Skip to content
Home » Articles » Boards Under Pressure: Governing Cyber, AI and CSR in 2026 (Part One)

Boards Under Pressure: Governing Cyber, AI and CSR in 2026 (Part One)

Why the Governance Gap Is Widening and What Boards Must Do About It

Good governance has always required directors to make decisions under conditions of uncertainty and incomplete information. That is not new. What is new, in 2026, is the speed at which the uncertainty moves, the technical depth it now demands, and the personal accountability that attaches to directors when oversight is found wanting.

I have worked with boards across private, and not-for-profit organisations for many years. The boards that navigate complexity well are not necessarily those with the most resources. They are the ones that have built the habit of asking hard questions early, before a crisis forces the conversation. Across cybersecurity, artificial intelligence, and corporate social responsibility, that habit has never mattered more.

Regulatory bodies, investors, insurers, customers and consumers are no longer prepared to accept “we have a policy” as a sufficient answer. They want evidence of informed, active oversight, and they are increasingly looking at individual directors when they do not get it.

This is the first of two articles examining the core governance challenges facing boards in 2026. Here, I focus on cyber and AI. In Part Two, I will turn to CSR, sustainability reporting, and the growing accountability pressures shaping stakeholder expectations.

The Cyber Threat Has Changed. Has Your Board?

Cybersecurity is no longer a technology problem. It is a board-level enterprise risk. That distinction matters enormously, and many boards have not yet made the shift in how they think and operate.

What has changed? Speed, primarily. Attacks that once unfolded over days now move across identity, cloud, and endpoint layers in hours, sometimes minutes. As Forvis Mazars noted in early 2026, “response windows are shrinking, and decisions about resilience can no longer sit siloed in the security operations centre.” Artificial intelligence has handed threat actors a powerful set of automation tools: reconnaissance, social engineering, and lateral movement, all accelerated and increasingly beyond human intervention timescales.

For boards, this compression of time creates a critical governance problem. The traditional cadence of quarterly reporting is structurally misaligned with an attack environment measured in minutes. Boards need to ask hard questions: Do we have real-time visibility into our threat posture? Is our crisis response plan current, tested, and genuinely practised rather than simply documented?

IMD’s Global Board Centre has highlighted that the best boards in 2026 are those that are “more robust, forward-looking, and organised than ever before,” utilising digital technology to simulate potential governance challenges and anticipate, rather than merely react to, emerging threats. Scenario planning is no longer optional. Neither is having at least one director with genuine cyber fluency who can ask the right questions, challenge management assumptions, and translate technical risk into board-level decision-making.

Ransomware remains a primary vector, with attackers now targeting backup systems before deploying their final payload. Supply chain vulnerabilities have widened the attack surface considerably. And the regulatory environment is tightening and cybersecurity governance is now explicitly framed as a leadership responsibility, not a technical function. Australian directors should note that the Australian Signals Directorate (ASD) and the Australian Cyber Security Centre (ACSC) have similarly escalated their expectations for board-level accountability under the revised Security of Critical Infrastructure Act.

The ISC2 GRC survey found that many executives still treat cybersecurity governance as a “check box” activity. In 2026, that approach carries real personal liability risk, not just organisational risk.

Governing AI: From Enthusiasm to Accountability

If cyber governance is challenging, AI governance is more complex still. The technology is moving faster than most regulatory frameworks, and boards are under pressure from two directions at once: pressure to adopt AI rapidly for competitive advantage, and pressure to demonstrate that adoption is responsible and controlled.

Gartner forecasts that 40% of enterprise applications will feature task-specific AI agents by the end of 2026. Yet research cited by Palo Alto Networks shows that only 6% of organisations have an advanced AI security strategy in place. That adoption gap, between deployment velocity and governance maturity, is precisely where board exposure lives.

The accountability question is crystallising. As noted in Harvard Business Review, “the question of who is responsible when AI goes wrong will move from a philosophical debate to a matter of legal precedent, creating a new standard of direct personal executive liability.” Boards that have waved through AI investment without interrogating the governance architecture around it are building exposure they may not yet see.

What does meaningful AI governance look like from a board perspective? At minimum, it requires understanding what AI systems the organisation is utilising, including shadow AI adopted without IT or legal oversight. Microsoft’s 2026 Cyber Pulse report found that more than 80% of Fortune 500 companies now use AI agents built with low-code or no-code tools, often by employees outside technical functions. This is not a technology problem. It is a governance and culture problem that lands squarely on the board agenda.

Boards need to be asking: Do we have a centralised AI registry? Are AI systems subject to the same risk management disciplines as other enterprise risks, with clear ownership, documented risk tolerances, and regular review? Are we exposed to “AI washing” risk, where claims about our AI capability do not hold up to scrutiny? The SEC has identified AI-related disclosures as a focus area for FY2026 examinations, and its Investor Advisory Committee has recommended enhanced disclosures on how boards oversee AI governance as part of managing material cybersecurity risks.

Internationally, the EU AI Act is the most significant regulatory development. Even for Australian companies with European operations or customers, its influence is substantial. It is establishing a global baseline for what responsible AI governance looks like. The newly released ISO/IEC 42001 for AI Management Systems standard is gaining traction as a benchmark that boards and regulators alike are beginning to reference. Organisations that cannot demonstrate this level of rigour will increasingly struggle to satisfy their boards, insurers, and regulators simultaneously.

The Questions Every Board Should Be Asking Right Now

Governance is ultimately about asking the right questions at the right time. As a director and advisor, I work with boards to move beyond passive reporting and into active, informed oversight. For cyber and AI, the foundational questions include:

  • Do we have a current, board-approved cyber risk appetite statement, and does it connect to our enterprise risk framework? 
  • Is cybersecurity a standing agenda item, or does it only appear when something goes wrong? 
  • Have we completed a simulation exercise in the past twelve months that tested our actual crisis response? 
  • Can management show us every AI system currently in use across the organisation, including those adopted informally? 
  • Who is accountable when an AI system causes harm to a customer, an employee, or a third party? 
  • How are we managing the risk of AI-enabled misinformation about our own company?

These questions are the minimum standard of informed stewardship that stakeholders now expect from directors.

Coming in Part Two: CSR and the Changing Accountability Landscape

In my next article, I will examine the third pillar of this governance challenge: corporate social responsibility, sustainability reporting, and the growing gap between what companies say and what stakeholders are prepared to accept. The backlash against ESG in some markets has created a new complexity for boards, specifically how to govern genuine social and environmental responsibility in a politicised environment, while managing the legal and reputational risk of greenwashing.

The stakes in 2026 are high across all three domains. Boards that govern with courage, curiosity, and rigour will be better positioned than those waiting for clarity that may never arrive.


About: Gary Morgan is a director, board advisor and principal consultant at MPT Innovation Group, specialising in governance, technology strategy, and organisational transformation for private and not-for-profit organisations. He is a Fellow and Member of the Queensland State Council of the Governance Institute of Australia, and an Adjunct Industry Fellow and Member of the Griffith University Industry Advisory Board for the ICT School. Gary publishes regularly on board governance, AI, technology, and cybersecurity.

Acknowledgment:  This article represents the author’s independent views and incorporates AI-assisted research and drafting.


References and Sources

  1. Forvis Mazars. (2026). Cybersecurity in 2026: Responsible AI Defence
  2. IMD Global Board Centre. (2025). Cyber Security Trends 2026 – Board Strategy
  3. Harvard Business Review. (2025). 6 Cybersecurity Predictions for the AI Economy in 2026
  4. Microsoft Security. (2026). 80% of Fortune 500 Use Active AI Agents: Observability, Governance, and Security Shape the New Frontier
  5. CyberSaint. (2026). The Top Security, Risk, and AI Governance Frameworks for 2026
  6. ISC2. (2026). GRC Challenges and Opportunities: Shift from Threat to Risk as a Core Consideration
  7. Wilson Sonsini Goodrich & Rosati. (2026). 2026 Year in Preview: AI Regulatory Developments for Companies to Watch Out For
  8. Corporate Compliance Insights. (2026). 2026 Operational Guide to Cybersecurity, AI Governance & Emerging Risks
  9. Just Security. (2026). Key Trends That Will Shape Tech Policy in 2026
  10. Australian Signals Directorate / ACSC. Security of Critical Infrastructure Act 2018 (Cth) — Board Obligations

en_AUEnglish