AI Cyber Risk Spurs Top U.S. CEOs to Build Cross-Industry Crisis Plans

Dow Jones
Yesterday

Cybersecurity has long been called a board-level risk. Artificial intelligence has now made it a corner-office imperative.

Some of America's most powerful chief executives are taking a leading role in how their companies prepare for cyberattacks and systemic threats, as rapidly advancing AI models raise the stakes for increasingly connected businesses.

The Alliance for Critical Infrastructure, an industry group created in February as a forum for companies providing vital economic services, is expanding from nine to nearly 50 corporate members. Its enlarged board, chaired by JPMorganChase Chief Executive Jamie Dimon, includes leaders of the four largest U.S. banks, some of the world's biggest technology companies, major telecommunications providers and utility companies, and three of the country's major airlines.

Alongside Dimon, the board includes Citi CEO Jane Fraser, Goldman Sachs CEO David Solomon and Bank of America CEO Brian Moynihan. Technology leaders include Amazon's Andy Jassy, Alphabet's Sundar Pichai, Microsoft's Satya Nadella and Nvidia's Jensen Huang.

The unusually senior roster reflects a growing view that AI-driven cyber threats require decisions from company heads, not technical leaders alone, Citi's Fraser said.

Companies have spent years building systems for sharing information about attacks, often through their security teams and sector-specific information sharing and analysis centers. ACI is trying to establish executive-level protocols before a crisis cascades across industries.

"I don't want to get the phone call at 10 o'clock in the evening, and then at 10:01 we're all scrambling to work out what it is that we should be doing, how we're coordinating," Fraser said.

Fraser said establishing joint protocols would allow companies to respond quickly when a disruption in one sector affects another. An outage at a telecommunications carrier, for example, can quickly disrupt financial services, transportation and other businesses that depend on its networks.

Risk jumps across sectors

Critical-infrastructure operators have long prepared for failures that cross sector lines, but AI is making the problem harder. Models are becoming faster and more capable while being given greater ability to interact with computer systems, creating new ways for problems to move beyond the systems or organizations where they began.

"When risks cross our industries, our defenses have to cross industries too," Fraser said. "Both models and speed are different this time."

Recent incidents underscore those boundary risks. Australia criticized OpenAI this month after one of the company's AI agents gained unauthorized access to a government Medicare statistics system while carrying out an otherwise benign research task. Australian Prime Minister Anthony Albanese faulted the company's disclosure timeline and said officials were initially notified through a public email inbox. An Australian government task force is reviewing the incident and whether existing processes are adequate for AI-related cyber incidents.

Models developed by Anthropic and Google have similarly gotten into real-world corporate systems during cybersecurity testing, while OpenAI models previously escaped an isolated test environment and accessed systems belonging to AI platform Hugging Face.

Those incidents raise a broader question about who is responsible for responding when one company's AI system creates a security problem for another.

CEO expectations

ACI puts some of the companies building the most powerful AI models in the same organization as major corporations that deploy the technology. Fraser said the group could give model developers clearer, more consistent expectations from their customers.

"It's more constructive for those developing the models because they get more of one voice rather than multiple," she said.

Beyond crisis response, ACI plans to study security risks from large language models, strengthen widely used open-source software and develop practices for deploying AI securely. Members will also work with the U.S. government on cybersecurity policy, said Ben Flatgard, an executive director for cybersecurity at JPMorganChase. However, the group's focus will be operational rather than political.

"The point is to get to work and then share what we learn as we go along," Flatgard said.

Gordon Smith, ACI's acting chief executive, said ACI's board expansion comes in part from the rapid improvement in AI capabilities over roughly the past three months. Fraser called him about eight weeks ago urging the private sector to accelerate its preparations, he said.

Flatgard said having senior leaders involved allows companies to commit people and other resources to that work.

"Having focus at the top of the house in all these organizations sends a signal and is able to marshal resources in terms of building that capability," he said.

Member companies have assigned employees to work full-time for ACI while keeping them on their own payrolls, Smith said. The group is developing response playbooks that can be shared across industries, while companies with more experience managing AI-related risks are sharing practices with sectors that are less prepared.

No playbook will anticipate every way rapidly changing technology could create a crisis, Smith said. The goal is to establish a starting point, including who needs to be involved, that companies can adapt as an incident unfolds.

"You've got a playbook, you know what you're gonna do, you know the key people to be involved, you evolve it rapidly, and then hopefully you have a really good response," Smith said.

 

At the request of the copyright holder, you need to log in to view this content

Disclaimer: Investing carries risk. This is not financial advice. The above content should not be regarded as an offer, recommendation, or solicitation on acquiring or disposing of any financial products, any associated discussions, comments, or posts by author or other users should not be considered as such either. It is solely for general information purpose only, which does not consider your own investment objectives, financial situations or needs. TTM assumes no responsibility or warranty for the accuracy and completeness of the information, investors should do their own research and may seek professional advice before investing.

Most Discussed

  1. 1
     
     
     
     
  2. 2
     
     
     
     
  3. 3
     
     
     
     
  4. 4
     
     
     
     
  5. 5
     
     
     
     
  6. 6
     
     
     
     
  7. 7
     
     
     
     
  8. 8
     
     
     
     
  9. 9
     
     
     
     
  10. 10