AI cyber risk

AI Cyber Risk Is Now a Board-Level Problem

The email looked like it came from the CFO in London. It mentioned a confidential transaction, and the finance employee in Arup’s Hong Kong office didn’t buy it. He thought it was phishing.

So they put him on a video call.

The CFO was there. So were a few colleagues he knew by sight. Everyone looked right and sounded right, and over the next week, in January 2024, he sent 15 transfers worth HK$200 million (about US$25.6 million) to five bank accounts. Every person on that call had been generated by AI.

What sticks with me is Arup’s later statement that none of its internal systems were compromised. That’s true, and it’s the scary part. Nobody hacked anything. The attackers just walked through a payment process that trusted a face on a screen.

This is why cyber risk keeps landing on board agendas, and why AI is speeding that up. Directors don’t have to become engineers. They do have to know whether risk is being managed or merely written down. Plenty of companies handle the plumbing with a governance risk and compliance solution, which maps policies, controls and evidence to the people responsible for them. Useful, but it only goes so far.

What Does Board-Level Cyber Governance Actually Mean?

A dashboard can tell you who owns a control. It can’t make that person do the work.

Here’s a line you’ll find in nearly every security policy ever written: access should be reviewed periodically. Fine. By whom, though? Covering which systems? Once a quarter, or whenever someone remembers? And when the review turns up a contractor who left in 2023 and still has admin rights, who actually switches that off?

If nobody can answer, the control is decoration.

AI policies have the same problem, only newer. “Staff may use approved AI tools” appears in a lot of employee handbooks now. Ask who keeps that approved list current, or how the company would even notice someone pasting client data into a chatbot it never signed off on. Answers get vague fast.

How Is AI Changing the Cyber Risk Boards Oversee?

Deepfakes Go After Processes

Go back to Arup. No malware, no stolen password. The weak point was an approval rule. Fixing it is boring, which is probably why it gets skipped: big or unusual transfers get a callback to a number already on file, however convincing the request seemed.

Someone senior has to own that rule. Otherwise it drifts.

Shadow AI Is Already in the Breach Data

IBM’s 2025 Cost of a Data Breach study is the best early evidence. About 13% of the organizations it looked at had suffered breaches involving their own AI models or apps. In 97% of those cases, basic AI access controls simply weren’t there.

Then there’s shadow AI, the tools staff use without approval. One in five organizations blamed a breach on it. When shadow AI use was widespread, breach costs ran roughly US$670,000 higher.

A policy alone didn’t fix it either. Around 63% of breached companies had no AI governance policy or were still drafting one, and among those that had one, only about a third checked regularly for unapproved tools. Writing the rule is the easy bit.

AI Systems Are Now Assets Worth Protecting

A copilot that can’t see your files isn’t much of a copilot. That broad access is the point, and it’s also the risk. It opens the door to leaks, prompt injection, and the ordinary misuse that happens when a tool can reach everything. Attackers have the same models defenders do, so a good chunk of security work now looks like AI-versus-AI contests playing out faster than any human can follow. AI systems belong on the risk register. Not in a footnote.

How Should Boards Read Cyber Metrics?

“We blocked 2.3 million attacks this quarter.” Directors hear some version of that all the time. It tells them almost nothing.

Context does the work. The same vulnerability is a crisis on the system that takes customer payments and a minor chore on the cafeteria booking app. Tie the numbers to the systems the business can’t live without, and the board meeting gets a lot more useful.

What management reportsWhat the board should ask
Attacks blocked, alert volumeWhich of these touched systems that make money or hold sensitive data?
Open critical vulnerabilitiesHow many sit on customer-facing or regulated systems, and how long have they been open?
Training completion rateHas anyone’s behavior actually changed in phishing tests or real incidents?
Backup coverageWhen did we last restore something critical, and how long did it take?
AI tools in useWhich are approved, what can they reach, and how do we find the ones that aren’t?
Vendor assessments completedHave the suppliers we can’t do without, AI providers included, been reviewed this year?

What Do Regulators Now Expect From Boards?

A lot more than they used to. Cyber oversight has drifted out of the IT budget and into corporate governance proper, and the rules reflect that.

Since December 2023, SEC rules have required US-listed companies to report material cyber incidents on Form 8-K, usually within four business days of deciding an incident matters. Annual reports now have to describe how the board oversees cyber risk, too.

Europe made it personal. Under NIS2, management bodies approve and oversee security measures, have to take training, and can be held liable. DORA, live since 17 January 2025, puts final responsibility for ICT risk in financial firms on the management body. NIST joined in with CSF 2.0 in February 2024 by adding a sixth function, Govern. The message across all of these is that leadership owns cyber risk.

AI rules are arriving more slowly. The EU AI Act’s bans on prohibited practices and its AI literacy requirements kicked in during February 2025, and the rules for general-purpose models followed that August. Then the 2026 Digital Omnibus bought companies time: stand-alone high-risk systems now face the toughest obligations from 2 December 2027, and AI built into regulated products from 2 August 2028.

A word of caution, though. Passing an audit and being safe are different things. Regulations describe a minimum, and the thing that hurts you is often a vendor, a data flow, or an AI tool no regulator has thought about yet.

Why Are AI Vendors Now a Board-Level Risk?

Count the outside companies with a hand in your systems. Cloud hosts, software vendors, the payroll provider, the managed IT firm, the consultants with VPN access. Now add the AI layer: model providers, copilots, and the AI features that SaaS products switched on in last month’s update without asking.

They don’t all deserve equal attention. I’d rank them on four things: the data they handle, how deep they connect, what stops if they go down, and how long it would really take to replace them. For AI vendors, ask a few awkward extra questions. Do they train on your data? Where does it go? Will they warn you before a model update changes how a workflow behaves?

The replacement question gets underrated the most. The Pentagon gave itself six months to drop Anthropic’s models and still ran about five weeks over, partly because the model sat inside a live intelligence platform. Once AI is woven into daily work, it doesn’t come out cleanly. Negotiate exit terms, audit rights and change notices early, while you still have leverage.

What Questions Should Boards Ask About Cyber and AI Risk?

No director needs to know how to configure a firewall. A few blunt questions do more:

  • What worries management most right now?
  • Which critical systems are we underprotecting?
  • Have we ever rehearsed a fake CEO asking for an urgent wire transfer?
  • If our main system went down tomorrow, how long until we’re back?
  • Who approved the AI tools that can see customer data?

Then press for proof, because “we have a policy” and “it works” aren’t the same claim. A backup plan means little until someone restores a critical system and times it. Ninety-eight percent training completion is nice. Phishing click rates that actually drop are better. And an AI policy nobody monitors is just a document.

FAQs

Q. Do board members need technical cybersecurity expertise?

Not really. They need enough to ask sharp questions and to translate tech risk into business risk. Some boards recruit a director with a security background, and others lean on outside advisers.

Q. Is AI risk part of cybersecurity governance or separate?

In practice, mostly part of it. AI brings new vendors, new data flows and new attack methods, so most companies fold it into the risk structure they already have.

Q. What is shadow AI?

AI tools employees use without approval or monitoring. IBM’s 2025 research tied it to one in five breaches.

The Real Test of Oversight

The Arup call took minutes. The approval process behind it had probably gone untested for years. That’s the board’s job now: find the gaps before someone with a deepfake does. AI keeps narrowing the time available to do it.

Related: AI Phishing Is Beating DMARC — Here’s What Still Works

Tags: