AI is already reshaping the risk landscape, so the real question for leaders is not whether they are using AI, but whether they can demonstrate they are using it safely, responsibly and with effective oversight.
A recent striking headline reported that AI belonging to a major technology company had hacked into another company’s systems during testing.
There’s no doubt it will have grabbed the attention of senior executives globally. The temptation is to picture an AI system escaping its laboratory and acting independently, with unintended and unwelcome consequences.
It’s dramatic. But for most organisations, it’s not the AI risk most likely to land on their desk.
The reality is far less sensational. But far more likely.
AI is creating new categories of cyber threat but it’s also acting as a force multiplier for risks that organisations already have, while creating operational and legal exposures that may have nothing to do with hackers at all. The easiest way to think about the problem is: how is AI being used against you, by you and around you?
AI used against you: amplified conventional attacks
Social-engineering attacks were commonplace long before generative AI arrived. Historically, poor grammar, unusual phrasing or factual inconsistencies could help expose a malicious email. Those inconsistencies are becoming less common.
Generative AI allows threat actors to produce convincing, personalised communications at speed and scale, drawing on information obtained from social media, public sources or breached data. Deepfakes and voice cloning further weaken controls that have traditionally relied upon people being able to verify whether an instruction genuinely came from a trusted source.
This is not a hypothetical future threat. The UK’s National Cyber Security Centre has assessed that AI is already making existing cyber intrusion techniques more efficient and effective, with particularly significant implications for reconnaissance and social engineering.
AI used by you: legal and professional exposure
The risks are not limited to malicious actors. Courts have already had to address lawyers relying upon false or inaccurate legal authorities apparently produced with the assistance of generative AI. The obvious lesson is that using AI without proper verification can create serious professional consequences.
However, the position is becoming more nuanced. In July, the UK Jurisdiction Taskforce published its non-binding Legal Statement on Liability for AI Harms. Among its conclusions was the proposition that a professional could potentially be negligent not only for using AI inappropriately, but for failing to use it at all where the exercise of reasonable skill and care required it. That creates an important governance problem. Organisations cannot safely reduce AI policy to either “use it” or “do not use it”. The real question is where its use is appropriate, what assurance is required and who remains accountable for the result.
The same principle applies beyond generative AI. In January 2024, France’s data-protection regulator publicised a €32 million fine imposed over employee-monitoring systems that it regarded as excessively intrusive. The case is a useful reminder that technology deployed to improve productivity can itself create significant regulatory exposure if governance does not keep pace with deployment.
AI around you: integrity and people risk
Universities are already confronting the difficulty of distinguishing legitimate student work from improperly AI-generated material. AI-detection tools themselves can produce false positives and false negatives, creating risks in both directions: failing to identify misconduct and wrongly accusing someone of it.
Recruitment presents a parallel problem. AI-assisted hiring tools can reproduce or introduce bias into candidate assessment, creating the potential for discrimination claims as well as wider reputational harm. The important point is that many businesses are racing to embrace the efficiencies AI offers before traditional governance processes have caught up.
None of these risks require a rogue AI system. They arise from ordinary technology being used by organisations, employees, suppliers, candidates and threat actors in entirely predictable ways. That is where risk managers should be focusing their attention. The question is not simply whether an organisation could withstand a hypothetical AI-driven breach. It is whether its human, technical and legal control environment has kept pace with the way AI is already being used by it, against it and around it.
Cyber resilience in this context means stress-testing the ordinary pathways through which AI is already changing risk: email, recruitment, employee monitoring, professional advice, decision-making and the handling of information. It means asking where AI has changed the speed, scale or credibility of an existing threat; where it has been introduced into a business process without adequate oversight; and where people are relying upon automated outputs without understanding how those outputs were produced.
The headline-grabbing AI-versus-AI story will continue to make news.
Fortunately, the risk more likely to arrive on an executive’s desk is far more mundane and much more manageable. The response is not panic about frontier AI. It is strong governance, assurance and oversight: clear rules for appropriate use, human accountability for material decisions and outputs, proportionate due diligence around systems that touch people or data, and regular testing of whether existing controls still work in an AI-enabled environment.
These are not exotic controls. They are the disciplines of good risk management applied consistently to a technology that is changing the environment around them.
AI is already reshaping the risk landscape, so the real question for leaders is not whether they are using AI, but whether they can demonstrate they are using it safely, responsibly and with effective oversight.
For guidance on building the governance and control environments needed to manage cyber and AI risk, contact Craig Kennedy, Partner and Head of Cyber Consultancy.
Related Insights
Airmic 2026 – Back to Basics: An Insurer Perspective
Airmic 2026 returned to Birmingham’s ICC with a timely theme: Back to Basics. For insurers operating against a backdrop of geopolitical volatility,...
Ten Things Every Board Needs to Know About Cyber Risk
Recent developments in artificial intelligence have underlined how quickly the cyber risk landscape is evolving. The recent controlled release of...
Wiping the Slate Clean… As An Act of Cyber Warfare
A recent cyberattack on US medical technology company Stryker with bases in Ireland, highlights a dangerous trend in modern cyber...
How the Escalating Iran Crisis Is Impacting Marine, Aviation and Cyber Risk for Clients
The Middle East has entered a period of severe instability, with the Strait of Hormuz experiencing a rapid escalation in...




