AI Risk Is Here, but Not in the Way You Might Expect

The dominant headlines of the past month have alerted the world to the unprecedented risk of AI-native cyberattacks. Multiple AI models have carried out autonomous attacks, illustrating how quickly AI risk is evolving.
That’s not the only AI risk that organizations need to prepare for. The technology also enhances human threat actors’ attacks, making them more sophisticated and harder to identify. What’s more, AI creates vulnerabilities from within a business when employees use unapproved or unregulated tools on company devices. It can be challenging to read these headlines and not feel like the sky is falling.
But when Resilience reviewed insurance claims data from the first half of 2026, it couldn't find a single claim involving an AI-native attack vector. In fact, it’s quite the opposite. In the first six months of 2026, 83.3% of financial losses in our portfolio stemmed from attacks exploiting human error (including phishing, social engineering, and transfer fraud).
While your organization is trying to prevent AI from tearing your security system apart, it’s incumbent upon us to remember that overindexing on AI and forsaking all else will only lead us to ignore the risk areas that actually lead to business disruption. Yes, AI threats are here. Yes, AI-driven risk must be taken into account. But what we’ve found is that focusing solely on AI, and not what AI will become a force multiplier of, won’t help us minimize loss and disruption.
Overwhelmingly, our claims in the first half of this year identify human error as the point of failure driving losses. AI is likely playing a role here by making social engineering far more convincing. Previously, phishing emails would come from an obviously foreign address or be littered with spelling errors, making it fairly easy for most employees to identify them as spam. Now, voice cloning and deepfakes can make it seem as though the attack is actually coming from someone the employee trusts — often someone with disproportionate influence and power, like their CEO.
With so much unknown, it can be challenging to understand how AI is actually moving the needle when it comes to cyber risk. I recommend that we think of AI as an accelerant for threat actors’ existing strategies. Think of how AI is helping threat actors find vulnerabilities to exploit faster than organizations can patch them. According to Mandiant’s 2026 frontline data, the average time-to-exploit is negative seven days. That means exploitation is now happening before a patch even exists.
Findings like these drive home the point that organizations have to take control of cybersecurity basics right now, before AI complicates things even more than it already has. It’s important to get ahead of potential AI risk hurtling toward us, but overindexing on that threat in a silo and ignoring the areas leading to real financial losses would be a mistake.
Instead, perfecting cybersecurity fundamentals is the best way to prepare for AI risk, regardless of the shape it takes next.
For instance, as AI evolves social engineering, it’s important to take existing employee phishing training one step further. Click rates in phishing training don’t matter when threat actors increasingly use a deepfake of a CEO’s voice to gain access. Better verification training and ensuring every part of the organization is fully enrolled in multi-factor authentication are great and easy ways to mitigate AI-enhanced social engineering.
The bottom line is that organizations should absolutely be prepared for agentic attacks, but shouldn’t spend the entire budget on defending only against them. AI is changing the cybersecurity landscape, but it’s not driving losses today. As such, the most secure organizations will take a risk-first approach to their cyber plans, identifying the areas that lead to the biggest losses and mitigating those risks. Implement the basic controls that work, and be safer for it.
