Business

AI adoption is outpacing governance, and cybersecurity is paying the price

As organizations embed AI into core workflows, outdated oversight frameworks and unclear accountability are creating dangerous security gaps that attackers are already exploiting.

EditorialΒ·28 Aug 2026
AI adoption is outpacing governance, and cybersecurity is paying the price

The gap between how quickly organizations adopt artificial intelligence and how slowly they govern it has become one of the most dangerous fault lines in modern cybersecurity. According to the World Economic Forum’s Global Cybersecurity Outlook 2026, 94% of cyber leaders now identify AI as a key driver of change in cybersecurity over the coming year, while 87% point to AI-related vulnerabilities as the fastest-growing cyber risk in 2025. The message from the data is unambiguous: the technology that promises to transform defense is also arming attackers, and the rules meant to keep it in check are lagging badly behind.

This matters because the financial stakes have moved from theoretical to staggering. Cyber-enabled fraud, supercharged by generative AI and large language models, is projected to cost $10.5 trillion globally in 2025, rising to $12.2 trillion by 2031. Those are not abstract losses; they represent drained corporate accounts, compromised customer data, disrupted supply chains, and eroded trust. For executives, founders, and security specialists alike, the question is no longer whether AI will be part of the threat landscape, but whether their governance structures can evolve quickly enough to contain it.

From experimentation to exposure

The core problem is one of speed and mismatch. Most organizations have moved from piloting AI tools to embedding them in core workflows β€” customer service, fraud detection, code generation, financial analysis β€” without a corresponding upgrade in oversight. The result is what security professionals call β€œshadow AI”: unsanctioned tools adopted by employees who find them useful but bypass formal procurement and risk review. These tools often lack the logging, access controls, and data protection measures that would be mandatory for any officially sanctioned system. The shift from AI experimentation to strategic integration has outpaced governance, leaving organizations exposed in ways they do not fully see.

Dani Michaux of KPMG has highlighted the governance gap as a central concern. The issue is not that organizations are ignoring AI risk entirely; it is that their existing cyber controls were designed for human users operating within defined permissions. Autonomous AI agents, which can act on behalf of users, access multiple systems, and make decisions at machine speed, do not fit neatly into those frameworks. A human employee might be caught by a rule that flags unusual login times or data volumes. An AI agent, operating continuously and legitimately across systems, can exfiltrate or manipulate data in ways that look normal to traditional monitoring tools. This mismatch between control design and AI behavior creates a risk exposure that many security teams are only beginning to understand.

PwC Ireland’s 2026 Responsible AI survey puts numbers on the struggle. It found that 77% of respondents cite difficulty scaling responsible AI principles across their organizations. More troubling, 37% lack clarity on who actually owns AI governance β€” a vacuum that invites inconsistency and finger-pointing. Another 30% say they simply do not have adequate tools to monitor or enforce AI policies. These figures, drawn from a survey of Irish respondents but reflecting a pattern seen across many markets, suggest that even well-intentioned governance efforts are stalling at the implementation stage. The result is a dangerous middle ground: organizations know they need better controls, but cannot yet operationalize them.

The boardroom blind spot

One of the sharpest criticisms emerging from security leaders is that AI security is still too often treated as an IT problem rather than a board-level governance priority. Len McAuliffe and David Lee of PwC Ireland argue that this framing is a critical flaw. When AI risk is delegated to technical teams, it tends to be addressed with technical fixes: better firewalls, stricter access lists, more monitoring. Those are necessary but insufficient. The deeper risks β€” biased decision-making, regulatory non-compliance, reputational damage from a rogue AI agent, liability for automated actions β€” require legal, ethical, and strategic oversight that only senior leadership can provide. Without board-level engagement, AI governance remains reactive and fragmented.

Fabiano Saccone and Ciara Weldon of Hiscox Ireland point to a related issue: the uncertainty around implementation. There is broad consensus that innovation and risk management must coexist. Few executives would argue that AI adoption should be halted entirely. But translating that consensus into concrete governance structures β€” clear ownership, defined escalation paths, regular board reporting, measurable risk metrics β€” remains elusive. Without those structures, organizations are left with a patchwork of policies that look good on paper but fail under pressure. The gap between stated commitment and practical execution is where many AI-related incidents begin.

The stakes are especially acute for small and medium-sized enterprises. SMEs often lack the dedicated security teams, legal counsel, and budget that larger firms can deploy. They are also increasingly dependent on AI-powered tools for efficiency, from automated invoicing to customer chatbots. That combination β€” high dependence, low governance capacity β€” makes them attractive targets for attackers who can exploit weak oversight to launch fraud or ransomware campaigns. David McNamara of Commsec has noted that the asymmetry between attacker sophistication and defender resources is widening, and it is widening fastest at the smaller end of the market. For these businesses, a single AI-driven fraud incident can be existential.

What robust governance actually requires

The path forward is not mysterious, but it is demanding. Security leaders and governance experts consistently return to a few core principles. First, accountability must be assigned at the highest level. Someone on the executive team β€” ideally with a direct line to the board β€” must own AI risk. That person needs authority to halt deployments, demand audits, and require remediation. Without that authority, governance is advisory rather than enforceable. The PwC finding that 37% of organizations lack clarity on ownership is not a minor administrative gap; it is a structural weakness that attackers can and do exploit.

Second, organizations need to adopt zero-trust principles for AI systems, not just for human users. Every AI agent, model, and data pipeline should be treated as potentially compromised until proven otherwise. Access should be scoped to the minimum necessary, continuously verified, and logged in ways that allow forensic analysis after an incident. This is a significant departure from how many AI systems are deployed today, where models are given broad access to internal data and tools in the name of efficiency. Zero-trust for AI means assuming that any component could be manipulated, and designing controls accordingly.

Third, governance must be scalable. A policy that works for a team of fifty will not survive a workforce of five thousand, especially when employees are actively seeking out new AI tools. This means investing in automated policy enforcement, real-time monitoring of AI behavior, and clear, accessible training that helps employees understand what is and is not acceptable. PwC’s finding that 30% of organizations lack adequate tools is a warning sign: governance that depends on manual review will simply not keep pace with the volume of AI activity in a modern enterprise. Scalable governance requires tooling that can detect shadow AI, flag anomalous agent behavior, and enforce policies without constant human intervention.

A strategic imperative, not a compliance exercise

The organizations that get this right will not treat AI governance as a box-ticking exercise. They will see it as a competitive advantage. Customers, partners, and regulators are increasingly asking hard questions about how AI systems are managed, what data they touch, and who is accountable when things go wrong. Companies that can answer those questions credibly will win trust. Those that cannot will face not only financial losses from cyber incidents but also slower sales cycles, higher insurance premiums, and regulatory scrutiny. In a global digital economy, trust is a currency, and AI governance is becoming one of its primary sources.

The World Economic Forum’s data makes clear that the threat is not hypothetical. Nearly nine in ten cyber leaders see AI-related vulnerabilities as the fastest-growing risk. Fraud costs are climbing into the trillions. Shadow AI is spreading faster than most organizations can track. The tools to address these challenges exist, but they require a shift in mindset: from AI security as a technical afterthought to AI governance as a core business function. For executives, founders, and specialists navigating a global digital economy, that shift is no longer optional. It is the price of resilience.

#AI governance #cybersecurity #risk management #corporate leadership

Newsletter

Get the AI news that matters

One short brief with the day's most important AI stories β€” written for professionals.

We send a confirmation link. No spam. Unsubscribe anytime.

WhatsApp