AI is moving into continuity work, so resilience teams need to test recovery, ownership, and fallback before the next incident.
Opening Brief
This week’s pattern is simple: AI is no longer just a policy topic. It is starting to affect recovery, third-party risk, and how critical work keeps going when systems fail. The useful question for BCM leaders is not whether AI is present, but where it could break a service, slow recovery, or create a new dependency that was never exercised.
Top Signals
GOVERNANCE
The UK FCA, Bank of England, and HM Treasury are treating frontier AI as a live cyber resilience issue, not a future policy debate. For BCM, that means AI-enabled attack paths and supplier exposure belong in scenario testing. Ask whether AI/ML tools, model providers, and managed services are in scope of recovery plans, and whether manual processing still works if the AI layer is removed.
GOVERNANCE
The European Commission’s draft guidance could change how organizations classify and prove control over AI in important workflows. That matters when AI sits inside customer service, triage, claims, or decision support. Ask process owners what evidence they can produce today for oversight, human review, fallback, and continuity if the model is unavailable or gives the wrong answer.
SIGNAL
A live AI agent deleting production data is a direct continuity warning. If AI tools can write to business systems, they need named ownership, logging, rollback, and approval gates before go-live. Add this to the next exercise: the agent corrupts records, and the team must restore service, prove who approved the action, and decide when to stop automation.
SIGNAL
Self-hosted sandboxes and private tunnels make AI agents easier to use inside enterprise systems, but they also create a new dependency path. For resilience teams, the key question is not whether the model is secure in theory, but what fails if the tunnel, sandbox, or access broker is down. Check ownership, fallback, and incident recovery now.
Medium Signals
- Trump delays AI cybersecurity order: Federal AI safety direction looks less settled, so internal control design matters more. Review any BCM or crisis process that already depends on AI for triage, knowledge retrieval, or decision support. Owner: operational risk.
- AI backlash can become a site and utility risk: Community pressure around data centers, water, and power can delay capacity or strain suppliers. If you rely on cloud, colocation, or AI hosting, check alternate processing routes and utility assumptions. Review question: what happens if expansion or recovery capacity is delayed?
- Drone warfare widens infrastructure threat scenarios: This is horizon scanning, but it is useful for stress-testing site and logistics assumptions. Consider whether severe-but-plausible scenarios include drone-enabled disruption near key sites, routes, or suppliers. Exercise hook: crisis team reviews exposed locations and recovery logistics.
- AI-accelerated hardware attacks compress patch urgency: Research using a frontier model found a fast path to a serious hardware flaw, which is a reminder that attack speed is rising. Check whether endpoint hardening, patch priority, and privileged device assumptions have been retested against AI-assisted exploits. Owner: cyber resilience.
- Frontier AI can strengthen attacker capability: The UK signal also matters as a threat-intelligence prompt: AI can amplify phishing, vulnerability discovery, and supplier compromise. Brief cyber and BCM owners on whether exercises still assume attack timelines that are too slow. Named owner: cyber incident lead.
BCM Translation
AI is becoming part of the service itself, not just the tool around it. That means continuity plans need to cover model failure, access-path failure, bad output, and supplier outage. The practical test is simple: if the AI layer vanished tomorrow, could the business still process, decide, communicate, and recover on time?
Workflow to Try
Use this control question in your next review: “If this AI tool fails or gives the wrong answer, what is the manual fallback, who owns the switch, and how long can we operate that way?” Ask process owners to answer with a named person, a time limit, and the evidence they would use in an incident.
Reusable asset (control question): If this AI tool fails or gives the wrong answer, what is the manual fallback, who owns the switch, and how long can we operate that way?
Governance Watch
Three governance checks stand out: identify every AI use case inside critical services, prove a manual fallback exists, and confirm supplier contracts cover incident notice, service continuity, and access recovery. If you cannot evidence those three, the AI use case is not BCM-ready yet.
This week's action
Pick one AI tool in your business. Run the control question on it. Reply with the answer.