AI adoption is outpacing governance, and cybersecurity is paying the price
As organizations embed AI into core workflows, outdated oversight frameworks and unclear accountability are creating dangerous security gaps that attackers are already exploiting.
The gap between how quickly organizations adopt artificial intelligence and how slowly they govern it has become one of the most dangerous fault lines in modern cybersecurity. According to the World Economic Forumβs Global Cybersecurity Outlook 2026, 94% of cyber leaders now identify AI as a key driver of change in cybersecurity over the coming year, while 87% point to AI-related vulnerabilities as the fastest-growing cyber risk in 2025. The message from the data is unambiguous: the technology that promises to transform defense is also arming attackers, and the rules meant to keep it in check are lagging badly behind.
This matters because the financial stakes have moved from theoretical to staggering. Cyber-enabled fraud, supercharged by generative AI and large language models, is projected to cost $10.5 trillion globally in 2025, rising to $12.2 trillion by 2031. Those are not abstract losses; they represent drained corporate accounts, compromised customer data, disrupted supply chains, and eroded trust. For executives, founders, and security specialists alike, the question is no longer whether AI will be part of the threat landscape, but whether their governance structures can evolve quickly enough to contain it.
From experimentation to exposure
The core problem is one of speed and mismatch. Most organizations have moved from piloting AI tools to embedding them in core workflows β customer service, fraud detection, code generation, financial analysis β without a corresponding upgrade in oversight. The result is what security professionals call βshadow AIβ: unsanctioned tools adopted by employees who find them useful but bypass formal procurement and risk review. These tools often lack the logging, access controls, and data protection measures that would be mandatory for any officially sanctioned system. The shift from AI experimentation to strategic integration has outpaced governance, leaving organizations exposed in ways they do not fully see.
Dani Michaux of KPMG has highlighted the governance gap as a central concern. The issue is not that organizations are ignoring AI risk entirely; it is that their existing cyber controls were designed for human users operating within defined permissions. Autonomous AI agents, which can act on behalf of users, access multiple systems, and make decisions at machine speed, do not fit neatly into those frameworks. A human employee might be caught by a rule that flags unusual login times or data volumes. An AI agent, operating continuously and legitimately across systems, can exfiltrate or manipulate data in ways that look normal to traditional monitoring tools. This mismatch between control design and AI behavior creates a risk exposure that many security teams are only beginning to understand.
PwC Irelandβs 2026 Responsible AI survey puts numbers on the struggle. It found that 77% of respondents cite difficulty scaling responsible AI principles across their organizations. More troubling, 37% lack clarity on who actually owns AI governance β a vacuum that invites inconsistency and finger-pointing. Another 30% say they simply do not have adequate tools to monitor or enforce AI policies. These figures, drawn from a survey of Irish respondents but reflecting a pattern seen across many markets, suggest that even well-intentioned governance efforts are stalling at the implementation stage. The result is a dangerous middle ground: organizations know they need better controls, but cannot yet operationalize them.
The boardroom blind spot
One of the sharpest criticisms emerging from security leaders is that AI security is still too often treated as an IT problem rather than a board-level governance priority. Len McAuliffe and David Lee of PwC Ireland argue that this framing is a critical flaw. When AI risk is delegated to technical teams, it tends to be addressed with technical fixes: better firewalls, stricter access lists, more monitoring. Those are necessary but insufficient. The deeper risks β biased decision-making, regulatory non-compliance, reputational damage from a rogue AI agent, liability for automated actions β require legal, ethical, and strategic oversight that only senior leadership can provide. Without board-level engagement, AI governance remains reactive and fragmented.
Fabiano Saccone and Ciara Weldon of Hiscox Ireland point to a related issue: the uncertainty around implementation. There is broad consensus that innovation and risk management must coexist. Few executives would argue that AI adoption should be halted entirely. But translating that consensus into concrete governance structures β clear ownership, defined escalation paths, regular board reporting, measurable risk metrics β remains elusive. Without those structures, organizations are left with a patchwork of policies that look good on paper but fail under pressure. The gap between stated commitment and practical execution is where many AI-related incidents begin.
The stakes are especially acute for small and medium-sized enterprises. SMEs often lack the dedicated security teams, legal counsel, and budget that larger firms can deploy. They are also increasingly dependent on AI-powered tools for efficiency, from automated invoicing to customer chatbots. That combination β high dependence, low governance capacity β makes them attractive targets for attackers who can exploit weak oversight to launch fraud or ransomware campaigns. David McNamara of Commsec has noted that the asymmetry between attacker sophistication and defender resources is widening, and it is widening fastest at the smaller end of the market. For these businesses, a single AI-driven fraud incident can be existential.
What robust governance actually requires
The path forward is not mysterious, but it is demanding. Security leaders and governance experts consistently return to a few core principles. First, accountability must be assigned at the highest level. Someone on the executive team β ideally with a direct line to the board β must own AI risk. That person needs authority to halt deployments, demand audits, and require remediation. Without that authority, governance is advisory rather than enforceable. The PwC finding that 37% of organizations lack clarity on ownership is not a minor administrative gap; it is a structural weakness that attackers can and do exploit.
Second, organizations need to adopt zero-trust principles for AI systems, not just for human users. Every AI agent, model, and data pipeline should be treated as potentially compromised until proven otherwise. Access should be scoped to the minimum necessary, continuously verified, and logged in ways that allow forensic analysis after an incident. This is a significant departure from how many AI systems are deployed today, where models are given broad access to internal data and tools in the name of efficiency. Zero-trust for AI means assuming that any component could be manipulated, and designing controls accordingly.
Third, governance must be scalable. A policy that works for a team of fifty will not survive a workforce of five thousand, especially when employees are actively seeking out new AI tools. This means investing in automated policy enforcement, real-time monitoring of AI behavior, and clear, accessible training that helps employees understand what is and is not acceptable. PwCβs finding that 30% of organizations lack adequate tools is a warning sign: governance that depends on manual review will simply not keep pace with the volume of AI activity in a modern enterprise. Scalable governance requires tooling that can detect shadow AI, flag anomalous agent behavior, and enforce policies without constant human intervention.
A strategic imperative, not a compliance exercise
The organizations that get this right will not treat AI governance as a box-ticking exercise. They will see it as a competitive advantage. Customers, partners, and regulators are increasingly asking hard questions about how AI systems are managed, what data they touch, and who is accountable when things go wrong. Companies that can answer those questions credibly will win trust. Those that cannot will face not only financial losses from cyber incidents but also slower sales cycles, higher insurance premiums, and regulatory scrutiny. In a global digital economy, trust is a currency, and AI governance is becoming one of its primary sources.
The World Economic Forumβs data makes clear that the threat is not hypothetical. Nearly nine in ten cyber leaders see AI-related vulnerabilities as the fastest-growing risk. Fraud costs are climbing into the trillions. Shadow AI is spreading faster than most organizations can track. The tools to address these challenges exist, but they require a shift in mindset: from AI security as a technical afterthought to AI governance as a core business function. For executives, founders, and specialists navigating a global digital economy, that shift is no longer optional. It is the price of resilience.
Sources
- AIβs next cybersecurity challenge: robust governance key to success
- Ideas and Forecasts on Stocks β Netherlands β TradingView
Written by an AI editorial process from the sources above. Errors may occur.
Newsletter
Get the AI news that matters
One short brief with the day's most important AI stories β written for professionals.
We send a confirmation link. No spam. Unsubscribe anytime.
Read next
The AI Cloud Race: Big Tech's $130B Power Play
Amazon, Microsoft, and Alphabet are spending billions to dominate AI through cloud infrastructure, reshaping global tech, security, and market dynamics.
19 Sep 2026
AI Inference Market to Hit $255B by 2030
Global demand for real-time AI decision-making drives explosive growth in inference infrastructure, with NVIDIA, Intel, and Siemens Healthineers leading diverse applications.
18 Sep 2026
Autonomous AI Agents Become Core Enterprise Infrastructure in 2026
The market for autonomous AI agents is projected to surge from $7.92 billion in 2025 to $236.03 billion by 2034, as enterprises shift from experimentation to governing systems that perform operational work.
14 Sep 2026