SecurityBrief UK - Technology news for CISOs & cybersecurity decision-makers
United Kingdom
AXA XL urges stronger governance as AI adoption surges

AXA XL urges stronger governance as AI adoption surges

Tue, 6th Oct 2026 (Today)
Raphael Veloso
RAPHAEL VELOSO News Editor

AXA XL and S-RM have published a report on priorities for resilient AI adoption, warning that many organisations are embedding AI into core business processes faster than they are strengthening governance and security.

Titled Building Resilient AI: Managing AI risk through governance, security and resilience, the report argues that companies should treat AI risk as an enterprise resilience issue rather than one confined to technology teams or compliance functions.

It cites research from McKinsey & Company showing that 88% of organisations now use AI in at least one business function. Against that backdrop, AI is creating new entry points for cyber threats while also introducing operational, regulatory and third-party risks.

The main concerns include data leakage, model manipulation, prompt injection, unreliable outputs, shadow AI and overly autonomous agents. Those risks increase as AI systems gain wider access to sensitive data, business applications and decision-making processes.

Five priorities

The report sets out five priorities for business leaders: establishing clear accountability for AI across the enterprise; protecting sensitive data and tightening identity and access controls; and managing AI risk across the full lifecycle, from data collection and model development to deployment, monitoring and incident response.

It also calls for stricter governance and due diligence over AI vendors and other critical third parties. In addition, it urges organisations to prepare for AI-related loss scenarios that may span cyber, fraud, liability and business interruption, as well as multiple areas of insurance cover.

Jonathan Salter, Head of Risk Consulting at AXA XL, said the debate has moved beyond trial use of AI tools.

"AI is moving from experimentation into the systems and processes organisations rely on every day, but governance is not always keeping pace," Salter said.

"The organisations best placed to capture AI's value will be those that know where it is being used, understand the business consequences when it fails, and build security and resilience into deployment from the outset."

Rebiah Bardot-Girard, Head of Cyber Risk Consulting Services at AXA XL, said AI risk often compounds problems companies already face elsewhere in the business.

"AI risk rarely emerges in isolation," Bardot-Girard said.

"It amplifies existing weaknesses in identity management, data governance, supplier oversight and incident readiness. A practical inventory of where AI is used, what data it can access, and where it can take or influence action is now a fundamental starting point for resilience."

Oversight gaps

Some companies are improving their controls. The report cites World Economic Forum data showing that 64% of organisations now assess the security of AI tools before deployment, up from 37% a year earlier.

Even so, it argues that pre-deployment checks alone are insufficient. Once AI systems are in use, organisations remain exposed unless oversight continues through deployment, operation and incident response.

That reflects a broader shift in how companies use AI. What began as limited experimentation in selected teams is increasingly moving into systems linked to sensitive information, business workflows and decision-making, making governance failures harder to contain.

Design and controls

Alongside the five priorities for leaders, the report outlines five foundations for secure AI by design: strong data governance, secure models and applications, ecosystem resilience, robust access controls and continuous monitoring.

The emphasis on identity, access and third-party oversight suggests concern not only about internally developed systems but also about AI tools embedded in software bought from suppliers. Organisations need visibility over formal deployments, software features that incorporate AI, and shadow AI adopted without central approval.

For risk managers and insurers, the findings underline the difficulty of separating AI-related incidents into neat categories. A single event may trigger cyber, fraud, liability or operational consequences at the same time, particularly when systems can act autonomously or influence human decisions.

AXA XL is the property, casualty and specialty risk division of AXA, while S-RM is a cybersecurity and intelligence consultancy. The two groups said their combination of risk consulting, cyber expertise and insurance insight can help organisations strengthen governance, test incident scenarios, and make decisions on mitigation and risk transfer.

The report's central message is that businesses need a clearer inventory of where AI is deployed, what data it can access, and what actions it can affect as adoption spreads further into day-to-day operations.