The World Economic Forum Global Cybersecurity Outlook 2026 reports that 94 per cent of cyber leaders identify artificial intelligence as a key driver of change in cybersecurity over the coming year, while 87 per cent identified AI-related vulnerabilities as the fastest-growing cyber risk in 2025.
As AI becomes increasingly embedded in business operations, organisations face new challenges around governance, oversight and security. Realising the benefits of AI requires organisations to manage the risks associated with its adoption.
AI has embedded itself in everyday work faster than leadership has been able to adapt, says Dani Michaux, EMA cyber leader at KPMG in Ireland. “What I’m seeing is a widening gulf between how AI is actually being used across organisations and how confident leaders are that this use is being managed.
“Much of this happens quietly, through so-called ‘shadow AI’ – unsanctioned tools adopted by staff without formal sign-off.”
READ MORE

The gap seen most often by David McNamara, founder of Commsec, is speed without a policy to match it. “Staff are using generative AI tools long before anyone has written down what is and is not acceptable, and almost nobody is sandboxing or testing these tools before they go live.
“That means sensitive data is moving through systems nobody has assessed, and nobody has actually decided who owns the risk. The pattern I see again and again is that cybersecurity and AI security get treated as one job, handed to the IT manager, and they are told to make it work. That is not governance.”

Introducing risk
AI agents introduce risk because they can access data, interact with systems, initiate workflows and make decisions at speed, warns Len McAuliffe, cybersecurity practice partner with PwC Ireland. “If permissions are too broad, oversight is weak or instructions are manipulated, the consequences can escalate quickly.
“Most organisations are still adapting. Their existing cyber controls were largely designed for human users and conventional applications, rather than autonomous tools operating across multiple systems and data sources.”
Innovation and risk management should not be viewed as competing priorities, explains Fabiano Saccone, senior technical underwriter at Hiscox Ireland. “Organisations that establish clear governance from the beginning often find they are able to innovate with greater confidence because responsibilities, approval processes and acceptable use policies are already in place.

“Boards have an important role in ensuring that AI adoption aligns with the organisation’s overall risk appetite and strategic objectives. By asking the right questions around governance, accountability and resilience, senior leaders can support innovation while helping to minimise unnecessary exposure.”
Boards and executive teams should treat AI adoption as a powerful enabler of business efficiency, innovation and competitiveness, rather than simply as a new source of risk, continues Saccone. “The objective should not be to slow adoption down, but to create the right internal conditions for AI to be used responsibly.”
Compliance complacency
AI adoption cannot happen successfully without robust AI governance, says David Lee, PwC Ireland chief technology officer. “One of the biggest gaps is that AI adoption is moving faster than governance. Organisations are rapidly rolling out AI agents, but many still lack clear accountability, risk controls, data governance, model monitoring and employee training.”
PwC’s 2026 Responsible AI survey found that responsible AI practices are still in their infancy in Ireland compared with the US, says Lee. “Few Irish companies have built the governance and operating discipline needed to make responsible AI work at scale.
“Over three-quarters [77 per cent] of Irish respondents reported that the single biggest barrier to operationalising responsible AI is the difficulty scaling responsible AI principles into operations. Over a third [37 per cent] said it was the lack of clarity on ownership and three out of 10 said it was lack of tools.”
Rather than lengthy policy documents, aim for one clear, shared understanding across the business of what responsible AI use looks like, says Michaux. “Leaders must be explicit that accountability always sits with people, not tools, and should model the judgment they expect from staff.
“That also means stronger data protection around how sensitive information moves through AI systems, and a clear ability to explain how AI-assisted decisions are reached.”
Future challenges
One of the most significant challenges is likely to be the growing sophistication of AI-enabled social engineering attacks, says Saccone. “Criminals are increasingly able to produce convincing emails, messages and other communications that are far more personalised and difficult to identify than traditional phishing attempts. This may be especially significant for SMEs, where employees frequently perform several roles and may have less access to specialist fraud prevention or cybersecurity support.”
At the same time, organisations will need to manage the risks associated with employees using AI tools without appropriate governance or oversight. Maintaining visibility of where AI is being used and ensuring appropriate controls remain in place will become increasingly important as adoption accelerates, he says.

Compliance and agility are not opposites if you build continuous review into how you operate, says McNamara. “That means regularly reviewing your AI policy, your usage and your guardrails, and having genuine visibility into both chat-based AI and agentic AI activity across the business.
“Policies need to be clear enough that people know what appropriate use looks like, and IT needs modern AI detection and response tools to catch what falls outside that. Ultimately, this comes down to open conversation and good governance. The board has to look at both sides of the coin: the productivity AI delivers and the risk it carries in terms of misuse, data breaches, and customer trust.”














