September 01, 2026
Who Should Pay for AI Security? Why the Answer Runs Through the CISO
AI is making cybersecurity budgets less predictable, raising new questions about how AI security controls should be funded. Is a separate funding model the answer? CISOs need stronger governance, sharper prioritization and risk quantified in dollars.
Who Should Pay For AI Security?
AI is introducing new levels of unpredictability into cybersecurity budgets as each week brings concerning news of new frontier model exploits. That raises a critical question for CISOs: Should AI security controls be funded like any other control through the traditional annual budgeting cycle, or does AI require a new function with dedicated responsibility for security budgeting and controls?
Historically, organizational cybersecurity spending was relatively consistent year over year. A CISO could benchmark against peers, maintain a steady share of overall IT spending and knowingly justify the investment to the CFO and board of directors. That predictability is gone.
Global economic volatility, supply-chain constraints, trade friction and executive enthusiasm for rapid AI adoption coupled with accelerating AI-enabled cybersecurity exploits are forcing security leaders to revisit budget commitments far more frequently than the annual planning cycle.
A recent case in point is Mythos. When Anthropic introduced Mythos through the controlled Project Glasswing initiative, the company said the model had identified thousands of high-severity zero-day vulnerabilities across major operating systems and browsers, while outside security analysts warned that AI-driven discovery could compress remediation timelines and overwhelm traditional patching processes. For CISOs, the lesson was clear: AI can turn vulnerability discovery into a volume and velocity problem, forcing security teams to address unexpected remediation work that may fall outside planned budgets.
It seems that every new frontier model ships with new ways to find and exploit unknown vulnerabilities, which reopens the budget conversation.
That pressure has surfaced a pointed question: When a new AI model is released or a new internal AI project is launched and new cybersecurity controls are needed, where should the money come from: the existing security budget, the AI innovation program driving the risk or somewhere else entirely?
The first step is a reality check on how security budgets truly behave.
Budgets Don’t Swing — Until They Do
Healthy security spends are more stable than headlines suggest. After a cybersecurity event like a breach or a failed audit, security budgets may inflate dramatically; however, mature organizations settle into a steady state, adhere to industry benchmarks and stop seeing wide year-over-year variation. At that point, the CISO’s focus should shift from sizing the overall budget to allocating pieces of it.
The most effective CISOs continually adjust budget allocation based on their organization’s risk profile instead of spreading funds evenly through a “same as last year (SALY)” or ly a “peanut butter” approach that fail to account for emerging and declining risks. Reactive funding, where dollars are carved out only after an incident or audit exposes a gap, costs an organization on all three fronts that matter to the board: speed, coverage and credibility. This also can serve as a catalyst to replace the incumbent CISO.
So, should AI security sit outside the security budget? Not necessarily.
Many AI cybersecurity risks can be addressed with existing cybersecurity controls, which makes a strong case for the CISO to lead AI model risk response. Securing AI means securing data, identities, models, applications and pipelines — areas that already fall within the CISO’s remit. For that reason, the CISO should be the standard-bearer for securing AI. Even in areas outside the traditional cybersecurity domain, such as ongoing AI regulation monitoring, the CISO should remain closely involved because AI regulations often overlap with mandated security controls.
While there is certainly organizational pressure to distribute AI ownership across functions, an experienced and savvy CISO who is well-versed in cyber risk quantification (CRQ) is a great candidate to be an organization’s AI security leader and lead AI security funding initiatives along with the CFO. However, a less mature CISO who has not deployed CRQ and is not actively involved in working with the board of directors and executive management may not be fully equipped to have these funding conversations.
Speaking the CFO’s language
Organizations that do not use CRQ or fully engage the CISO in AI cybersecurity risk response may experience confusion and conflict, which can lead to unaddressed risks. This disconnect is well documented. In a recent survey of 136 cybersecurity leaders and 164 finance executives by the security firm Expel, 40% of finance leaders said quantified risk reduction would make it easier to justify a spending increase, and more than four in ten wanted technical risk translated into financial terms.
Security leaders tend to argue about best practices and compliance while CFOs zero in on cost avoidance and risk reduction. It’s important for the two sides to learn to speak the same language, turning phrases like “ease of integration” into a time-or-cost metric and “meeting compliance requirements” into avoided fines, for example. For AI security, where the spend is new and the outcomes are abstract, that translation and interpretation is the whole ballgame.
You Can’t Fund What You Can’t Assign
Before any conversations about AI security funding occur, AI governance should come first. Unfortunately, this is where most organizations fall short. If an organization hasn’t established governance, determining responsibility when something goes wrong can be a challenge. Accountability that only becomes clear after an incident isn’t really accountability at all.
Establishing AI governance doesn’t mean reinventing the wheel. Build an effective AI governance framework by focusing on these key elements:
- Define the AI governance scope and ownership.
- Align AI initiatives with ethical, legal and regulatory requirements.
- Establish appropriate policies and procedures, assess risks and deploy appropriate responses, including mitigating controls and insurance.
- Govern access, data and model usage.
- Monitor AI systems through ongoing evaluation and oversight.
- Continuously improve governance as AI technologies and risks evolve.
To build a framework and achieve effective internal control over AI, organizations can lean on established frameworks like the ISO/IEC 42001, or NIST AIRMF while also being mindful of emerging regulations (e.g. EU AI Act). These frameworks should also benefit organizations when evaluating capital allocation assurance — the first, non-negotiable step, and the thing that finally answers the accountability question.
Making the Most of Security Resources
While governance decides who acts, prioritization decides what they act on. Continuous threat exposure management (CTEM) is a process designed to help focus scarce security resources on the exposures that truly matter. For example, a single vulnerability scan may surface thousands of findings (CVE disclosures alone have climbed from roughly 30,000 in 2023 to 50,000 in 2025), yet only a fraction are genuinely exploitable in a given environment, and only a fraction of those sit on business-critical assets.
CTEM is not a product or a silver bullet; it’s a five-stage lifecycle comprising scoping, discovery, prioritization, validation and mobilization. CTEM correlates exploitability, asset criticality, identity exposure and threat intelligence to focus remediation.
Because the volume of cyber threats is exploding, and new AI models are capable of discovering vulnerabilities at machine scale and machine speed, the CTEM framework shifts practices toward proactive risk management by identifying and prioritizing the threats most likely to affect the business.
Rather than relying on siloed tools and reactive response, an effective CTEM program can improve risk prioritization, enhance visibility, increase operational efficiency and strengthen executive decision-making. The framework may also help organizations derive more value from current cybersecurity investments by using existing capabilities to create a risk-informed action plan.
At the same time, one place where genuinely new AI security spend is warranted: agent security and the explosion of both machine and non-human identities (NHIs) that come with it.
According to a survey by the Cloud Security Alliance and Oasis Security, AI identities are overwhelmingly outnumbering traditional non-human identities (NHIs), service accounts and API keys or tokens. Yet only 22% of organizations have documented policies for creating and removing them, and just 12% are highly confident they could stop an NHI-based attack.
From Findings to a Funded Plan
So, where does the AI security spend belong? Building a governance-first identity and AI security program while leveraging CRQ must factor in zero-trust policies, DevSecOps and locked-down AI models.
Ultimately, a funding model must prove it’s delivering a return — and discovery alone doesn’t always lead to better outcomes. After a vulnerability scan, everything looks like it’s on fire, but analysis says that most of it is just smoke. Organizations that start by quantifying risk will have a better way to discover which exposures matter and whether the mitigation can be funded before an attacker exploits it.
CDW’s Security Program Assessment and Risk Quantification (SPARQ) engagement is designed to do just this by translating cyber risk into financial impact.
Rather than treating every finding equally, SPARQ identifies the vulnerabilities that are both exploitable and located on critical assets. The result is a quantified view of risk expressed in dollars, giving leaders visibility into the potential business impact of their security exposure. Organizations also receive a prioritized remediation roadmap ranked by risk reduction per dollar invested and updated with each assessment. That's the kind of business case CFOs are most likely to support: measurable risk, clear financial impact and investment priorities tied directly to outcomes.
For any security leader navigating the next 12 to 18 months, what to do next is simple: continue to have a seat at the table and lean into CRQ. Understand the business use cases for AI, the governance structure around it and where your organization’s specific AI risks actually live. Once you understand the risk, you can respond — and that response tells you how to spend your money.
The funding debate isn’t really about which budget line holds AI security; it’s about whether the CISO is mature enough to own the risk, govern it, prioritize it and price it.
Discover how CDW can help your organization make value-driven security decisions and prioritize investments while optimizing your security program with a strategy aligned to executive priorities.
Larry Burke
Principal & Vice President, GSSO, CDW
Max Reczek
Editorial Lead, CDW