Skip to main content
Welcome to Deloitte

If we have selected the wrong experience for you, please change it above.

Governing the convergence of AI and cyber risk

As published in the NACD Directorship®  magazine

Artificial intelligence has permanently changed the speed and scale of cyberthreats. AI-powered tools can compress an attack timeline from weeks to hours at a scale no human team can match. Simultaneously, organizational AI adoption has introduced a new and largely ungoverned cyberattack surface: the AI models, training data pipelines, and third-party AI tools many security teams use.

Companies that treat AI purely as a business opportunity and cybersecurity as a separate operational concern risk a significant gap between the pace of AI adoption and the maturity of the controls protecting the organization.

However, the boards that bring AI and cybersecurity together in strategy discussions, budgets and investment decisions, and governance will be better positioned to lead through what comes next.

The question is now: Are we resilient enough to detect, contain, and recover from an AI-accelerated attack? 

Two directions, one conversation

The AI and cybersecurity agenda can run in two codependent directions: how companies use AI to stay ahead of evolving cyberthreats and how boards ensure AI investments don’t become liabilities. The board’s role is to ensure management addresses both simultaneously, and that roadmaps and budgets reflect that duality.

Getting ahead of the curve

Cyberthreats don’t impact organizations the same way. What matters is knowing which risks are exploitable in a business’s ecosystem, which services must remain operational if an attack occurs, and how contained an incident can be. These business and security decisions necessitate discussions at the board level before a cybersecurity incident forces the conversation.

Emerging risks worth watching

AI enables highly personalized phishing and deepfake impersonation, eroding trust in communications. Human judgment, often the last line of defense against cyberattacks, is under pressure as the quality and volume of AI-generated deception grows.

Third-party AI providers and shared platforms create concentrated, cascading risk. A compromise in an upstream vendor can propagate across every dependent organization, often before anyone is aware.

Adversaries who manipulate AI model inputs or corrupt training pipelines can cause harm that resembles a business decision, making detection harder.

Sophisticated threat actors are exfiltrating encrypted data, anticipating that future advances in quantum computing will enable decryption. Sensitive data may be at risk of future exposure even if it is currently well protected.

Actions directors can consider taking:

  • Ask management where AI is used across the enterprise, what data it touches, and whether cybersecurity requirements were part of the procurement process.
  • Request that the resilience plan includes AI-specific threat scenarios, such as automated cyberattacks, AI-generated fraud, AI model integrity risks, and supply chain compromise.
  • Understand the company’s blast radius. If a critical system is compromised, how far can the impact spread, and does existing architecture limit that through segmentation?
  • Inquire about the roadmap for post-quantum cryptography, especially for data with long-term sensitivity.
  • Champion a culture in which security and AI teams collaborate from the start of any AI initiative.

The convergence of AI and cybersecurity is a defining strategic opportunity. Organizations positioned for what comes next will be those whose boards lean in, ask the right questions, and oversee the investments that can turn resilience into a competitive advantage.

About Deloitte's Center for Board Effectivness

Deloitte’s Center for Board Effectiveness supports directors in fulfilling their oversight responsibilities and navigating today’s most critical governance priorities through actionable insights and experiences.

From NACD’s Directorship® Magazine. © 2026 National Association of Corporate Directors. All rights reserved. Reprinted with permission.

Deloitte is a NACD partner, providing directors with critical and timely information, and perspectives. Deloitte is a financial supporter of the NACD.

As used above, Deloitte refers to a US member firm of Deloitte Touche Tohmatsu Limited, a UK private company limited by guarantee (DTTL). This article contains general information only and Deloitte is not, by means of this article, rendering accounting, business, financial, investment, legal, tax, or other professional advice or services. This article should not be used as a basis for any decision or action that may affect your business. Before making any decision or taking any action that may affect your business, you should consult a qualified professional advisor. Deloitte shall not be responsible for any loss sustained by any person who relies on this article.