The Signal

Twenty-seven IT leaders in thirteen industries named the same obstacle this month. Ten named budget.

The twenty-seven said they cannot define the scope. That puts money fourth on the list, behind scope, behind open-ended exploration, behind internal alignment. Scope outranks budget almost three to one.

The pattern is sharpest among the people who can sign. Thirteen leaders in the network said they hold the decision themselves. Nine of those thirteen named scope. Two named budget.

Here is what they were trying to scope. Seventeen of the twenty-seven were talking about AI agents, shadow AI, or AI governance.

An interim CTO in Healthcare wants to audit the agents already running in production and keep a human in the loop. A strategy director at a law firm is watching AI sprawl outrun the firm's process. A Manufacturing CIO has a list of approved tools and no idea what else is in use. An Education IT leader is pushing AI projects toward production and trying not to create shadow AI on the way.

None of those are budget problems. They are boundary problems. You cannot write a scope document for a category that had no line item eighteen months ago. There is no prior contract to copy. There is no peer benchmark that fits. So the decision sits, funded, waiting on a definition nobody has written yet.

These leaders are not stalling. Fourteen of the twenty-seven attached a timeline, and eight of those put the decision inside six months. They intend to buy. They do not yet know what they are buying.


From the people who send this

CXO Brief is published by DoGood. More than seventy enterprise vendors are currently paying for 30-minute briefings with IT and security leaders on AI governance, third-party risk, identity, observability and infrastructure. You choose which vendors to meet, if any. Every completed briefing pays you $150 to $200, as a premium gift card, cash, or a donation to a charity you pick if your employer restricts gifts. Membership is free and by invitation.

Claim your invite

Or reply to this email with the word "briefing" and Ryan will set you up personally.


From the Network

"Need to understand and manage agents being deployed and currently running. How do we audit and make sure we have human in the loop for these agents. What type of security are needed"
— Interim Chief Technology Officer, Healthcare

"A lot of AI sprawl including agentic, need to have a lot more governance and visibility asap. Current firm ways of working is lacking on process & tech aspect, so hoping to at least address latter"
— Senior Director of Strategic Intelligence, Law Firms and Legal Services

"We have several approved tools in use but no insight into what other tools may be in use."
— Chief Information Officer, Manufacturing

Three leaders, three industries, one missing artifact. Each can describe the risk precisely. None can yet describe the boundary.


Top Open Priorities This Week

Two raw asks pulled directly from member submissions in the last 14 days, unedited:

"We are actively moving AI initiatives forward, but in a thoughtful, enterprise manner to avoid shadow AI across the org. We need help thinking big in this space and moving initiatives to production."
— Senior Director of Enterprise Applications, Education

"we started deploying AI org wide primarily with copilot. but we do allow other AI use based upon request and approval process. We dont have a way to track and montior that. Lokking to fill that gap"
— Director of Information Technology, Construction

Both have already said yes to AI. Neither can yet say where it stops.


What vendors are paying to discuss this week

Across the briefings enterprise vendors are currently funding, four topics dominate:

Discovery and runtime control of AI agents across cloud, SaaS and endpoints. This is the exact category the members above cannot scope.

Identity governance that covers machine identities alongside human ones. Every agent in this week's Signal will need a credential and an owner.

Cost control across observability, licensing and data platforms. No tie to this week's stories. It is simply what is being funded.

Human risk, including deepfake and voice-impersonation readiness on live calls. Also no tie this week.


The Context

The headlines are catching up to what the network already knew. On September 1 the OWASP GenAI Security Project published the Agent Control Standard alongside its 2026 Top 10 for LLM Applications. The standard, donated by Zenity, is a vendor-neutral contract for where policy sits in an agent's execution path. It pauses the agent before a runtime effect, sends the pending action to a policy authority, and honors the answer.

That is a real answer to a real gap. It is also version 0.1, a public preview. And it answers a different question than the one members are asking.

Bottom Line: The standard tells you where to put the control point. It cannot tell you which actions your agents may take. That list is the artifact nobody outside your company can write for you.


What to Do About It

Open a blank page and write the scope for one AI agent already running in your environment. Name the systems it may touch, the actions it may take without a human, and the person accountable for it. If you cannot fill all three lines in twenty minutes, that gap is your blocker, not the budget.


The CXO Brief is published by DoGood, the network where enterprise IT leaders are paid for 30-minute vendor briefings.
Know a CIO who needs this? Forward it and they can subscribe here.
Run IT or security at a $100M+ company? Claim your invite.