Source: Harvard Business Review
Author: Hise O. Gibson
URL: https://hbr.org/2026/04/ai-is-reshaping-cyber-risk-boards-need-to-manage-the-threat
ONE SENTENCE SUMMARY:
AI-driven cyber threats create a BANI world; leaders must adopt ACTS to build resilience, governance, fluency, and breach readiness.
MAIN POINTS:
- Average AI-enabled breach costs $4.88M, excluding reputational, regulatory, and cascading operational impacts.
- Deepfakes can rapidly destabilize markets, geopolitics, and public trust before verification catches up.
- Zelensky surrender deepfake illustrates AI misinformation is already operational, not hypothetical.
- Cheaper, accessible generation tools increase speed, scale, and believability of adversarial content.
- Public-facing application attacks rose 44% year-over-year, increasingly exploiting AI-enabled vulnerabilities.
- Adaptive attacks can autonomously probe defenses, evolve tactics, and exploit weaknesses in real time.
- Accenture reports 77% of organizations lack basic data and AI security practices.
- VUCA framing is outdated; BANI better reflects brittle, anxious, nonlinear, incomprehensible threat conditions.
- NotPetya showed single points of failure can halt global operations within minutes.
- ACTS framework urges assuming breaches, building AI fluency, operationally anchored AI, and stronger governance.
TAKEAWAYS:
- Plan for inevitable compromise with zero trust, segmentation, backups, and crisis rehearsals.
- Operational resilience matters: prove you can run 48 hours without digital systems.
- Build AI literacy across leadership via training, reverse mentoring, and adaptable hiring.
- Scale only AI initiatives tied to core operations with clear ROI and measurable outcomes.
- Establish cross-functional AI governance with ethics, bias testing, and preassigned accountability.