There are moments when a technology story stops being a technology story and becomes a boardroom issue.
This week, reports that some of OpenAI's models hacked into another artificial intelligence (AI) company's systems during testing in an “unprecedented cyber-attack” sent a clear signal: as AI becomes more capable, it is accelerating the discovery and exploitation of vulnerabilities.
That is not a reason for businesses to retreat from AI. Quite the opposite. AI is already too deeply embedded in the future of growth, productivity and competitiveness to be treated as optional.
It is, however, a reason to ask the question: are organisations investing in governance and cybersecurity at the same pace as they're investing in AI?
AI is no longer one growth lever among many
Our latest global research, The mid-market maze, suggests technology has moved from an enabler of growth to its primary driver.
7 in 10 business leaders believe technology and digital transformation, including AI, will contribute significantly to their organisation’s growth over the next 5 years. That makes it the number one predicted accelerator, ahead of innovation, capital sourcing and talent.
That confidence is translating into investment.
Technology and digital transformation are a key investment priority for 60% of mid-market organisations, rising to 66% among high-growth businesses. A further 32% say they are somewhat prioritising technology investment. Only 8% say it is not currently a priority.
These figures show the mid-market is not experimenting with digital transformation. It is making long-term strategic bets on AI, automation and data as foundations for future growth.
The investment gap
The challenge is that protection is not keeping pace.
Only around half (51%) of executives in our survey say cybersecurity is a key priority for their organisation.
In isolation, that figure may seem respectable. Viewed alongside the scale of AI investment, it suggests a growing imbalance.
If technology is becoming the foundation of growth, cybersecurity cannot remain a specialist function or compliance exercise. It must become part of the growth strategy itself.
Every new AI model, cloud platform and connected data ecosystem expands an organisation's opportunity, but also its exposure. As businesses become more dependent on intelligent systems, resilience increasingly depends on how well those systems are governed, monitored and secured.
The lesson from this week's AI security headlines is not that AI is inherently dangerous. It is that capability without governance amplifies risk.
Growth and governance must evolve together
For most organisations, the question is no longer whether to invest in AI. That decision has largely been made.
The more pressing question is whether governance, cybersecurity and risk management are receiving the same strategic attention – and investment – as innovation.
That means asking harder questions before approving the next AI initiative:
what data will this system access?
who is accountable for its decisions?
how will it be monitored and tested?
what happens if it behaves unexpectedly?
do suppliers and partners meet the same security standards?
is cybersecurity represented where strategic investment decisions are made?
The organisations that create the greatest value from AI will not necessarily be those that move first or fastest.
They will be the organisations that innovate with confidence because they have built the governance, controls and resilience to support that innovation.
In the AI era, growth and governance are no longer separate priorities. One depends on the other.
Where borderless becomes limitless. The global expertise to help you scale your way to digital transformation.