Skip to content
NEWSR
Digital Safety · 5 min read

AI Cybersecurity Risks Now Reach Fraud, Privacy and Board Oversight

AI is widening cybersecurity exposure beyond malware and phishing, increasing pressure on verification, governance, cloud controls and accountability.

Jordan Ellis
In this story
AI Cybersecurity Risks: Practical Guidance for Leaders — Newsr illustration

Key takeaways

  • AI expands cybersecurity exposure across fraud, privacy, intellectual property, operations and reputation.
  • Aon reports approximately 54% click-through rates for AI-generated phishing versus approximately 12% for traditional attacks in cited analysis.
  • Cloud, identity and third-party dependencies can make automated threats harder to detect and contain.
  • Security spending is rising, but the supplied evidence does not show which controls deliver the strongest return.
  • The next useful milestone is comparable incident, loss and control-effectiveness data.

AI cybersecurity risks are no longer limited to whether a company uses an AI tool. The 2026 evidence supplied for this article points to a broader exposure: artificial intelligence can make fraud more convincing, accelerate attacks, increase dependence on cloud and third-party systems, and complicate responsibility when automated systems fail. The immediate consequence is a governance and verification problem that reaches security teams, executives, insurers and employees.

The evidence does not prove that every organization faces the same level of danger. It does show why a narrow focus on malware detection is insufficient. Aon describes AI-related exposure across privacy, intellectual property, operational resilience and reputation, while Fortinet says attackers are using AI alongside cloud and identity weaknesses. Together, those findings support a practical conclusion: the risk is distributed across business processes rather than confined to the security perimeter.

How the exposure widened in 2026

Aon’s May 2026 analysis places the change in the context of broader enterprise adoption. It cites an increase in organizations using AI in at least one business function from 78% in 2024 to 88% in 2025. As more decisions and workflows depend on AI, a failure can affect more than a single application. It can expose data, alter an operational process or create uncertainty about who approved an action.

The same analysis links AI to more convincing social-engineering attacks. It reports that AI-generated phishing campaigns showed approximately 54% click-through rates, compared with approximately 12% for traditional attacks, citing CrowdStrike analysis. Aon also identifies voice phishing and deepfake impersonation as concerns. These figures are not a universal forecast of attack success, but they illustrate the mechanism: generated text, audio and images can make familiar verification habits less reliable.

That mechanism changes the control that organizations need. Training employees to spot awkward wording may help against some older scams, but it does not resolve a forged voice call or a message that appears to match a known executive’s style. Verification must therefore rely more heavily on independent approval paths, identity checks and limits on high-impact actions. The supplied evidence supports that direction, although it does not quantify how effective any one control is.

The turning point is accountability, not just detection

Fortinet frames 2026 as a period when threats are becoming more automated and harder to detect. Its analysis also points to cloud misconfiguration, stolen credentials, fragmented technology environments, regulatory pressure and alert fatigue. The practical trade-off is clear: adding more detection tools can increase coverage, but it can also produce more alerts and more dependence on systems that security teams must configure and monitor correctly.

That makes accountability a central cybersecurity issue. If an AI system recommends a transaction, processes sensitive information or triggers an operational response, leaders need to know which team owns the decision, what data the system can access and how the action can be reversed. Aon’s call for clear accountability and board-level oversight follows from that exposure. It is a governance recommendation, not evidence that every board currently has an effective AI risk program.

The financial stakes are also moving upstream. Fortinet cites Gartner’s forecast that global end-user spending on information security will reach $240 billion in 2026, a 12.5% increase from 2025. That forecast indicates stronger defensive investment, but spending is not the same as reduced risk. Companies still have to decide whether money goes toward identity controls, cloud security, monitoring, resilience, staff training or response planning. The evidence pack does not establish which allocation produces the best return.

What leaders can verify before expanding AI use

First, organizations can map where AI touches sensitive data, customer communications, payments and operational decisions. That inventory identifies which failures would create privacy, fraud or continuity consequences. Second, they can separate low-impact experimentation from actions that require human approval and independent verification. Third, they can test whether logs, access controls and rollback procedures are available when an automated system behaves unexpectedly.

These steps do not eliminate the threat. They make the exposure more measurable and clarify where a failure would be detected. They also help distinguish a demonstrated control from a vendor promise. Fortinet describes continuous monitoring and proactive protection as responses to changing threats, while Aon emphasizes governance and resilient controls. Neither source supplies independent performance results for a specific product or program.

The next evidence will come from losses and oversight

The most useful next milestone is not another broad prediction about AI. It is comparable evidence showing how often AI-enabled fraud, cloud compromise or automated operational failures occur, how much they cost and which controls worked. Regulatory decisions, insurance requirements and documented incident reports may also show whether organizations are converting high-level concern into enforceable practice.

For now, the defensible decision is to treat AI adoption and cybersecurity planning as one connected risk assessment. The evidence supports stronger verification, clearer ownership and attention to privacy, cloud and third-party dependencies. It does not support a precise probability of loss or a claim that one security technology can solve the problem.

Newsr Reframed

The 2026 evidence points to a shift from isolated AI security concerns toward an enterprise control problem. More convincing impersonation can weaken familiar verification habits, while cloud, identity and third-party dependencies widen the blast radius of failure. That means affected organizations must connect technical monitoring with approval rules, data access limits and board-level accountability. The evidence supports those priorities, but leaves the most decision-relevant questions open: how frequently AI-enabled incidents succeed, what they cost by sector and which safeguards measurably reduce losses.

Sources and methodology

Share this story Facebook X LinkedIn Reddit WhatsApp Email

Latest stories