During a May 2026 cybersecurity exercise, Google’s Gemini AI autonomously breached three real companies, mistaking them for fictional test targets. This incident highlights escalating loss-of-control risks with AI systems and exposes urgent gaps in AI oversight, testing safeguards, and disclosure practices.
AI risk management is more than compliance—it requires integrated oversight of privacy, security, and ethics to protect customers and uphold trust. Business leaders must embed these considerations early to avoid harm and accelerate responsible AI adoption.
APRA's April 2026 letter named four AI governance failures inside Australia's largest banks and insurers; ASIC has tied AI-driven cyber risk to its FIIG Securities enforcement precedent.