The Member Signal is DoGood’s weekly peer-intelligence briefing for the member network. This issue went to members on July 15, 2026, and appears here lightly edited for the web.
The Signal
The network’s AI question changed shape this month. Through the spring, members mostly asked how to see and police employees using AI on their own: shadow ChatGPT, unsanctioned tools, browser tabs nobody approved. In the last 30 days the dominant ask is different. Members want to govern the AI agents they are now building and buying themselves.
A manufacturing VP of IT is standing up agents for new projects with a small team and wants guidance before they ship. A healthcare IT director is weighing agents her team builds against agents purchased from third-party vendors, and wants one way to monitor both. A software security lead is trying to police which agents run across the business units at all. Different industries, same shift: the risk moved from the tool an employee opens to the agent the company deploys.
Nearly one in five priorities members raised this month touched AI security or governance, and the through-line is agents, not apps. No single vendor owns this yet. Members are researching the category cold, which is why the asks read as urgent rather than comparative.
From the Network
“Joint venture company with a small staff who needs guidance for AI agents for new projects.”
VP of Information Technology, Manufacturing
“I would like to talk about how your solution manages internally developed agents and those agents purchased from 3rd party vendors.”
Director of Information Technology, Healthcare
“Looking for tools to better understand and police what AI agents are being leveraged across the business units.”
Head of Cybersecurity Strategy & Operations, Software
Three stages of the same problem, in order: building agents, buying them, and finding the ones already running.
Top Open Priorities
“Trying to understand ways to address AI citizen developers/vibe coders with realistic and approachable SDLC options.”
Enterprise Security Program Manager, Finance
“It is out of control. I have just started researching AI governance vendors! Everyone using anything they want. We have written policies but unable to really implement! very little visibility! We have to implement something soon!”
Principal & Chief Information Officer, Business Services
One team is trying to secure the code its own developers generate with AI; the other has lost sight of what AI is running at all. Both asks are two weeks old, and both are the same governance gap at different stages.
Member Spotlight
Deb Cafarella, IT Security & Infrastructure, Shields Health. This week’s Signal is about governance that keeps pace instead of saying no, and nobody makes that case better than Deb. She leads IT Security & Infrastructure at Shields Health, and she put the cost of the alternative plainly in her DoGood Member Spotlight: “If you’re a department of no and you’re not collaborative, people go around you.”
Deep Dive: Offensive Security & Exposure Management
Seventeen member priorities in the last 90 days touched penetration testing, exposure validation, or vulnerability management, and the dominant pattern is a shift away from the once-a-year compliance test toward continuous testing, driven by something nobody had to worry about two years ago: securing the code AI now writes.
Where activity is concentrated
The volume splits three ways. The largest cluster is members trading point-in-time pentests for continuous testing and bug bounty programs, several of them re-shopping because they rotate testing vendors on a fixed cycle. A second, fast-growing cluster is squarely about AI-generated code: a construction cybersecurity director wants to remediate vulnerabilities introduced by AI coding assistants, a business services CISO with roughly 1,300 engineers using those assistants wants to auto-remediate at scale, and a hospitality team wants “to get to the vuln before they get into code.” The third cluster is straightforward compliance: annual regulatory tests for financial institutions, SoC 2 patching cadence, merger-driven assessments.
What your peers are buying
Two vendors are actually getting meetings booked across the network. HackerOne is drawing finance CISOs and software product leaders for bug bounty and AI red-teaming. Sprocket Security is booking continuous-penetration-testing meetings with finance CISOs and law-firm security managers, including one who rotates pentest vendors yearly and added Sprocket for exactly that reason.
What’s still open
Two capability areas have clear demand and no vendor members are naming. First, automatic remediation of AI-generated-code vulnerabilities at engineering-team scale: members describe the problem in detail but name no tool they trust to fix it. Second, prioritization. One mining-sector security director wants a platform that can “distill vulnerabilities to a shorter list of issues that truly warrant attention.” The scanning is solved; the triage is not.
What it means for your stack
Before your next annual pentest auto-renews, ask whether a once-a-year test still matches how fast your engineers ship. Pull the number of repositories where AI coding assistants are enabled, and compare it to the scope of your last test. If code changes weekly and testing happens yearly, the gap between those two numbers is where your next finding is hiding.
The Context
The headlines are catching up to what the network already knew.
In the last few weeks the security industry has declared non-human identity governance the defining gap of the agentic era: the Cloud Security Alliance published a framework for governing AI-agent and non-human identities, Gartner named agentic AI governance a top cybersecurity trend for 2026, and researchers keep returning to the same number. In cloud-native environments, non-human identities now outnumber humans by roughly 144 to 1, up from 92 to 1 a year and a half ago. The agents your peers are asking how to govern are already the majority of the identities in their environment.
Bottom Line: The vendors are racing to give agents identities, audit logs, and guardrails. The harder problem your peers keep naming comes one step earlier: knowing which agents exist at all, especially the ones a business unit built or bought without telling you.
What to Do About It
Before you evaluate a single agent-governance platform, run the inventory those platforms assume you already have. Pull every AI agent running in your environment right now and sort it into three buckets: agents your team built, agents another business unit built, and agents bought from a vendor. The third bucket is where your policy has no reach and the fastest-growing one, so start there this week.