Every enterprise CFO faces two fast-moving, high-stake risks: cybersecurity and artificial intelligence (AI). Cyber risk has decades of history and a mature response playbook. AI risk is newer, expanding exponentially, and already generating multi-billion-dollar losses.
2️⃣ Cyber Risk – Billions in Impact, Incremental Growth
Cyber has been on CFO and board agendas for more than 20 years. According to the FBI IC3 reports, U.S. businesses lost $6.9 billion (2021) rising to more than $16 billion (2024) in reported cybercrime. (FBI Internet Crime Report 2024) Cyber’s mature profile includes:
- Risks: ransomware, phishing, supply-chain exploits, insider threats
- Frameworks: NIST, ISO, and cyber-insurance markets (>$20 billion annual premiums)
- Reality: Threats evolve, but quantification tools, insurance, and reporting frameworks are established.
3️⃣ AI Risk – Emerging with Exponential Growth
AI failures are only beginning to surface, cutting across operations, compliance, and capital markets. AI’s emerging risks include:
- Operational: incorrect outputs, robotic accidents, bad advice
- Legal / Compliance: bias, biometric privacy, copyright infringement
- Financial / Market Cap: sudden valuation shocks in the hundreds of billions
As adoption accelerates, CFOs must extend risk analysis with frameworks to understand their financial reality.
4️⃣ Quantitative Comparison
The following two graphs provide valuable insights into the losses generated by cyber and AI failures.

📊 Graph A – Economic (i.e. non-Market Cap) Losses (Billions USD)
In the U.S., the FBI IC3 data (blue bars) shows cybercrime steadily growing. AI failures (orange bars), sourced from BleederBoard.ai, are less predictable but already material in scale. Public reporting on AI failures remains incomplete, thus losses are likely understated. Nevertheless, CFOs must quantify the losses in financial statements and explain them on investor calls.

📊 Graph B – Economic + Market-Cap Impacts (Billions USD)
The red bars (with right y-axis) show how market cap impacts out-scale economic losses. Boardrooms demand more AI adoption, yet CFOs are rightfully hesitant. Even the best and brightest have been impacted. Management teams must adapt.
5️⃣ The Path Forward
Cyber provides the playbook: form a team, partner with experts, establish executive visibility, and allocate resources to top threats. AI requires a parallel framework, one that extends beyond model risk management through to covering the generative risk.
The AI risk blast radius is expanding faster and less predictably than cyber. The race to deploy AI must include risk quantification and reserves for inevitable failures. The path forward includes new methodologies to compete.
Call to Action: Develop financial quantification of AI risk in your 2026 budgets. Teaching teams to price AI risk enables benchmarking and consistent decisions on business cases.
Get started here


Comments are closed