If we have selected the wrong experience for you, please change it above.
Artificial intelligence has permanently changed the speed and scale of cyberthreats. AI-powered tools can compress an attack timeline from weeks to hours at a scale no human team can match. Simultaneously, organizational AI adoption has introduced a new and largely ungoverned cyberattack surface: the AI models, training data pipelines, and third-party AI tools many security teams use.
Companies that treat AI purely as a business opportunity and cybersecurity as a separate operational concern risk a significant gap between the pace of AI adoption and the maturity of the controls protecting the organization.
However, the boards that bring AI and cybersecurity together in strategy discussions, budgets and investment decisions, and governance will be better positioned to lead through what comes next.
The question is now: Are we resilient enough to detect, contain, and recover from an AI-accelerated attack?
The AI and cybersecurity agenda can run in two codependent directions: how companies use AI to stay ahead of evolving cyberthreats and how boards ensure AI investments don’t become liabilities. The board’s role is to ensure management addresses both simultaneously, and that roadmaps and budgets reflect that duality.
Cyberthreats don’t impact organizations the same way. What matters is knowing which risks are exploitable in a business’s ecosystem, which services must remain operational if an attack occurs, and how contained an incident can be. These business and security decisions necessitate discussions at the board level before a cybersecurity incident forces the conversation.
Opens in new window
The convergence of AI and cybersecurity is a defining strategic opportunity. Organizations positioned for what comes next will be those whose boards lean in, ask the right questions, and oversee the investments that can turn resilience into a competitive advantage.
From NACD’s Directorship® Magazine. © 2026 National Association of Corporate Directors. All rights reserved. Reprinted with permission.
Deloitte is a NACD partner, providing directors with critical and timely information, and perspectives. Deloitte is a financial supporter of the NACD.
As used above, Deloitte refers to a US member firm of Deloitte Touche Tohmatsu Limited, a UK private company limited by guarantee (DTTL). This article contains general information only and Deloitte is not, by means of this article, rendering accounting, business, financial, investment, legal, tax, or other professional advice or services. This article should not be used as a basis for any decision or action that may affect your business. Before making any decision or taking any action that may affect your business, you should consult a qualified professional advisor. Deloitte shall not be responsible for any loss sustained by any person who relies on this article.