Do Not Put AI in the Cybersecurity Box: Discuss AI Governance, AI Driven Threats, and Cyber Risks separately
- Merlin @GovernanceCentral

- Jul 28
- 5 min read
Artificial intelligence has quickly become one of the most discussed topics in boardrooms.
Yet many organizations continue to approach AI through a familiar lens: cybersecurity.
That instinct is understandable. AI is increasingly associated with deepfakes, phishing attacks, fraud, misinformation, and emerging security concerns. But viewing AI primarily as a cybersecurity issue creates a governance blind spot.
The reality is that boards are not dealing with one topic. They are dealing with three:
Cyber Risk
AI Governance
AI-Driven Threats
These topics overlap, but they are not the same. And boards that separate them will be better equipped to oversee risk, strategy, and organizational resilience.
Why Boards Need a Different Framework
One of the most common questions directors ask is:
“Where does AI fit within board oversight?”
The answer is not straightforward because AI touches virtually every part of the enterprise. Unlike cybersecurity, which primarily focuses on protecting assets and operations, AI affects strategy, innovation, governance, workforce transformation, risk management, trust, compliance, and competitive advantage. This distinction matters.
When boards collapse AI into cybersecurity discussions, directors often focus disproportionately on what could go wrong while spending insufficient time discussing how AI may reshape business models, customer experiences, operational efficiency, and competitive positioning. The better question is:
What are the distinct governance responsibilities created by cybersecurity, artificial intelligence, and AI-enabled threats?
Topic 1: Cyber Risk — Protecting the Enterprise
Cyber risk remains a foundational board responsibility. Cybersecurity focuses on protecting:
Systems
Networks
Applications
Data
Operations
Critical business services
The core objective is resilience.
The National Institute of Standards and Technology (NIST) Cybersecurity Framework defines cybersecurity around identifying, protecting, detecting, responding to, and recovering from cyber incidents. This framework remains highly relevant regardless of advances in artificial intelligence.
For directors, the fundamental question remains:
Can the organization withstand and recover from a significant cyber event?
Board discussions should focus on:
Ransomware readiness
Business continuity
Third-party cyber risk
Data protection
Incident response capabilities
Operational resilience
These are not new issues. The National Association of Corporate Directors (NACD) has consistently identified cyber-risk oversight as a core governance responsibility because cyber incidents can directly affect operations, reputation, financial performance, and stakeholder confidence. The important takeaway is this:
Cybersecurity was a board issue before AI, and it will remain a board issue long after today’s AI headlines fade.
Topic 2: AI Governance — Creating Value Responsibly
Many organizations mistakenly begin the AI conversation with risk. Boards should begin with value.
Artificial intelligence is not simply a technology to govern. It is a business capability that can transform how organizations operate, compete, and innovate.
Organizations are using AI to:
Improve productivity
Accelerate innovation
Enhance customer experiences
Improve decision-making
Reduce operational friction
Support growth initiatives
Research from McKinsey’s State of AI studies continues to show that organizations increasingly view AI as a strategic capability rather than merely an IT initiative. For boards, the critical question becomes:
How do we create value responsibly with AI?
This question introduces an entirely different governance discussion. It requires directors to consider:
Strategy
How does AI support long-term business objectives?
Governance
Who is accountable for AI decisions and outcomes?
Workforce
How will AI change jobs, skills, and organizational structures?
Compliance
How are emerging regulatory obligations being addressed?
Trust
How do customers, employees, and stakeholders perceive the organization’s use of AI?
The World Economic Forum and OECD have both emphasized that AI governance extends beyond technology risk to include economic, societal, organizational, ethical, and strategic considerations.
This is why AI governance cannot be delegated solely to IT or cybersecurity teams.
It is fundamentally an enterprise-wide governance issue.
Topic 3: AI-Driven Threats — Understanding the New Risk Landscape
The third topic is where confusion often emerges. AI-driven threats are not the same as cyber threats. Some are. Many are not.
Artificial intelligence is reshaping the threat environment by making harmful activities faster, more scalable, more convincing, and more accessible.
Microsoft’s Digital Defense reporting and research from MIT Sloan have highlighted the increasing use of AI in activities such as phishing, social engineering, synthetic media creation, and other forms of cyber-enabled deception. [microsoft.com] [mitsloan.mit.edu]
Examples include:
AI-generated phishing campaigns
Deepfake executive impersonation
Synthetic misinformation
AI-enabled fraud
AI-assisted cyberattacks
Model manipulation and data poisoning
The key governance distinction is that not every AI-driven threat is a cybersecurity problem. Consider the following examples:
AI-Generated Phishing
The objective is to steal credentials or gain unauthorized access. This is both:
A cyber threat
An AI-driven threat
Executive Deepfakes
The objective may be to manipulate investors, deceive employees, or damage trust. This is:
An AI-driven threat
Not necessarily a cybersecurity issue
Synthetic Misinformation
The objective may be to influence perception, reputation, or public confidence. This is:
An AI-driven threat
Primarily a reputation and governance issue
The NIST AI Risk Management Framework explicitly recognizes that AI-related risks extend beyond traditional cybersecurity concerns and can affect trustworthiness, governance, legal exposure, organizational outcomes, and societal impacts.
For boards, this means AI-driven threats frequently require coordinated oversight across:
Cybersecurity
Enterprise risk management
Legal
Compliance
Communications
Human resources
Investor relations
The CISO owns only part of the conversation.
The Most Overlooked Governance Risk
Ironically, the greatest risk may not be cyber risk, AI governance, or AI-driven threats themselves. It may be confusing one for another.
When boards group all AI discussions into a single category, several problems emerge:
Strategic opportunities receive insufficient attention.
Ownership becomes unclear.
Accountability becomes fragmented.
Risk discussions become overly technology-focused.
Enterprise-wide implications are overlooked.
The World Economic Forum’s AI Governance Alliance has repeatedly emphasized the need for cross-functional governance because AI affects virtually every major corporate function. Boards need the same mindset. Effective governance starts with clear distinctions.
Three Questions Every Director Should Be Asking
When evaluating oversight responsibilities, directors can simplify the discussion into three questions:
Cyber Risk
How do we protect the enterprise?
Focus areas:
Security
Resilience
Business continuity
Recovery
AI Governance
How do we create value responsibly?
Focus areas:
Strategy
Innovation
Accountability
Trust
AI-Driven Threats
How is AI changing our risk landscape?
Focus areas:
Emerging threats
Fraud
Reputation
Trust
Organizational resilience
The Future Board Agenda
Over the next decade, boards will likely spend more time discussing artificial intelligence than any other emerging technology. The directors who navigate this successfully will recognize that AI is not merely a cybersecurity topic. It is three distinct board-level topics:
Cyber Risk
Protecting the enterprise from disruption and compromise.
AI Governance
Creating sustainable value through responsible AI adoption.
AI-Driven Threats
Understanding how AI reshapes cyber, fraud, reputational, operational, and governance risks.
These conversations are related. But they are not the same. And boards that separate them thoughtfully will be far better positioned to govern organizations in a world increasingly shaped by artificial intelligence.
Sources
NIST Cybersecurity Framework 2.0
NIST AI Risk Management Framework 1.0
National Association of Corporate Directors (NACD), Director’s Handbook on Cyber-Risk Oversight
NACD, Governing Artificial Intelligence: Key Issues for Directors
World Economic Forum, AI Governance Alliance
OECD AI Principles
McKinsey, State of AI
Microsoft, Digital Defense Report [microsoft.com]
MIT Sloan, AI Cyberattacks and Three Pillars for Defense [mitsloan.mit.edu





Comments