SecureWorld News

Agentic AI Adoption Gap Is a Security and Change Management Problem

Written by Cam Sivesind | Thu | Aug 20, 2026 | 1:21 PM Z

McKinsey's latest research on organizational readiness for agentic AI contains a finding that should catch every CISO's attention, even though it wasn't written with security teams in mind. In its 2026 State of Organizations research, McKinsey surveyed thousands of global business leaders and asked what's actually holding back agentic AI at scale. The answer wasn't infrastructure, budget, or model capability; it was change management and siloed ways of working—organizational problems, not technical ones.

That finding, explored in McKinsey's follow-up piece, "How to close the agentic adoption gap," is aimed at CEOs, CFOs, and CHROs. But read it as a security leader, and it describes something very familiar: the exact conditions under which shadow AI, ungoverned agent sprawl, and inconsistent risk exposure take root.

If change management and organizational silos are the real bottleneck to scaling agentic AI well, they're also the real bottleneck to scaling it safely. Security teams that treat this as someone else's problem are going to inherit the consequences of it anyway.

McKinsey's framing of silos as an adoption blocker will sound familiar to anyone who has tried to inventory shadow IT, let alone shadow AI. When business leaders identify siloed ways of working as a bigger obstacle than technology infrastructure, they are effectively describing an environment where different teams are adopting AI agents independently, with different tools, different data-handling habits, and no shared governance model connecting any of it.

That's not a hypothetical risk. It's the precise mechanism behind most of the AI governance gaps that security and compliance teams are already fighting: a marketing team standing up an agent to draft campaigns, a finance team automating vendor onboarding with a different tool, a product team wiring an agent directly into a customer-facing workflow—each one making its own judgment calls about data exposure, access scope, and oversight, with no consistent policy connecting them.

McKinsey's research suggests this isn't a temporary, early-adoption phase problem. It's a structural one, and it will persist—and compound—for as long as organizations keep treating agentic adoption as a series of disconnected departmental initiatives rather than a coordinated capability.

The 'compliance vs. capability' distinction applies to security too

One of the more pointed arguments in McKinsey's piece is that traditional change management—periodic communications, one-time training, static guidance documents, top-down rollout plans—creates awareness but doesn't build the trust, habits, and operating discipline organizations actually need to scale agentic AI responsibly. McKinsey argues the goal should shift from compliance (did employees complete the training) to capability (are they learning to redesign their work responsibly, faster than last quarter).

This is worth sitting with, because it's also an accurate description of how a lot of security awareness and AI governance programs are currently run. An annual phishing training module or a one-time "acceptable AI use" policy memo checks a compliance box, but it doesn't build the ongoing judgment employees need to make good decisions the next time a new AI tool shows up in their workflow, or the next time an agent is given a little more autonomy than the one before it. McKinsey's research on the broader organization applies directly to security: static, one-time governance artifacts are necessary but insufficient. They create awareness; they don't create discipline.

For security teams that have spent years pushing for continuous, behavior-based awareness programs over annual check-the-box training, this is validating—and it's also a reason to make sure AI governance specifically doesn't slide back into the compliance-only model that security teams have already learned doesn't work.

What 'C4 leadership' means for the CISO's seat at the table

McKinsey introduces a leadership framework it calls "C4," which includes leaders who model uncertainty rather than project certainty, and who lead people through learning rather than managing them through resistance to a known plan. The research found that leaders who admit they're still figuring things out accelerate adoption more than those issuing confident strategy narratives.

That's a genuinely uncomfortable idea for security leaders, whose instinct— and whose job, often—is to project certainty: here is the policy, here is the control, here is the acceptable boundary. But McKinsey's research points to something CISOs should take seriously: if the rest of the organization is moving toward a model of continuous, adaptive learning around agentic AI, and security governance stays anchored in the old model—fixed policies, defined end states, periodic reviews—the security function risks becoming exactly the kind of static, siloed artifact McKinsey warns will fail to keep pace. Worse, it risks being routed around entirely by business units eager to move faster than a compliance-first security function can accommodate.

The alternative McKinsey describes isn't abandoning governance, it's building governance that can evolve at the same speed as adoption. For security, that likely means fewer static AI-use policies frozen at a point in time, and more continuous risk assessment processes that get revisited as agent capabilities, permissions, and use cases expand. It means CISOs showing up not just as the function that approves or blocks a new agentic use case, but as a partner helping the organization learn what safe, scaled agentic adoption actually looks like as it goes—which is a materially different posture than gatekeeping from the sidelines.

The five chapters, read as a governance roadmap

McKinsey lays out what it calls the organizational playbook for agentic adoption: awareness, belief, commit, develop, and enforce. It's worth reading this sequence specifically as a governance model, not just a change management one, because it maps cleanly onto where most organizations' AI security programs currently stall.

Most organizations have "awareness," as everyone knows AI agents are coming, or already here. Many have started to "commit," standing up pilots and initial tools. Far fewer have built "develop," the ongoing capability-building that turns one-off AI experiments into consistent, well-governed practice. And fewer still have reached "enforce," where governance is actually operationalized and consistently applied rather than aspirational.

That gap between early-stage awareness and late-stage enforcement is exactly where security risk concentrates. An organization with high AI awareness but low AI enforcement is an organization full of agents operating with inconsistent oversight, inconsistent access controls, and inconsistent data handling—not because anyone decided that was acceptable, but because governance never made it past the early chapters of the playbook. Security leaders reading McKinsey's framework have a useful diagnostic here: which chapter is your organization actually in, honestly, for agentic AI governance, and does your security function have a defined role in getting to "develop" and "enforce," or is it waiting to be looped in once the enforcement problem has already become an incident?

McKinsey highlights CFOs treating "extreme budget pressure" as a catalyst for learning, forcing the organization to find leaner, more effective ways of getting work done with agentic tools, rather than layering AI spend on top of existing processes without redesigning them. There's a security parallel worth drawing out explicitly: budget pressure that drives faster, less deliberate agentic rollouts without commensurate governance investment is exactly how organizations end up with the "ineffective adoption" McKinsey warns generates real token, compute, governance, and oversight costs without matching performance gains.

In practice, that means security and risk functions need a seat in how CFOs are allocating that "portfolio of experiments" McKinsey describes—not to slow down the pace of experimentation but to make sure governance and oversight capacity scale in proportion to it. An organization that treats security and governance as a separate, laggard budget line from the AI experimentation budget is setting up exactly the kind of adoption-value divergence the research warns about, just with a risk dimension layered on top of the performance one.

The takeaway for security leaders

McKinsey's research wasn't built to answer a cybersecurity question, but it inadvertently makes a strong case for one: the same organizational conditions that block value creation from agentic AI—siloed adoption, static change management, compliance-first governance, leadership that projects false certainty—are the conditions that produce ungoverned, high-risk AI sprawl. Solve for one, and you materially improve your odds on the other.

For CISOs and security leaders, the practical takeaway is to stop treating AI governance as a control layered on top of business-led AI adoption, and start treating it as one of the core organizational capabilities—alongside the CEO's ambition-setting, the CFO's budget discipline, and the CHRO's workforce development—that determines whether agentic AI scales well at all.

That means pushing for continuous, capability-building governance over one-time policy documents, breaking down the silos between how different business units are adopting agents before those silos become the shadow-AI inventory nobody can fully account for, and getting a seat at the table early enough in the "awareness to enforce" journey to shape it rather than being the function that shows up once enforcement has already failed.