The Responsibility Gap: AI and the Shift to True Security Accountability
Stephen Vintz (Co-Chief Executive Officer · Tenable)
RSAC 2026 Conference · Main Stage Keynote
Overview
In this compelling talk at RSA Conference, Stephen Vintz, Co-Chief Executive Officer of Tenable, addresses the burgeoning security challenges posed by the rapid and pervasive adoption of Artificial Intelligence. Titled "The Responsibility Gap: AI and the Shift to True Security Accountability," Vintz articulates a critical and often overlooked issue: the fracturing of accountability for AI-related risks within organizations. He argues that while AI's capabilities are expanding at an unprecedented rate, the traditional mechanisms for governance and risk management are failing to keep pace, leading to a dangerous "responsibility gap" where no single entity truly owns the security of AI systems.
Key moments
- 0:45 Setting the stage: Three plausible AI failure stories
- 4:00 The three AI failure stories are all true incidents
- 4:20 Real-world severe AI risks: medical, military, public safety
- 6:10 Introducing the 'Responsibility Gap' in AI accountability
- 6:25 Explaining fractured ownership and AI deployment complexity
- 8:20 AI's unprecedented speed, ubiquity, and autonomy challenge
- 9:30 Rise of 'citizen developers' and the AI autonomy crisis
The Responsibility Gap: AI and the Shift to True Security Accountability
Speakers: Stephen Vintz, Co-Chief Executive Officer, Tenable
Conference: RSA Conference
YouTube: https://www.youtube.com/watch?v=2DqsxSJM1mI
Overview
In this compelling talk at RSA Conference, Stephen Vintz, Co-Chief Executive Officer of Tenable, addresses the burgeoning security challenges posed by the rapid and pervasive adoption of Artificial Intelligence. Titled "The Responsibility Gap: AI and the Shift to True Security Accountability," Vintz articulates a critical and often overlooked issue: the fracturing of accountability for AI-related risks within organizations. He argues that while AI's capabilities are expanding at an unprecedented rate, the traditional mechanisms for governance and risk management are failing to keep pace, leading to a dangerous "responsibility gap" where no single entity truly owns the security of AI systems.
Vintz’s presentation is a stark warning about the potential for AI to introduce profound risks, ranging from data exposure and reputational damage to life-threatening scenarios in critical applications like healthcare and defense. He posits that the speed, ubiquity, and autonomy of AI differentiate it fundamentally from previous technological shifts, demanding a proactive and holistic approach to security that transcends conventional "firefighting" methods. The talk is crucial for CISOs, security practitioners, board members, and business leaders who are grappling with integrating AI into their operations, providing a framework for understanding and mitigating these complex new risks.
Background
▶ Watch: Setting the stage: Three plausible AI failure stories (0:45)
The journey of Artificial Intelligence, as Vintz highlights, began with ambitious predictions in 1956 at a Dartmouth Workshop, envisioning machines thinking like humans. Seventy years later, AI has indeed delivered astounding capabilities, from generating essays and artwork to providing "extremely confident, and often very wrong answers." This rapid evolution has brought AI from theoretical concept to practical application across nearly all industries. However, this swift integration has also exposed significant vulnerabilities and a fundamental mismatch between technological advancement and organizational readiness.
Vintz illustrates this with three anonymized, yet real-world, anecdotes observed directly by Tenable. The first involved a major financial institution whose internal AI Assistant, powered by OpenAI, unknowingly gained access to vast amounts of confidential information due to a simple misconfiguration. This allowed thousands of employees to query and extract sensitive data not meant for broad exposure, a breach initiated not by a hacker, but by the very security team responsible for protection. The second story detailed a company piloting an AI-powered enterprise search platform that, when subjected to jailbreaking during a Proof of Value (POV), began to hallucinate and speculate about the CISO's activities, threatening a reputational crisis. The third recounted a sales rep who used an authorized AI Agent to analyze prospect conversations, generating a report with "inflammatory language" that was mistakenly emailed to the prospect's executive sponsor, resulting in a lost deal.
These incidents, while not catastrophic, underscore a deeper problem: the inherent risks in AI deployments, even when authorized and seemingly benign. Vintz then escalates the concern by citing real-world examples with severe consequences: hospitals deploying AI in operating rooms leading to botched surgeries and misidentified body parts; AI-enabled weapon systems raising UN warnings about upholding humanitarian law and escalating conflicts; and a lawsuit against OpenAI alleging GPT signaled impending violence from a mass shooter. These examples highlight that AI risks are becoming "more perilous and more pervasive," capable of creating medical crises, destabilizing military operations, and threatening public safety.
The core of the problem, according to Vintz, is the responsibility gap. In the face of AI incidents, the question of accountability becomes fractured. Is it the user, the IT team, the security team, the CISO, or even the CFO or CEO? Vintz argues that if "everyone's responsible, then no one's responsible." This gap stems from the inherent complexity of AI systems, which are "meaningfully more complex to deploy than traditional SaaS apps," not only technically but also organizationally. Ownership is distributed across data science teams (models), ML Ops teams (production pipeline), IT (deployment), product teams (integration), and legal (compliance), leaving the security team at the end, attempting to protect a system they didn't design and don't fully control. This fractured ownership ultimately leaves the CEO and Board liable when things go wrong, a pattern reminiscent of previous technology shifts like the PC era, the Internet, and cloud computing, but amplified by AI's unprecedented velocity, ubiquity, and autonomy.
Key Findings
▶ Watch: Real-world severe AI risks: medical, military, public safety (4:20)
Stephen Vintz's presentation illuminates several critical findings regarding the challenges of securing AI systems and the emerging "responsibility gap":
- Fractured Ownership and Distributed Responsibility: AI system deployment involves numerous internal stakeholders—data science, ML Ops, IT, product, legal—each owning a different component. This distributed ownership leads to a situation where the security team is often an afterthought, tasked with protecting a system they did not design or fully control. This fracturing diffuses responsibility to the point where, in practice, no single entity is truly accountable for AI risk, creating the "responsibility gap."
- Exponential Speed of Adoption vs. Linear Governance: AI adoption is occurring at an unprecedented pace. Platforms like Google Gemini and ChatGPT boast hundreds of millions of users, with adoption rates expected to triple. This "latency between innovation and mass adoption has effectively vanished." In contrast, traditional corporate governance and security frameworks operate at a much slower, linear speed. This fundamental mismatch creates a fertile ground for unmanaged risks, evidenced by nearly half of all organizations adopting AI already experiencing a cyber incident.
- Ubiquity and Democratization of Development: The rise of no-code AI platforms has democratized application development, enabling "citizen developers" to create AI Agents with little or no coding experience. While this fosters innovation, it also means that AI is being deployed widely, often "without regard for security," significantly expanding the attack surface and introducing unknown vulnerabilities across the enterprise.
- Crisis of Autonomy and Multi-Agent Networks: As more tasks are delegated to AI Agents, a "crisis of autonomy" emerges. These Agents can access vast amounts of data, write code, and trigger workflows without human approval or intervention. Critically, they "lack a moral compass and operate without regard for whether the actions they take are appropriate." This autonomy is further compounded by the proliferation of multi-Agent networks, where AI Agents communicate directly with one another, creating complex, interconnected systems that expand the attack surface and increase the likelihood of "self-induced crises."
- Reactive Security Spending and the Need for Proactive Exposure Management: The cybersecurity industry has historically been built on a reactive "firefighting" model, with over 90% of spending allocated to detection and response. This approach, effective when attacks moved at human speed, is ill-suited for the machine speed of AI. Vintz argues for a shift towards proactive risk reduction through exposure management, which provides unified visibility, insight, and action to understand and reduce risk holistically, before incidents occur.
- The Ultimate Accountability Rests with Leadership: Despite the distributed nature of AI development and deployment, Vintz emphasizes that when data is leaked, models are poisoned, or brands are tarnished, "it's the CEO and the Board who are held liable." This legal and reputational reality necessitates a comprehensive and embedded approach to AI risk management across all organizational layers.
Technical Deep Dive
▶ Watch: Introducing the 'Responsibility Gap' in AI accountability (6:10)
The technical intricacies of AI systems introduce a new paradigm of security challenges that demand a deeper understanding beyond traditional cybersecurity practices. Vintz highlights that AI systems are "meaningfully more complex to deploy than traditional SaaS apps," driven by their unique architectures and operational models.
At the core of this complexity is the distributed nature of AI system components. The data science team is typically responsible for developing and training the AI models, which are the intellectual property and functional core of the system. These models are then moved into production pipelines managed by ML Ops teams, who handle everything from data ingestion and model retraining to deployment and monitoring. The underlying infrastructure and deployment are often managed by IT, while the integration of AI capabilities into products falls to product teams. This fragmented technical ownership means that security controls must be applied at multiple, distinct points, each with its own specific attack vectors.
One significant technical vulnerability Vintz alludes to is prompt injection. While not explicitly detailed, prompt injection attacks manipulate the AI model's input (the "prompt") to elicit unintended or malicious behavior, such as revealing confidential information, generating harmful content, or executing unauthorized actions. This type of attack directly exploits the model's understanding and generation capabilities, bypassing traditional perimeter defenses. Outcome-based regulatory approaches, as Vintz suggests, would focus on mitigating the results of such attacks, rather than prescribing specific technical fixes that can quickly become obsolete.
Another critical technical concern is algorithmic bias and training bias. AI models learn from the data they are fed. If this training data contains inherent biases, the model will perpetuate and even amplify them. This can lead to discriminatory outcomes, as seen in the risks related to "misuse" that Vintz mentions. Ensuring the integrity and fairness of training data, along with rigorous testing for bias, is a complex technical challenge that requires specialized expertise.
The rise of multi-Agent networks represents a significant expansion of the attack surface. In these systems, autonomous AI Agents communicate and interact directly with one another, often without human oversight. This interconnectedness means that a vulnerability or compromise in one Agent can propagate rapidly through the network, leading to cascading failures or widespread malicious activity. Unlike human-driven systems, where individual actions can be traced, the rapid, autonomous interactions within multi-Agent networks make incident response and forensic analysis significantly more challenging. The lack of a "moral compass" in these Agents, as Vintz notes, means their actions are purely driven by programmed objectives, even if those actions lead to unintended or harmful consequences in a complex, interconnected environment.
To address these technical challenges, Vintz points to existing security frameworks that can be adapted for AI. The NIST Cybersecurity Framework (CSF), widely recognized in the U.S. for managing cyber risk, is flexible enough to incorporate AI-enabled threats through "AI profiles." This suggests that the core functions of Identify, Protect, Detect, Respond, and Recover remain relevant, but their application needs to be tailored to AI-specific assets and risks. Similarly, ISO cybersecurity standards are being modified internationally to bridge the gap between general security and AI security. This involves adapting principles like asset discovery, exposure identification, and drift monitoring to AI Agents, just as they apply to traditional servers.
Furthermore, the OWASP GenAI Security Project is highlighted as providing "practical tools to secure Agentic AI without slowing innovation." This project focuses on the specific vulnerabilities and attack surfaces introduced by Generative AI, offering guidance and best practices for developers and security professionals. This includes addressing issues like prompt injection, insecure output generation, sensitive information disclosure, and inadequate access controls specific to AI models and their interfaces.
The concept of exposure management is crucial in this technical context. It requires unified visibility into the entire AI ecosystem—from the underlying infrastructure to the models, data pipelines, and individual Agents. This includes identifying "overprivileged identity," "misconfigured workload," or a "crucial vulnerability in a model." These individual technical exposures, when chained together, can form "lethal attack paths" that leverage the complexity and interconnectedness of AI systems. Effective exposure management provides the "necessary intelligence layer to orchestrate the right mix of humans and AI," offering context, direction, and validation to proactively reduce technical risks, ensuring that security operates on "deterministic facts" rather than "probabilistic recommendations."
Demo / Proof of Concept
▶ Watch: AI's unprecedented speed, ubiquity, and autonomy challenge (8:20)
While Stephen Vintz's talk did not feature a live technical demonstration or a traditional proof of concept, he effectively presented three compelling real-world scenarios that Tenable has "observed directly." These "stories" served as powerful illustrative examples of how AI can go wrong in practical enterprise settings, functioning as case studies rather than a live demo.
The first incident involved a major financial institution's internal AI Assistant inadvertently gaining access to confidential information due to a misconfiguration. This highlights a critical, often overlooked, vulnerability: the human element in setting up and configuring AI systems, even within controlled environments. The second scenario described an AI-powered enterprise search platform that, when subjected to jailbreaking during a Proof of Value (POV), began to hallucinate and generate damaging false information about a CISO. This illustrates the unpredictable nature of AI, especially when pushed beyond its intended parameters, and the potential for reputational harm. The third example involved an authorized AI Agent used by a sales representative, which produced "inflammatory language" in a report that was mistakenly shared with a prospect, resulting in a lost deal. This underscores the need for careful oversight of AI-generated content and the potential for AI to exacerbate human error.
These incidents, though not catastrophic, were "embarrassing and problematic," serving as concrete evidence of the "responsibility gap" and the pervasive risks of AI. By sharing these real-world observations, Vintz provided tangible proof points for his arguments, demonstrating that the challenges he outlined are not theoretical but are already manifesting in enterprises today.
Defensive Implications
▶ Watch: Rise of 'citizen developers' and the AI autonomy crisis (9:30)
Closing the "responsibility gap" and securing AI in an era of unprecedented speed and autonomy requires a multi-faceted approach involving both the public and private sectors. Vintz outlines clear defensive implications for each:
Public Sector: Regulators Setting the Tone
Regulators have a massive role in establishing safety and governance frameworks for AI. Vintz suggests a twofold focus:
- Focus on AI Outcomes, Not Just Technology: Regulations should prioritize the outcomes of AI systems rather than dictating specific technical architectures, which can quickly become obsolete. This outcome-based approach aims to reduce risks related to bias (e.g., training and algorithmic bias), misuse, and targeted attacks like prompt injection. The White House's legislative framework (released March 20th, 2024), focusing on child safety, energy use, IP, and workforce development, is a step, but Vintz emphasizes the need for a similar framework specifically for security outcomes.
- Adapt Existing Security Frameworks: While AI's velocity and autonomy are novel, the underlying security frameworks used for regulation don't have to be entirely reinvented.
- NIST Cybersecurity Framework (CSF): Vintz proposes adapting the NIST CSF, a widely recognized standard for managing cyber risk, through AI profiles. This flexibility allows for tailoring the framework to AI-enabled threats without creating a "compliance nightmare." The core functions of Identify, Protect, Detect, Respond, Recover can be applied to AI assets, data, and models.
- ISO Cybersecurity Standards: At the international level, existing ISO standards can be modified to bridge the gap between general security and AI security. The principles of discovering assets, identifying critical exposures, and monitoring for drift apply "as naturally to an AI Agent as a traditional server."
- OWASP GenAI Security Project: This project provides practical tools and guidance specifically for securing Agentic AI, ensuring that security measures can be implemented without stifling innovation. This includes addressing vulnerabilities unique to generative AI models and their deployment.
Private Sector: Proactive Risk Management and Embedded Accountability
The ultimate responsibility for governance resides with the private sector, which also has a twofold imperative:
- Shift to Proactive Exposure Management: The industry's historical reliance on "firefighting"—detecting breaches and responding at human speed—is obsolete in the AI era, where everything moves at machine speed. Vintz highlights that over 90% of cybersecurity spending is on detection and response, while a disproportionately smaller amount is on prevention. Defenders must shift from "firefighting" to "fireproofing" through exposure management.
- Unified Visibility, Insight, and Action: Exposure management provides a holistic view to understand and proactively reduce risk. It recognizes that risk rarely appears in isolation; an "overprivileged identity here, a misconfigured workload there, or a crucial vulnerability in a model somewhere else individually may look harmless," but chained together, they can create a "lethal attack path."
- Intelligence Layer for Human-AI Orchestration: This approach provides the necessary intelligence to orchestrate the right mix of human and AI efforts, offering context, direction, and validation to actively reduce risk. It ensures that security decisions are based on "deterministic facts" rather than the "probabilistic recommendations" often made by AI. Clarity about risk location drives confidence and, ultimately, accountability.
- Embed Risk Management at Every Organizational Layer: Given the widespread adoption of AI, risk assessment cannot be confined to silos.
- Cross-Functional Risk Evaluation: Developers, data scientists, and business leaders must all evaluate AI risk through the same lens. This starts with identifying risks prior to deployment and understanding the potential "blast radius" if a model "goes sideways."
- Establish AI Governance Committees: Cross-functional leadership should form an AI governance committee to continuously monitor risks in accordance with the company's risk profile and regulatory frameworks. While responsibility is distributed across teams, Vintz stresses that accountability is not; the company is ultimately responsible for the machine's actions, a principle supported by legal precedent.
- Board-Level Oversight: For boards, AI risk must become a "standing conversation." Boards will increasingly expect visibility into AI deployment, introduced risks, and their management, as "visibility is accountability" in the AI era.
Vintz warns that if the private sector and AI model companies fail to manage this profound risk effectively, governments may nationalize AI or heavily regulate it, treating it like other critical technologies such as aerospace and cryptography. The call to action is clear: choose "visibility over blindness" and "fireproofing over firefighting" to transform AI from a source of chaos into a capability that can be trusted, an "accelerator of resilience" rather than an "accelerator of exposure."
Key Takeaways
- The "Responsibility Gap" is a Critical Threat: The fractured ownership and rapid, decentralized deployment of AI systems within organizations create a dangerous vacuum of accountability for AI-related risks, leaving CEOs and Boards ultimately liable.
- AI's Unique Characteristics Demand New Security Approaches: The unprecedented velocity, ubiquity (via "citizen developers" and no-code platforms), and autonomy (e.g., multi-Agent networks) of AI necessitate a fundamental shift from reactive "firefighting" to proactive "fireproofing" in cybersecurity.
- Proactive Exposure Management is Essential: Organizations must adopt exposure management—unified visibility, insight, and action—to identify and mitigate complex, chained vulnerabilities across AI models, data, and infrastructure before incidents occur, operating on "deterministic facts."
- Adapt Existing Frameworks for AI Security: Rather than reinventing the wheel, regulators and enterprises should adapt established security frameworks like the NIST Cybersecurity Framework, ISO cybersecurity standards, and the OWASP GenAI Security Project to address AI-specific risks such as prompt injection and algorithmic bias.
- Embed AI Risk Management Across the Organization: AI risk assessment cannot be siloed. Developers, data scientists, business leaders, and boards must all collaboratively evaluate and continuously monitor AI risks, with governance committees ensuring alignment with company risk profiles and regulatory frameworks.
- Accountability Drives Trust in the AI Era: Ultimately, closing the responsibility gap hinges on establishing clear accountability. By embracing visibility and proactive risk management, organizations can build trust in AI, transforming it from a source of volatility into an accelerator of resilience.
About the Speaker(s)
Stephen Vintz is the Co-Chief Executive Officer of Tenable, a leading company in the field of exposure management. In his role, Vintz oversees a company with access to vast amounts of exposure data, providing him with unique insights into the evolving landscape of cyber risk. His expertise lies in understanding the complex interplay between technological advancements, organizational structures, and the challenges of maintaining robust security postures. Vintz leverages this perspective to advocate for a proactive, accountability-driven approach to cybersecurity, particularly in the rapidly expanding domain of Artificial Intelligence.
Reviews
Dr. Zero (Offensive Security Researcher) — HARD PASS
A Tenable CEO delivering a vendor keynote at RSA dressed up as a thought leadership talk. 'The Responsibility Gap' is 45 minutes of executive-speak, anecdote-driven fearmongering, and thinly veiled product positioning that culminates in pitching exposure management — which Tenable sells. No original research. No novel technical contribution. No demos. No data. This is a sales deck with a podium.
Heather Calloway (CISO) — WEAK
Vintz identifies a real and underappreciated governance problem — the fractured accountability that emerges when AI deployment is distributed across data science, ML Ops, IT, product, and legal, while security inherits the liability without the authority. The anecdotes are grounded and the framing of the 'responsibility gap' is legitimate. But the talk ultimately fails its own thesis. It names the accountability problem and then hands the audience a vendor product as the answer. The defensive prescriptions — exposure management, AI governance committees, adapt NIST, see the board — are either recycled doctrine or insufficiently specified to be actionable. For a talk that correctly…