BlueprintBlueprint
Security review is where most AI Agent deals stall. Here's how to walk your CISO through the use case and get to a confident sign-off.
Bringing on a new AI Agent often gets held up at security review, and it’s rarely because of the technology itself. More often, by the time you're asking your Chief Information Security Officer (CISO) to sign off, they’re missing the information they need about how you’re planning to use the Agent, what data it touches, what actions it can take.
To get around that, you need to bring your CISO in at the right time, and give them the right context when you do. Neither requires security expertise, but you need to be prepared.
Here’s how to walk your CISO through your Agent’s use case and answer any questions they’ll raise, so they can sign off with confidence.
Around 90% of what a security review covers for an AI Agent isn’t new. It’s the same security requirements you’d apply to any software vendor – your data stays isolated from other customers’, it’s deleted on request, and access stays limited to the people who need it. The standard controls still apply there.
None of this makes AI security less serious, or less regulated. The point is that you’re not starting from scratch. The remaining 10% is where it changes: the new, AI-specific risks a standard review won't catch. That’s what the Agent introduces, and where the conversation with your CISO is best spent.
Our guide on AI Agent certifications and compliance covers what that 10% looks like in more detail.
Before meeting with your CISO, write a short paragraph and send it to them ahead of time, so it's not something they're hearing for the first time in the room. It should cover three areas:
An Agent raises two kinds of concerns. The first comes from what it says, like hallucination and prompt injection – when hidden instructions are slipped into a message to steer the Agent off the rules you’ve set.
The second comes from what it does. Once the Agent starts taking actions, your CISO will want to know two things: how it proves its identity to the systems it reaches, and who’s responsible for the data it pulls back.
Security teams call this the “shared responsibility model.” The vendor secures its own system and the Agent, and you decide what each action is permitted to reach and how you handle the data it returns.
With the use case clear, prepare for the questions most likely to come up:
You’ll have some of these answers already. For the rest, the vendor’s trust center is your first port of call. A credible vendor should have a self-serve hub with certifications and audit reports that answers most questions without a live conversation. If you need a person, look for their CISO or, increasingly, a Chief Trust Officer – a newer role combining security and AI safety.
Your CISO already knows an AI Agent can’t be made completely risk-free. Hallucination and prompt injection are inherent to how the technology works. A vendor who claims otherwise does more to erode your trust than build it.
Look instead for a vendor who is specific about the risks and can demonstrate the steps they take to mitigate them.
Take prompt injection as an example. Over a long enough conversation, a determined user might get the Agent to drift off its configured tone. Doing it doesn’t take special access, only the ability to message the Agent like any other customer. However, a well-built Agent won’t go further. Strong guardrails stop it from acting beyond the permissions you’ve set or reaching another customer’s data. How strict these guardrails are varies by vendor, so it’s something worth pressing them on.
Ask:
If you’re using Fin, one of those guardrails is defensive prompting. It adds extra protective instructions in the background when it processes a customer message, helping it to ignore attempts to override its original instructions.
The strongest evidence you can ask for is independent, recurring adversarial testing. That means external red-teaming and penetration tests run multiple times a year, not once at launch. Some certifications now require this. AIUC-1, for example, mandates a quarterly penetration test with no high or critical findings to keep the certification. A vendor who can show you current results from that testing proves it is still checking its own work.
How a vendor handles these questions is itself a signal. One that is upfront that risks exist and can show how it keeps them contained is more trustworthy than one that dismisses concerns.
A CISO conversation that gets stuck almost always comes down to the same thing – the CISO was asked to sign off without the context to weigh the security and compliance questions.
Bring them in at the right time for your industry, and get the use case in front of them before the review starts, not in the room. Do that, and the review still does its job. It just ends in a confident yes instead of a blocked deal.
Thibault Candebat is Chief Information Security Officer at Fin. Connect with him on LinkedIn.
Follow Fin for the latest research, guides, and product updates on AI customer service.