Why AI Might Be Your Biggest Cybersecurity Threat Yet—And How Smart Investors Are Turning Risk Into Gold
Ever feel like artificial intelligence is speeding down the organizational risk highway while leadership is still stuck trying to find the ignition key? It’s a wild ride out there. AI isn’t just knocking on the door anymore—it’s already moved in, reprogramming workflows and quietly reshaping risk profiles before leaders have even had their morning coffee. Dani Michaux of KPMG hits the nail on the head, showing why AI isn’t just a tech puzzle but a full-blown people challenge that demands crystal-clear governance. The real kicker? The risks arising aren’t just about systems glitching but about how folks trust and over-rely on AI, sometimes without the skepticism critical thinking demands. This isn’t reserved for the tech giants alone—companies of all sizes, tangled in complex supply chains, must seriously rethink how AI fits into their risk landscape and resilience playbook. So, how do you steer your ship in these fast-changing waters to avoid the hidden icebergs of “shadow AI”? Let’s dig into what leaders need to do now, before the gap between AI use and risk awareness becomes an unbridgeable chasm. LEARN MORE
Artificial intelligence is changing organisational risk profiles faster than leadership behaviour can adapt. KPMG’s Dani Michaux explains how to build cyber resilience, and why leaders need to treat AI as a people risk, putting clear governance around how it is used across the organisation
THE CYBER ISSUE LEADERS ARE FACING RIGHT NOW
AI has rapidly become embedded in everyday productivity tools, putting experimentation at the fingertips of most team members — often quietly, and often without explicit leadership direction.
As a result, many organisations now face a growing gap between how AI is used and how leaders believe risk is being managed.
As that gap widens, many organisations are also rethinking governance, oversight, and adoption choices through AI consulting alongside cyber risk management.
That gap matters.
While AI is often discussed as a technology issue, the most significant risks emerging are not purely technical.
They are behavioural, cultural, and organisational.
And they are affecting organisations of all sizes.
WHAT IS SHADOW AI? AND WHY DOES IT MATTER FOR CYBER RESILIENCE?
AI is no longer sitting at the edges of the organisation. It is writing code, analysing data, supporting decisions and automating activities that were previously human-led.
In many cases, it has become part of ‘how work gets done’ before organisations have fully agreed how it should be used, challenged, or governed.
This spread of unsanctioned AI use (sometimes called shadow AI) creates blind spots that are difficult to detect until risk has already materialised.
This changes the nature of risk. Exposure is no longer confined to system failures or cyber vulnerabilities.
It now increasingly sits in how people trust AI outputs, where overreliance can quietly replace critical thinking, and fundamental reasoning is applied less rigorously than before.
You may want to ask: where could this be happening today, without anyone in your organisation intentionally taking a risk?
THIRD-PARTY AND SUPPLY CHAIN EXPOSURE
Crucially, this is not just a large corporate problem. Smaller and mid-sized organisations are often deeply embedded in supply chains and ecosystems.
Their perceived size does not reflect their actual importance — or the impact if something goes wrong.
Third-party vendors and partners can introduce additional exposure, and the AI tools they use may extend risk into the organisation in ways that are not always visible.
In cases where organisations are responding well, they tend to engage early — identifying where AI is already in use and addressing cyber risk as it emerges, rather than waiting for an incident to force action.
HOW CAN LEADERS BUILD CYBER RESILIENCE?
The actions you need to take are practical, not transformational. They are about clarity, consistency and intent.
Treat AI as a people risk: Be explicit about the expectations for AI use. That includes reinforcing that responsibility always sits with people, not tools.
Just as importantly, leaders must model the behaviours they expect to see — curiosity, challenge, and judgement — rather than blind reliance on outputs.
Use AI for threat detection and defence: Most organisations frame AI through the lens of efficiency.
Few frame it as a defensive capability. Yet AI’s real resilience value lies in its ability to simulate before execution — threat detection, modelling anomalies, and stress testing decisions and scenarios before issues arise.
Shifting the narrative from ‘AI as eciency’ to ‘AI as defence’ changes how it is designed, deployed and governed.
Build enterprise-wide consistency: Fragmented experimentation creates fragmented risk. Leaders should move away from isolated pilots towards enterprisewide principles.
The goal is not endless policy detail, but clarity on ‘what good looks like’ and how it is reinforced in everyday decisions.

AI THREATS TO WATCH IN THE COMING MONTHS
Several trends will intensify pressure on leaders over the coming months. Bad actors are becoming more sophisticated in their use of AI.
Regulatory and stakeholder scrutiny is increasing across jurisdictions.
In that environment, timely regulatory advisory can help organisations interpret new expectations and translate them into workable controls.
AI related risk is already here.
The real question is how deliberately it is managed.
You don’t need perfect answers, but you do need to set a clear direction for your team.
For organisations formalising that response, KPMG in Ireland’s AI consulting team can help shape governance, controls and safe adoption across the business.
Photo: KPMG’s Dani Michaux




Post Comment