CISOs, CIOs and CPOs are the de facto authority on AI safety. They must not wait for pauses or regulations, since sovereignty sets the pace of the AI race.
As of 15 September 2026, several prominent tech leaders indicated concerns about AI safety, suggesting a need for a “pause” and for more regulation. For example, Anthropic’s CEO, Dario Amodei, called on the U.S. government to regulate AI companies to slow the pace of the technology’s development in a blog post, with this statement receiving a rare endorsement from competing AI executives, such as Sam Altman (OpenAI) and Elon Musk (xAI). Meanwhile, the U.S. executive branch rejected calls to regulate the industry, setting up further debate on the subject.
Note: This is the Gartner First Take on the growing calls for AI safety and regulation.
However, nations and these companies are still in competition to win the AI race, which hinders motivation for a real slowdown. In fact, most of the prominent frontier AI companies have previously made a commitment in their self-disclosed safety frameworks to pause development should it become too dangerous. If, as their public communications indicate, they believe we are at that stage, they should take action to honor and invoke those pause commitments immediately. None have. As a result, the three most influential cybersecurity leaders — CISOs, CIOs and CPOs — are the de facto authorities on AI safety.
Fierce competition drives a relentless global race for AI developments, but sovereignty sets its pace. The world’s superpowers are competing for technological dominance, making global participation in a broad slowdown unlikely, despite safety concerns. On top of that, export controls, regulations and other government interventions are becoming permanent features of the AI landscape. CISOs, CIOs and CPOs must factor sovereignty and its impact on the vendor landscape into their AI safety and cybersecurity strategies.
Key recommendations:
Lead AI cybersecurity governance with digital sovereignty top of mind. AI safety discourse and regulation will impact digital sovereignty. We have already seen export control restrictions around cyber-capable models emerge. Unfortunately, for many organizations, there are no good sovereign AI options at this time. Cybersecurity leaders must instead anticipate these limitations and engage in scenario planning to mitigate continuity risks from model regulation.
Factor vendor lock-in risks into AI safety. Models and harnesses can improve safety, observability and control but also create vendor lock-in. Deliberately design for portability by separating the harness from the model, and externalize configuration rather than hard coding. Treat the harness as a critical layer. Identify points of lock-in, analyze the exit costs and ensure a degree of portability so that it doesn’t become the next layer of lock-in.
AI is not a monolith. The full AI ecosystem must be understood to manage AI safety. Complete AI safety evaluations must include data, models, harnesses, APIs, multiagent systems and agentic swarms, and the AI supply chain. Cybersecurity leaders must proactively assess AI safety risks before harm occurs.
Key recommendations:
Anticipate and respond to dark AI threats today. Many critical AI safety risks will arise from dark AI. Address your dark AI risks to address AI safety.
Extend your AI safety focus beyond model regulation. Regulation always lags behind technical developments and innovation. Get ahead of regulations to promote AI safety by focusing on how all aspects of your AI ecosystems may cause harm.
Include logical, psychological and physical safety. Until now, most of the focus was on logical and psychological safety, but the rapid emergence of physical AI makes focusing on physical safety a necessity.
AI safety debates distract from immediate AI cybersecurity risks. CISOs, CIOs and CPOs are not in a position to solve global AI safety concerns. These C-suite leaders must ignore the hype and focus on internal governance and tactical implementation. Securing AI infrastructure and understanding the interaction between models and harnesses is more important than safety of the model itself.
Key recommendations:
Align your AI governance practices to an AI cyber risk framework. Start with a foundation for AI security and safety through your selection of an AI cyber risk framework.
Evolve AI security beyond the basics. Build out your roadmap to secure and enable the use of AI. This includes discovery and inventory capabilities, runtime defenses, and monitoring and logging capabilities.
Strengthen your cyber defenses now. Bad actors already use relatively recent models to conduct advanced attacks. Newer frontier models increase the threat. Enterprises should counter this by leveraging cyber-capable models that have predictable capabilities and guardrails, and invest in tools to secure the use of AI.
Attend a Conference
Experience Information Technology conferences
With exclusive insights from Gartner analysts on the latest trends, sessions curated for your role and unmatched peer networking, Gartner conferences help you accelerate your priorities.
Gartner IT Symposium/Xpo™
Orlando, FL
Drive stronger performance on your mission-critical priorities.