Artificial intelligence is beginning to change the nature of cyber risk. The concern is not only that attacks may become more sophisticated, but that they may become faster, cheaper to execute and easier to scale.
Recent global regulatory discussions have increasingly highlighted this issue. In August 2026, the Financial Stability Board drew attention to the potential of frontier artificial intelligence to amplify cyber risk in the financial system. The concern is significant because artificial intelligence can support both defenders and attackers. It can help institutions detect anomalies, analyse vulnerabilities and automate responses, but it can also support reconnaissance, phishing, impersonation, vulnerability discovery and other malicious activity.
This changes an important assumption in cyber risk management: the time available to detect, assess and respond to a threat may continue to shrink.
Many organisations still manage cyber risk through periodic assessments, scheduled testing, vulnerability reports and conventional escalation processes. These remain necessary, but they may not be sufficient in an environment where weaknesses can potentially be identified and exploited much faster.
The risk management challenge is therefore becoming one of speed, resilience and preparedness.
Cybersecurity cannot be viewed only as a preventive control function. Organisations must assume that some incidents will bypass preventive safeguards. The critical issue then becomes whether essential operations can continue, whether the incident can be contained and whether critical services can be restored within acceptable timeframes.
This is why cyber resilience is becoming increasingly important. On 8 September 2026, CPMI-IOSCO published a Cyber Resilience Toolkit for financial market infrastructures, reinforcing the importance of preparedness, testing, response and recovery. The broader lesson applies across sectors: resilience must be demonstrated through tested capability, not merely documented through policies and procedures.
Third-party dependence is another major concern. Organisations today depend extensively on cloud providers, technology vendors, data processors and external platforms. A weakness or disruption at one critical service provider can affect several institutions simultaneously. Risk managers must therefore look beyond individual vendor assessments and examine concentration risk, substitutability and the business impact of provider failure.
Boards and senior management also need to reconsider how cyber risk is discussed. Reporting should move beyond counts of incidents, patches and training programmes. Management needs visibility into critical vulnerabilities, major technology dependencies, recovery capability, third-party concentration and the organisation’s ability to operate during a severe disruption.
Artificial intelligence does not make traditional cyber risk management irrelevant. It makes disciplined risk management even more important.
The organisations best prepared for the next phase of cyber risk will be those that combine stronger technology controls with faster decision-making, clear escalation, realistic scenario testing and robust recovery capability.
As artificial intelligence accelerates the threat environment, the real test of cyber risk maturity will increasingly be how quickly an organisation can detect, respond and recover.