Continued operational oversight essential to prevent exposure as AI gains access to sensitive data: AXA XL

technology

Artificial intelligence (AI) is becoming embedded into core business processes faster than many organisations can establish their governance, security and incident-response capabilities, according to a recent report by AXA XL and cyber security consultancy S-RM.

The report, ‘Building Resilient AI: Managing AI risk through governance, security and resilience’, cautions that executive teams are facing a widening governance deficit, and it calls on business leaders to treat AI risk as an enterprise resilience issue rather than solely a technology or compliance concern.

With McKinsey & Company’s 2026 State of AI survey showing that 88% of organisations now deploy AI in at least one business function, the technology’s rapid integration into sensitive data flows, operational applications, and automated decision-making has created more potential entry points for cyber threats and introduced new forms of exploitation, operational failure, and regulatory scrutiny. 

The report identified five priorities for business leaders to help counter these vulnerabilities. The transition starts with the establishment of clear accountability for AI across the enterprise, including formal deployments, embedded software features and shadow AI.

Because autonomous systems increasingly interface with critical intellectual property, organisations must simultaneously harden identity and access architectures while enforcing strict data protections.

The report also advises business leaders to manage AI risk throughout its lifecycle, from data collection and model development to deployment, monitoring and incident response.

Rigorous governance and due diligence should also apply to AI vendors and other critical third parties. Additionally, risk managers should prepare for AI-related loss scenarios that may cut across cyber, fraud, liability, business interruption and other areas of insurance coverage.

See also  Verisk withdraws from AccuLynx acquisition

Jonathan Salter, Head of Risk Consulting at AXA XL, said: “AI is moving from experimentation into the systems and processes organisations rely on every day, but governance is not always keeping pace. 

“The organisations best placed to capture AI’s value will be those that know where it is being used, understand the business consequences when it fails and build security and resilience into deployment from the outset.”

“AI risk rarely emerges in isolation,” said Rebiah Bardot-Girard, Head of Cyber Risk Consulting Services at AXA XL. “It amplifies existing weaknesses in identity management, data governance, supplier oversight and incident readiness. A practical inventory of where AI is used, what data it can access and where it can take or influence action is now a fundamental starting point for resilience.”

The report examines risks including data leakage, model manipulation, prompt injection, unreliable outputs, shadow AI and overly autonomous agents.

It sets out five foundations for secure AI by design: strong data governance, secure models and applications, ecosystem resilience, robust access controls and continuous monitoring.

While data from the World Economic Forum shows 64% of organisations now assess the security of AI tools before deployment, up from 37% a year earlier, pre-deployment checks alone are not enough.

As AI gains access to sensitive data, core applications and decision-making processes, continued operational oversight remains essential to prevent exposure, analysts highlight. 

The post Continued operational oversight essential to prevent exposure as AI gains access to sensitive data: AXA XL appeared first on ReinsuranceNe.ws.

Spread the love

Leave a Reply

Your email address will not be published. Required fields are marked *