AI Creates Two New Challenges for Boards: AI-Powered Threats and AI-Driven Risk

Most boards are spending significant time discussing AI opportunities.
The questions are familiar. How can AI improve productivity? Where can it accelerate growth? How can it enhance customer experience? How quickly should the company move?
Far less time is often spent discussing the risks that accompany those opportunities.
That is why recent comments from Palo Alto Networks CEO Nikesh Arora deserve attention. Arora argues that roughly $1 trillion of cybersecurity infrastructure was built before the emergence of modern AI systems and was not designed for threats operating at machine speed. He believes many organizations are relying on security architectures developed for a very different technology environment. [cnbc.com], [finance.yahoo.com]
At first glance, this may sound like a cybersecurity company making the case for a new spending cycle.
Part of it is. Part of it isn't.
Understanding the difference is important for directors and senior executives.
Distinguishing the Sales Message from the Strategic Message
Whenever cybersecurity executives talk about outdated security infrastructure, boards should recognize the commercial context.
Palo Alto Networks sells cybersecurity platforms. If organizations decide they need to modernize security architectures, Palo Alto stands to benefit. The same is true for competitors such as CrowdStrike, Microsoft, Cisco, and others. [cnbc.com], [cnbc.com]
That is the sales message. The sales message is essentially:
Existing security tools are becoming inadequate.
Organizations should modernize their cybersecurity environment.
Significant new investment will be required.
Security vendors can help solve the problem.
There is nothing unusual about that. Every technology cycle creates winners that advocate for modernization.
What is more interesting is that the underlying concern is now being echoed well beyond Palo Alto Networks. CrowdStrike CEO George Kurtz has argued that AI is exposing weaknesses in legacy security environments and enabling attackers to identify and exploit vulnerabilities far more quickly than before. [cnbc.com]
More than 100 technology and security companies, including Microsoft, OpenAI, Anthropic, Google, Amazon Web Services, Cisco, IBM, CrowdStrike, and Palo Alto Networks, have collectively warned that organizations have a limited window to prepare for increasingly sophisticated AI-enabled attacks. Their conclusion was straightforward: existing approaches are unlikely to be sufficient indefinitely. [forbes.com]
Boston Consulting Group has made a different, but related, observation. The firm argues that many organizations are adopting AI faster than they are adapting cybersecurity, governance, and risk management practices. According to BCG, this is becoming a CEO and board issue rather than merely a technology issue. [bcg.com], [bcg.com]
That is the strategic message. And unlike the sales message, it applies whether a company uses Palo Alto, CrowdStrike, Microsoft, Cisco, or any other provider.
What Does Arora Mean by "$1 Trillion of Cybersecurity Infrastructure"?
Many directors hear the headline and assume it refers to hardware. It does not.
Arora's estimate represents what he describes as accumulated cybersecurity infrastructure and cybersecurity debt developed over many years of enterprise technology investment. [finance.yahoo.com], [cnbc.com]
Cybersecurity infrastructure includes:
Identity and access management systems
Endpoint protection platforms
Security monitoring and analytics
Cloud security controls
Security operations centers
Data protection technologies
Network security architectures
Threat detection and response systems
Governance processes that support cyber operations
Some are hardware. Most are software platforms and cloud-based services.
Together, they form the security architecture that organizations depend upon to protect their data, operations, customers, and critical business processes.
Arora's argument is not that these systems suddenly stopped working. His argument is that many were designed before organizations began deploying generative AI, AI agents, and highly automated workflows. They were built for a world in which attackers operated largely at human speed. [cnbc.com], [finance.yahoo.com]
Whether the modernization requirement is truly $1 trillion is open to debate.
The more important question is whether today's security architecture is adequate for tomorrow's threat environment.
Two Different Challenges Are Emerging
One reason boards sometimes struggle with AI discussions is that several different risks get grouped together under the label "AI risk." In reality, two separate challenges are emerging.
AI-Powered Threats
This is the challenge most cybersecurity leaders are discussing. The motivations of attackers have not changed. They still seek to steal information, commit fraud, disrupt operations, extort organizations, or gain unauthorized access.
What has changed is capability. AI enables attackers to automate activities that previously required considerable human effort:
Finding vulnerabilities
Conducting reconnaissance
Generating phishing campaigns
Writing malicious code
Scaling attacks across large numbers of targets
In practical terms, AI can compress the timeline of cyberattacks while increasing their scale and sophistication. Activities that once took days or weeks can now occur much more rapidly. [cnbc.com], [cnbc.com], [business-s...andard.com]
This is the issue Arora is largely focused on when he discusses modernizing cybersecurity infrastructure.
AI-Driven Business Risk
The second challenge receives less attention but may prove equally important.
These risks arise not because attackers are using AI.
They arise because the organization itself is using AI. Examples include:
Hallucinated outputs influencing decisions
Regulatory violations
Intellectual property leakage
Exposure of confidential information
Biased or discriminatory outcomes
Inaccurate recommendations
Autonomous agents exceeding intended authority
Lack of accountability for AI-generated decisions
None of these necessarily involve a cybersecurity event. Yet any of them could create significant financial, legal, operational, regulatory, or reputational consequences. [bcg.com], [forbes.com]
This distinction matters because companies can have excellent cybersecurity programs and still suffer significant AI-related failures. Cybersecurity and AI governance increasingly overlap, but they are not the same thing.
The Governance Gap
Many organizations are moving rapidly to deploy AI capabilities. That is understandable. Few leaders want to be left behind during a major technology transformation. The challenge is that governance often develops more slowly than technology adoption.
Boards routinely review plans focused on:
Productivity gains
Cost savings
Innovation
Customer experience
New business opportunities
Less attention is often paid to how governance, risk management, controls, and oversight mechanisms must evolve alongside those initiatives. [bcg.com], [bcg.com]
As AI becomes embedded throughout the enterprise, organizations become increasingly dependent on data, algorithms, interconnected systems, third-party providers, and automated decision-making. That dependence creates new forms of risk that many governance frameworks were not designed to address.
Why This Has Become a Board Issue
For years, cybersecurity could largely be delegated to technical specialists. AI changes that equation.
AI affects strategy, operations, compliance, legal exposure, workforce management, customer trust, reputation, and long-term competitiveness. These are traditional board responsibilities. [bcg.com], [bcg.com]
As a result, directors need visibility into both sides of the challenge:
How is the company protecting itself from AI-enabled attackers?
And:
How is the company managing the risks created by its own use of AI?
Those are different questions requiring different expertise, different controls, and often different governance structures.
Questions Worth Asking
A productive board discussion might begin with questions such as:
How is AI changing our threat landscape?
Which parts of our security architecture were designed before our current AI strategy?
Can our security operations respond effectively to AI-enabled attacks?
Where are we deploying AI across the business?
What are the most significant risks associated with those deployments?
How are AI decisions being monitored and validated?
Who is accountable for AI governance across the enterprise?
How are cybersecurity, compliance, legal, audit, and business leaders coordinating oversight?
The objective is not for directors to become cybersecurity experts. The objective is to ensure management is approaching AI with the same rigor applied to any other material enterprise risk.
What Boards Should Take Away
Boards should not accept every vendor claim at face value. The exact size of the cybersecurity modernization opportunity is debatable. The winners of any future spending cycle remain uncertain. Those are market questions. The governance question is different.
A growing group of cybersecurity leaders, technology companies, consultants, and risk professionals believe that AI is changing both cyber threats and enterprise risk faster than many organizations are adapting. [cnbc.com], [forbes.com], [bcg.com], [bcg.com]
For directors, the central challenge is not simply cybersecurity. It is understanding and overseeing two related but distinct issues:
AI-powered threats, where attackers use AI against the enterprise.
And AI-driven business risks, where the enterprise's own use of AI creates new operational, regulatory, legal, and reputational exposures.
The organizations that emerge strongest from this transition are unlikely to be the ones that adopt AI the fastest. More likely, they will be the ones that pair innovation with disciplined governance, modern risk management, and a clear understanding of how AI is reshaping both opportunity and risk. [bcg.com], [bcg.com]
See the Strategic Pivot Scenario (TM) boardroom simulation.





Comments