top of page

Do Not Put AI in the Cybersecurity Box: Discuss AI Governance, AI Driven Threats, and Cyber Risks separately

  • Writer: Merlin @GovernanceCentral
    Merlin @GovernanceCentral
  • Jul 28
  • 5 min read

Artificial intelligence has quickly become one of the most discussed topics in boardrooms.


Yet many organizations continue to approach AI through a familiar lens: cybersecurity.

That instinct is understandable. AI is increasingly associated with deepfakes, phishing attacks, fraud, misinformation, and emerging security concerns. But viewing AI primarily as a cybersecurity issue creates a governance blind spot.


The reality is that boards are not dealing with one topic. They are dealing with three:

  1. Cyber Risk

  2. AI Governance

  3. AI-Driven Threats


These topics overlap, but they are not the same. And boards that separate them will be better equipped to oversee risk, strategy, and organizational resilience.


Why Boards Need a Different Framework


One of the most common questions directors ask is:

“Where does AI fit within board oversight?”

The answer is not straightforward because AI touches virtually every part of the enterprise. Unlike cybersecurity, which primarily focuses on protecting assets and operations, AI affects strategy, innovation, governance, workforce transformation, risk management, trust, compliance, and competitive advantage. This distinction matters.


When boards collapse AI into cybersecurity discussions, directors often focus disproportionately on what could go wrong while spending insufficient time discussing how AI may reshape business models, customer experiences, operational efficiency, and competitive positioning. The better question is:

What are the distinct governance responsibilities created by cybersecurity, artificial intelligence, and AI-enabled threats?

Topic 1: Cyber Risk — Protecting the Enterprise


Cyber risk remains a foundational board responsibility. Cybersecurity focuses on protecting:

  • Systems

  • Networks

  • Applications

  • Data

  • Operations

  • Critical business services


The core objective is resilience.


The National Institute of Standards and Technology (NIST) Cybersecurity Framework defines cybersecurity around identifying, protecting, detecting, responding to, and recovering from cyber incidents. This framework remains highly relevant regardless of advances in artificial intelligence.


For directors, the fundamental question remains:

Can the organization withstand and recover from a significant cyber event?

Board discussions should focus on:

  • Ransomware readiness

  • Business continuity

  • Third-party cyber risk

  • Data protection

  • Incident response capabilities

  • Operational resilience


These are not new issues. The National Association of Corporate Directors (NACD) has consistently identified cyber-risk oversight as a core governance responsibility because cyber incidents can directly affect operations, reputation, financial performance, and stakeholder confidence. The important takeaway is this:


Cybersecurity was a board issue before AI, and it will remain a board issue long after today’s AI headlines fade.


Topic 2: AI Governance — Creating Value Responsibly


Many organizations mistakenly begin the AI conversation with risk. Boards should begin with value.


Artificial intelligence is not simply a technology to govern. It is a business capability that can transform how organizations operate, compete, and innovate.


Organizations are using AI to:

  • Improve productivity

  • Accelerate innovation

  • Enhance customer experiences

  • Improve decision-making

  • Reduce operational friction

  • Support growth initiatives


Research from McKinsey’s State of AI studies continues to show that organizations increasingly view AI as a strategic capability rather than merely an IT initiative. For boards, the critical question becomes:

How do we create value responsibly with AI?

This question introduces an entirely different governance discussion. It requires directors to consider:


Strategy

How does AI support long-term business objectives?


Governance

Who is accountable for AI decisions and outcomes?


Workforce

How will AI change jobs, skills, and organizational structures?


Compliance

How are emerging regulatory obligations being addressed?


Trust

How do customers, employees, and stakeholders perceive the organization’s use of AI?


The World Economic Forum and OECD have both emphasized that AI governance extends beyond technology risk to include economic, societal, organizational, ethical, and strategic considerations.


This is why AI governance cannot be delegated solely to IT or cybersecurity teams.

It is fundamentally an enterprise-wide governance issue.


Topic 3: AI-Driven Threats — Understanding the New Risk Landscape


The third topic is where confusion often emerges. AI-driven threats are not the same as cyber threats. Some are. Many are not.


Artificial intelligence is reshaping the threat environment by making harmful activities faster, more scalable, more convincing, and more accessible.


Microsoft’s Digital Defense reporting and research from MIT Sloan have highlighted the increasing use of AI in activities such as phishing, social engineering, synthetic media creation, and other forms of cyber-enabled deception. [microsoft.com] [mitsloan.mit.edu]


Examples include:

  • AI-generated phishing campaigns

  • Deepfake executive impersonation

  • Synthetic misinformation

  • AI-enabled fraud

  • AI-assisted cyberattacks

  • Model manipulation and data poisoning


The key governance distinction is that not every AI-driven threat is a cybersecurity problem. Consider the following examples:


AI-Generated Phishing

The objective is to steal credentials or gain unauthorized access. This is both:

  • A cyber threat

  • An AI-driven threat


Executive Deepfakes

The objective may be to manipulate investors, deceive employees, or damage trust. This is:

  • An AI-driven threat

  • Not necessarily a cybersecurity issue


Synthetic Misinformation

The objective may be to influence perception, reputation, or public confidence. This is:

  • An AI-driven threat

  • Primarily a reputation and governance issue


The NIST AI Risk Management Framework explicitly recognizes that AI-related risks extend beyond traditional cybersecurity concerns and can affect trustworthiness, governance, legal exposure, organizational outcomes, and societal impacts.


For boards, this means AI-driven threats frequently require coordinated oversight across:

  • Cybersecurity

  • Enterprise risk management

  • Legal

  • Compliance

  • Communications

  • Human resources

  • Investor relations


The CISO owns only part of the conversation.


The Most Overlooked Governance Risk


Ironically, the greatest risk may not be cyber risk, AI governance, or AI-driven threats themselves. It may be confusing one for another.


When boards group all AI discussions into a single category, several problems emerge:

  • Strategic opportunities receive insufficient attention.

  • Ownership becomes unclear.

  • Accountability becomes fragmented.

  • Risk discussions become overly technology-focused.

  • Enterprise-wide implications are overlooked.


The World Economic Forum’s AI Governance Alliance has repeatedly emphasized the need for cross-functional governance because AI affects virtually every major corporate function. Boards need the same mindset. Effective governance starts with clear distinctions.


Three Questions Every Director Should Be Asking


When evaluating oversight responsibilities, directors can simplify the discussion into three questions:

Cyber Risk

How do we protect the enterprise?

Focus areas:

  • Security

  • Resilience

  • Business continuity

  • Recovery


AI Governance

How do we create value responsibly?

Focus areas:

  • Strategy

  • Innovation

  • Accountability

  • Trust


AI-Driven Threats

How is AI changing our risk landscape?

Focus areas:

  • Emerging threats

  • Fraud

  • Reputation

  • Trust

  • Organizational resilience


The Future Board Agenda


Over the next decade, boards will likely spend more time discussing artificial intelligence than any other emerging technology. The directors who navigate this successfully will recognize that AI is not merely a cybersecurity topic. It is three distinct board-level topics:


Cyber Risk

Protecting the enterprise from disruption and compromise.


AI Governance

Creating sustainable value through responsible AI adoption.


AI-Driven Threats

Understanding how AI reshapes cyber, fraud, reputational, operational, and governance risks.


These conversations are related. But they are not the same. And boards that separate them thoughtfully will be far better positioned to govern organizations in a world increasingly shaped by artificial intelligence.


Sources

  • NIST Cybersecurity Framework 2.0

  • NIST AI Risk Management Framework 1.0

  • National Association of Corporate Directors (NACD), Director’s Handbook on Cyber-Risk Oversight

  • NACD, Governing Artificial Intelligence: Key Issues for Directors

  • World Economic Forum, AI Governance Alliance

  • OECD AI Principles

  • McKinsey, State of AI

  • Microsoft, Digital Defense Report [microsoft.com]

  • MIT Sloan, AI Cyberattacks and Three Pillars for Defense [mitsloan.mit.edu

Comments


Commenting on this post isn't available anymore. Contact the site owner for more info.
bottom of page