027 security budget: fund, cut, defend

Summary. We request [total] for FY2027, a change of [+/- X%]. New spend for AI agents is [amount]. We will fund [amount] of it by retiring overlapping tools at renewal, so the net increase is [amount].

Why now. [Business unit] will put [number] AI agents into production by [date], with access to [systems]. Today we cannot list every agent, name its owner, or revoke its access quickly. Our revocation drill took [time].

Fund.

  1. Agent inventory and ownership: every agent registered with a named owner and an expiry date. [amount]
  2. Revocation: cut off one agent, or every token it holds, across the systems it uses. [amount]
  3. Audit: each agent action logged with the human, agent, tool and data involved, sent to our SIEM. [amount]

Cut. [Tool A] and [Tool B] duplicate [function] already covered by [platform]. Last notice dates: [dates]. Saving: [amount].

Defend (hold flat). MFA and SSO coverage, access reviews, privileged access, vulnerability remediation and third-party access review. Agents inherit these controls from the people who create them.

We will report quarterly. Share of production agents with a named owner. Time to revoke an agent in a drill. Dollars retired against plan.

Decision requested. Approve the Fund lines, contingent on the Cut savings landing by [date].

The evidence behind each call

LineCallEvidence to cite
Agent inventory and ownershipFundCyberArk: 42% of machine identities hold privileged or sensitive access
AI tool discoveryFundBlackFog and Sapio: 49% of employees use unsanctioned AI tools
Overlapping tools at renewalCutWiz: 58% of organizations run more than 25 security tools
Vulnerability remediationDefendVerizon DBIR: 31% of breaches start with exploitation
Third-party access reviewDefendVerizon DBIR: third parties involved in 48% of breaches
The reallocation framing itselfContextIANS and Artico: 4% budget growth against a market growing about 12.5%

What to do next

  • Ask every business unit for the agents it plans to run in production in 2027, with dates and the systems each will touch.
  • Run one revocation drill on a pilot agent and record the time.
  • Add a named owner and an expiry date to every agent you already know about.
  • Fill in the overlap register and sort it by last notice date.
  • Pick the benchmark cards you will cite and write your own number into each comparator.
  • Send the memo to the CFO before the formal budget meeting, not during it.

Frequently Asked Questions

How many companies have deployed AI agents?

Gartner's 2026 CIO and Technology Executive Survey, fielded in June 2025, found 17% of CIOs had already deployed AI agents. Another 42% planned to deploy them within twelve months.

How much are security budgets growing for 2027 planning?

The IANS Research and Artico Search benchmark of 587 CISOs found average security budget growth of 4%, the lowest in five years. Security fell from 11.9% to 10.9% of IT spend, and more than half of respondents reported flat or shrinking budgets.

How do you fund AI agent security without a bigger budget?

Reallocate from overlapping tools at renewal. Wiz found 58% of organizations run more than 25 security tools. Use an overlap analysis to find duplicated functions, then retire only the tools whose notice date you can still meet this cycle.

What should the first AI agent budget line pay for?

Inventory and ownership. Each agent should be registered with a named human owner and an expiry date, so it stops working unless someone renews it. Revocation and audit build on that list, and neither works without it.

What security spending should a CISO defend from cuts in 2027?

MFA and SSO coverage, access reviews, privileged access, vulnerability remediation and third-party access review. Verizon's 2026 DBIR found exploitation behind 31% of breaches and third parties involved in 48%, and agents inherit identity controls from the people who create them.

Get new Scams & Cybersecurity writing

Enjoyed this? Subscribe and tell us what you read most. Scams & Cybersecurity is already ticked for you. No tracking pixels, unsubscribe with one click.

Tell us what you read most (optional)

About DeepakPublicationsAnalysisAll tracks