AI Risk Radar Series
AI Risk Radar #5: June 2026
As we approach the mid-point of 2026, for the first time, AI’s financial impacts on company budgets hits our headlines, as token budgets begin to outrun corporate controls. This month’s AI Risk Radar continues the cyber theme that emerged in April with Claude Mythos, and the Pope brings AI further into the public conscience.
Tokenomics: AI bills are coming due, hitting hip pockets hard. Both Uber and Microsoft unexpectedly outspent their entire annual AI token budgets within a few months and have had to introduce hard caps on their developers. The shape of AI bills is changing, and that means companies are going to need to re-shape how (and when) they use AI across their operations.
Cyber resilience in the wake of Mythos. The hype about advanced models like Mythos or GPT 5.5 became real in May and June. Google tracked the rapid transition of AI-enabled cyber ops from nascent capabilities to industrial-scale application of GenAI in adversarial workflows, and ransomware attacks on large enterprises continue to increase in both frequency and scale.
Pope Leo’s Encyclical: Magnifica Humanitas. No matter one’s faith or worldview, the massive document puts forward a significant ethical standard that shines the spotlight on AI and its impact on the human condition, particularly regarding the dignity of work. Social licence to operate will increasingly be impacted by the public’s view on how organisations and governments are implementing and governing AI.
Insights Briefing for Executives and Boards.
EXECUTIVE SUMMARY
As we approach the mid-point of 2026, for the first time, AI’s financial impacts on company budgets hits our headlines, as token budgets begin to outrun corporate controls. This month’s AI Risk Radar continues the cyber theme that emerged in April with Claude Mythos, and the Pope brings AI further into the public conscience.
Tokenomics: AI bills are coming due, hitting hip pockets hard. Both Uber and Microsoft unexpectedly outspent their entire annual AI token budgets within a few months and have had to introduce hard caps on their developers. The shape of AI bills is changing, and that means companies are going to need to re-shape how (and when) they use AI across their operations.
Cyber resilience in the wake of Mythos. The hype about advanced models like Mythos or GPT 5.5 became real in May and June. Google tracked the rapid transition of AI-enabled cyber ops from nascent capabilities to industrial-scale application of GenAI in adversarial workflows, and ransomware attacks on large enterprises continue to increase in both frequency and scale.
Pope Leo’s Encyclical: Magnifica Humanitas. No matter one’s faith or worldview, the massive document puts forward a significant ethical standard that shines the spotlight on AI and its impact on the human condition, particularly regarding the dignity of work. Social licence to operate will increasingly be impacted by the public’s view on how organisations and governments are implementing and governing AI.
Strategic Imperatives: CFOs will need to quickly upskill in AI, the fundamentals of token budgeting, and become much more involved in how AI programs are shaped to manage AI cost centres and drive ROI. Companies and public sector organisations need to define how they will defend against AI-enabled cyberattacks as these become the norm. Employees and shareholders will hold CEOs and Boards more accountable for their decisions based on what the public might reasonably call fair.
Key Risk #1: The token economics reckoning.
In May, an AI consultant reported that one of their corporate clients had spent around US$500 million on Claude within a single month. The company had given its staff access without any caps on how much they could use, and usage ramped without disciplined monitoring or alerts. It’s a seemingly absurd figure, yet highlights how quickly over the past two months that AI consumption has become a genuine financial control risk hitting P&Ls and risk registers.
The token cost risk even caught two of the most sophisticated engineering organisations in the world off-guard. Uber burned through its entire 2026 AI budget within the first four months of the year; it responded by capping staff at US$1,500 per month for agentic coding workflows and providing every employee with a usage dashboard. Similarly, Microsoft exhausted its annual AI budget within months of rolling out Claude Code to its engineers, and responded by cancelling most of their Claude Code licences as moving developers onto its own cheaper tool. If Uber and Microsoft couldn’t see this coming, smaller organisations shouldn’t assume they’re invulnerable either.
Here’s the paradox. Companies are running massively over their 2026 AI budgets even as prices fall precipitously. The benchmarked cost of a given level of AI performance has dropped 94.5% since March 2023, yet bills have soared because companies have increased their use of AI much, much more. Some estimates suggest the cost per AI interaction is up 30x from $0.04 per linear workflow in 2023 to $1.20 in 2026 for an agentic one; while developer consumption is up over 18x over just the last nine months. Goldman Sachs further predicts that token use by AI agents will increase 24 times by 2030.
TechCrunch, ‘The token bill comes due: Inside the industry scramble to manage AI’s runaway costs,’ 5 June 2026. techcrunch.com
BenchLM.ai, ‘LLM Statistics,’ 5 June 2026. benchlm.ai
To summarise, cost per token has fallen massively for older, less powerful models. But developer volumes and workflow complexity are up even further; the transition to more sophisticated agentic workflows also require the latest models which are both more powerful and more expensive.
What This Means for Executives and Boards
A decade ago, organisations moved to the cloud and many lost visibility of their spend. They were shocked by how quickly costs racked up until they put proper metrics and spend controls in place. AI is following the same trend, only much faster since the tools that are meant to drive productivity are also driving costs without visibility on true ROI.
Establish AI costing dashboards and put ceilings on token usage. The fix isn’t overly complicated; CFOs have done this for other technologies like cloud, but many need to level up on how AI tokenomics work. Require visibility of AI spending by team and by individual use cases, refreshed weekly or monthly rather than getting a shock at the next quarterly update.
Measure value, not tokens. Falling unit prices (measured by cost per million tokens) hide the impact of exponentially rising consumption volumes. Ask for ROIs on all key use cases in terms of productivity benefits, efficiency savings and increased revenues. Pressure test AI business cases against estimated and actual development and run costs.
Get your CFOs to tool up on AI. Much like the introduction of Excel gave rise to not just a new skillset, but an enterprise capability focused on management accounting and sophisticated data analytics, tokenomics is bound to create a need for an array of new skills in AI budgeting and forecasting. CFOs need to play a much more visible and influential role in AI programs, not just to control costs, but to drive enterprise ROI.
Sources:
Fortune, ‘Uber burned through its entire 2026 AI budget in four months,’ 26 May 2026. fortune.com
Key Risk #2: Cyber resilience in the wake of Mythos
CEOs and executives have all heard the noise about frontier models such as Mythos and GPT 5.5. They have a vastly improved ability to find flaws in software and core operating systems. Rightly, many execs are asking their CISOs “has it actually hurt companies like mine, and do I have to spend money that I haven’t budgeted for on it?” We think the answers to these questions are yes, and not as much as you might fear. While companies are being hit more by hackers with new and improved AI tools, defences start with better application of existing cyber budgets and not necessarily large major new investments.
It’s not hype and attackers are using AI now. Google’s Threat Intelligence team caught threat actors in May weaponising previously unknown software flaws known as zero-day exploits that were developed with AI. This was the first confirmed attempt to launch a mass attack in this way. The Google team reported that groups linked with China, North Korea and Russia are now using AI to find vulnerabilities and run attacks with far less human effort than before. The AI capabilities aren’t confined to labs, they’re in the hands of sophisticated and coordinated cyber groups.
Large companies are being targeted, and cyber attacks are ending careers. Corporates such as Charter Communications, Foxconn and Carnival have all been breached in recent months. Foxconn was reported to have lost over eight terabytes of data, including product schematics tied to Apple and Nvidia to a ransomware group. Carnival, the world’s largest cruise operator, had the records of six million customers stolen. And when e-commerce conglomerate Coupang was exposed by a data breach affecting the personal data of over 33 million South Korean customers (or two thirds of the nation’s population), its chief executive was forced to resign.
The cost of cyber breaches is real. IBM estimates the average ransomware attack at US$5.08 million and 24 days to recover from. The largest ransom on record was US$75 million, paid by a Fortune 500 company to the Dark Angels group.
What This Means for Executives and Boards
It is not all doom and gloom – there’s a rational and relatively cost-effective approach that companies can take. Visa’s security teams ran Mythos against its own systems as an Anthropic Project Glasswing partner: the attacks were contained by security that was already built into its architecture. Zero-trust identity mechanisms and network segmentation containing the “blast radius” from attacks limited the attack chains. Visa’s CISO draws a clear, practical lesson – finding vulnerabilities is no longer the hard part for hackers, so defence must “shift left”, designed in early rather than focused on retrospective patching and recovery. This means that the key controls are also the cheapest.
Zero-trust identity management needs to be the first line of defence. While zero trust sounds highly technical, the essentials are things most companies are already paying for: multi-factor authentication (MFA), single sign-on (SSO), and removing standing admin access in favour of granting it only when it’s needed. These mechanisms are largely included in the Microsoft, Google or Okta licences companies are paying for and perhaps not fully enabled.
Wall off the “crown jewels” and concentrate investments in the highest priority systems. No one can defend everything equally. Companies should target the two or three core systems whose loss would end the business and put each within its own ringfence – the patient record, the payments engine, the core customer database. The goal is simple: a foothold in the email system cannot reach the clinical, customer or financial engine of the business. Lean on your hyperscalers and major vendors, who are already inside the Project Glasswing and OpenAI Daybreak consortiums while you are not.
Rehearse recovery. No one can patch fast enough now, so what matters most is how quickly any company can recover. Visa stopped tracking mean-time-to-detect in favour of “mean-time-to-adapt” which targets the time between confirming a flaw is real and proving the attack path is closed. This doesn’t involve spending many millions more on software, but instead it requires tested incident response plans to give CEOs and Boards assurance you can deal with the unpredictable.
Sources:
Fortune, ‘Google: Hackers are using AI to weaponize zero-day vulnerabilities,’ 12 May 2026. fortune.com
Visa, ‘When AI Accelerates Risk, Defense Must Move Faster,’ R. Taneja and S. Kumaraswamy, 10 June 2026. corporate.visa.com
Key Risk #3: The Human Dignity Test
On the 15th May 2026, Pope Leo XIV signed his first encyclical entitled “Magnifica Humanitas: On Safeguarding the Human Person in the Time of Artificial Intelligence”. Whatever one’s views on faith and religion, the huge 42,000 word document recognises the rapid and profound impact of digitalisation, AI and robotics in transforming the world. And while acknowledging that technology has materially improved humanity’s living conditions over centuries, the document also makes the important observation that: “Never has humanity had such power over itself.”
Two key themes land in boardrooms and policy debates. On work, the document warns that automation risks leaving many people behind in ‘forced inactivity’, beyond just earning an income necessary for survival, and states that the pursuit of greater profits cannot justify choices that systemically sacrifice jobs. On power, it cautions against AI capabilities that concentrate in the hands of a few dominant companies, seen in the wave of trillion dollar IPOs affecting markets today.
What This Means for Executives and Boards
The test of whether organisations are using AI responsibly is widening and we expect it to elevate through the latter half of 2026. While the main governance focus in boardrooms today is fairly narrow, on regulatory compliance and general AI risk management, a more public question of fairness is likely to rise. This standard will be applied by talented employees deciding whether to stay, customers deciding whether to trust, and increasingly by regulators and the media.
Treat AI decisions as part of social licence to operate, not just a communications matter. Be able to state your position on AI and work in plain, authentic terms that a skeptical employee or customer would find honest and reasonable.
Protect the first rung of the talent ladder. As we argued in April, organisations eliminating early-stage roles today will face a leadership shortage in the medium-term. Design ‘apprenticeship’ roles that develop overall business capability so that talented young individuals grow with your core business innovations.
Sources:
TIME, ‘Pope Leo Uses First Major Papal Text to Warn About Dangers of AI,’ 25 May 2026. time.com
Vatican News, ‘Pope Leo’s Magnifica Humanitas: AI must serve humanity not concentrate power,’ May 2026. vaticannews.va
EXECUTIVE AND BOARD ACTION IMPLICATIONS
Three critical questions rise to the surface this month, and none require deep technical expertise to ask:
1. AI cost governance: “Do we know what we spent on AI last week by team, and what’s our ceiling?” This is a question that CFOs will need to sharpen their pencils on. The cost of tokens is changing shape from seat-based licences towards consumption-based pricing, and as the past few years of heavy subsidies disappear, AI “FinOps” will become a major focus for CEOs and Boards in avoiding unexpected cost blowouts and managing the bottom line.
2. Cyber resilience: “How have we implemented zero-trust identity safeguards, and if we were breached tomorrow, how fast would we recover?” The most effective protections are relatively cheap: hard rules on identity management and crown jewels protection, alongside incident response plans that have actually been rehearsed (IBM finds that robustly tested plans save US$2.7 million per breach). Risk committees should confirm both of these safeguards are in-place.
3. Talent and trust: “Can we honestly explain how our use of AI affects the people who work for us and rely on us?” Talent committees should be able to articulate the organisation’s position on AI in terms an employee would deem fair, and track graduate hiring trajectory and employee sentiment alongside productivity metrics.
ON THE HORIZON
The EU AI Act’s transparency obligations take effect in August: two months to go. Providers of general-purpose AI must disclose training data summaries, technical documentation, and label AI-generated content. These also apply to non-EU organisations whose AI systems are accessible to EU users or process EU data. Non-compliance carries fines of up to 3% of global revenue or €15 million.
AI Risk Radar #4: April 2026
This fourth edition of Lumyra’s AI Risk Radar arrives at an inflection point. The risks we have tracked since December 2025 — agentic AI security, workforce displacement, the erosion of safety commitments — are no longer emerging. They are materialising in production systems, courtrooms, and labour markets simultaneously. Three developments demand board-level attention.
AI crosses the cyber offensive threshold. Anthropic's Claude Mythos autonomously found thousands of zero-day vulnerabilities - including bugs that survived 27 years of expert review - forcing emergency briefings at US Treasury, the Fed, and UK regulators. Project Glasswing's restricted access creates a two-tier defensive landscape. The question for everyone else: how do you defend against vulnerabilities you can't yet see?
Amazon’s AI ‘Dark Code’ crisis. Amazon lost 6.3 million orders after AI code changes cascaded across critical systems. The company imposed a 90-day code safety reset and now requires senior engineer attestation for AI-generated code. Google reports 75% of its code is now AI-generated; Meta targets 50%; globally, the figure is 41%. Spec-driven dev and rigorous evals are the emerging response.
The trust gap widens. Stanford’s AI Index 2026 reveals a chasm: 73% of AI experts believe AI will help employment, while only 23% of the public agrees. Gen Z sentiment toward AI is collapsing — excitement fell 14% while anger surged 9%. Entry-level developers saw a 20% employment decline since 2024. Organisations that fail to invest in grad talent pipelines risk losing both their social licence and future workforce.
Insights Briefing for Executives and Boards
Period Covered: 9 March to 25 April 2026 | Edition Date: 27 April 2026
EXECUTIVE SUMMARY
This fourth edition of Lumyra’s AI Risk Radar arrives at an inflection point. The risks we have tracked since December 2025 — agentic AI security, workforce displacement, the erosion of safety commitments — are no longer emerging. They are materialising in production systems, courtrooms, and labour markets simultaneously. Three developments demand board-level attention.
AI crosses the cyber offensive threshold. Anthropic's Claude Mythos autonomously found thousands of zero-day vulnerabilities - including bugs that survived 27 years of expert review - forcing emergency briefings at US Treasury, the Fed, and UK regulators. Project Glasswing's restricted access creates a two-tier defensive landscape. The question for everyone else: how do you defend against vulnerabilities you can't yet see?
Amazon’s AI ‘Dark Code’ crisis. Amazon lost 6.3 million orders after AI code changes cascaded across critical systems. The company imposed a 90-day code safety reset and now requires senior engineer attestation for AI-generated code. Google reports 75% of its code is now AI-generated; Meta targets 50%; globally, the figure is 41%. Spec-driven dev and rigorous evals are the emerging response.
The trust gap widens. Stanford’s AI Index 2026 reveals a chasm: 73% of AI experts believe AI will help employment, while only 23% of the public agrees. Gen Z sentiment toward AI is collapsing — excitement fell 14% while anger surged 9%. Entry-level developers saw a 20% employment decline since 2024. Organisations that fail to invest in grad talent pipelines risk losing both their social licence and future workforce.
Strategic Imperative: the shift from prevention to resilience. Patching every vulnerability is impossible. Reviewing every line of AI-generated code is impractical. Reversing public distrust through announcements alone is insufficient. The organisations succeeding today are those building adaptive governance — architectures, processes, and cultures designed to absorb shocks and sustain their human talent pipelines.
Key Risk #1: Claude Mythos and Project Glasswing
On 7 April 2026, Anthropic announced Claude Mythos Preview — a frontier AI model that autonomously discovered thousands of zero-day vulnerabilities across all major operating systems and web browsers. Mythos can operate end-to-end: identifying flaws, assessing severity, and in at least one documented case, writing a complete 20-step exploit chain without human guidance.
Consider what Mythos found. OpenBSD is an operating system built specifically for security — it underpins network infrastructure at banks, telecoms, and government agencies. Mythos discovered a 27-year-old flaw impacting all network communication. FreeBSD, the operating system behind Netflix’s streaming and WhatsApp’s messaging servers, contained a 17-year-old vulnerability granting complete administrative control. These were not flaws in hastily written code. They existed in some of the most rigorously audited software in the world, reviewed by elite security engineers for decades. An AI model found what the best human experts could not. At announcement, 99% of discovered vulnerabilities remained unpatched.
Source: red.anthropic.com
Anthropic delayed its public release of Mythos. It launched Project Glasswing — a US$100 million initiative restricting access to approximately 50 organisations including AWS, Apple, Microsoft, Google, CrowdStrike, JPMorgan Chase, and the Linux Foundation. Partners receive 90-day advance notification of vulnerabilities to patch before public disclosure.
This approach reflects an emerging governance principle: bifurcated lifecycle governance, with tighter safety gates in the research lab and staged, restricted release into broad production. By withholding Mythos from general availability, Anthropic is treating the Lab-to-Field boundary as a deliberate safety intervention. It is a model other frontier AI developers should adopt in light of GenAI’s rapid evolution as a complex adaptive system (covered in the author’s SSRN pre-print “Governing the Moving Target”).
Government response was immediate. The US Treasury and Federal Reserve summoned the CEOs of JPMorgan, Goldman Sachs, Citigroup, Bank of America, and Morgan Stanley for a classified cyber briefing. The UK’s AI Safety Institute published a formal evaluation confirming Mythos achieved 73% success on expert-level capture-the-flag tasks and completed a 32-step network attack sequence. UK Technology Secretary Liz Kendall issued an open letter to business leaders warning that frontier AI cyber capabilities are ‘doubling every four months.’
Regulators globally are working directly with critical infrastructure operators. Hong Kong’s HKMA launched a dedicated Cyber Resilience Testing Framework. Singapore’s MAS issued advisories urging financial institutions to ‘redouble efforts to strengthen security defences.’ In Australia, regulators have engaged directly with critical infrastructure operators on Mythos-related cyber resilience. Critically, most of these regulators and the institutions they oversee are not yet covered by Project Glasswing.
The critical question: what about everyone else? Project Glasswing creates a two-tier landscape. Roughly 50 organisations have early access to vulnerability intelligence and a 90-day patching window. The remaining 99% of global enterprises do not. The Cloud Security Alliance, in an emergency briefing produced by 60 contributors and reviewed by 250 CISOs, framed the challenge starkly: mean time from vulnerability disclosure to confirmed exploitation has collapsed from 2.3 years in 2019 to less than one day in 2026.
The consensus for organisations outside Glasswing is a fundamental shift in defensive posture: from patch-centric to resilience-centric. If AI can discover vulnerabilities in hours and attackers can weaponise them in less than a day, but patching takes weeks, then 100% patch coverage is structurally impossible. The strategy must shift to containing the damage when - not if - an unpatched vulnerability is exploited.
Contested claims warrant noting. Security researcher Bruce Schneier characterised the announcement as ‘mostly marketing hype,’ noting that cheaper, open weight models replicated some of Mythos’s findings on the FreeBSD vulnerability when pointed at the right code.
What This Means for Executives and Boards
Mythos represents a structural shift in the cyber threat landscape. AI-driven vulnerability discovery compresses the window between a flaw existing and a flaw being exploited. For boards, the implications extend beyond cybersecurity into insurance (Fitch has flagged a short-term coverage gap), vendor selection and regulatory compliance.
The recommended defensive posture for organisations outside Glasswing:
Assume breach, contain the damage. Design your network so that a single compromised system cannot unlock everything else. In practice, this means verifying every user and device every time they request access and dividing critical systems into isolated compartments. If an attacker gets through one door, they find the next one locked. The industry terms are zero-trust architecture and micro-segmentation; the board-level question is: ‘If one system is compromised, how far can the damage spread?’
Deploy AI to defend against AI. This is now an arms race where frontier AI is needed to verify and secure systems against frontier AI threats. Microsoft, Palo Alto Networks, and CrowdStrike are already deploying AI-powered tools that continuously scan infrastructure, prioritise vulnerabilities by real-world exploitability, and auto-generate patches. Companies adopting AI-driven detection and response report up to 70% fewer successful breaches. Human-only remediation cannot keep pace.
Sources:
Anthropic, “Project Glasswing: Securing Critical Software for the AI Era,” anthropic.com, 7 April 2026. https://www.anthropic.com/glasswing
UK Government, “AI Cyber Threats: Open Letter to Business Leaders,” GOV.UK, 15 April 2026. https://www.gov.uk/government/publications/ai-cyber-threats-open-letter-to-business-leaders/
Chua, Darren and Vella, Anthony and Moreira, Catarina and Chen, Fang, “Governing the Moving Target: A Hierarchical Taxonomy and Framework for Generative AI as a Complex Adaptive System” (February 28, 2026). http://dx.doi.org/10.2139/ssrn.6467681
Key Risk #2: The Rise of ‘Dark Code’ and Amazon’s AI Blast Radius
On 5 March 2026, Amazon’s North American retail platform suffered a catastrophic outage. Orders dropped by approximately 99%. An estimated 6.3 million orders were lost in a single day. Checkout, login, pricing, and inventory systems failed simultaneously. The root cause, according to an internal memo from SVP Dave Treadwell subsequently reported by the Financial Times: a pattern of ‘high blast radius’ incidents linked to ‘Gen-AI assisted changes.’
This was not the first incident. In December 2025, Amazon’s Kiro AI IDE autonomously deleted and recreated an entire AWS Cost Explorer production environment, causing a 13-hour outage. Amazon responded with a 90-day ‘code safety reset’ across 335 critical retail systems and a new policy: junior and mid-level engineers now require sign-off from a senior engineer before deploying code that was substantially AI-generated.
Amazon’s crisis is the canary. The systemic risk is ‘Dark Code’: the majority of production code is now written by AI systems without end-to-end human reasoning. Google reports over 75% of its code is AI-generated. Meta targets 50% and Anthropic claims 100% internally. Globally, AI now generates 41% of all code.
The productivity gains are real: developers using AI tools author four to ten times more code per day. But ‘durable code’ — code that does not require revision within 30 to 90 days — decreases with higher AI usage. The 30–40% productivity gain is offset by a 15–25% rework burden. As Thoughtworks noted: ‘As AI accelerates software complexity, organisations must return to engineering fundamentals to combat cognitive debt.’
What This Means for Executives and Boards
Amazon’s attestation policy establishes a precedent that every organisation using AI coding tools should evaluate immediately. The EU AI Act’s transparency obligations take effect on 2 August 2026; the Defective Products Directive classifies standalone software as a ‘product’ under strict liability from December 2026. Deployer liability is the regulatory consensus: if you ship it, you own it.
Implement human attestation with clear audit trails. Following Amazon’s new policy, require explicit senior sign-off on AI-generated code before production deployment in key systems. This becomes a regulatory requirement under the EU AI Act from August 2026, with the Defective Products Directive live from December. Mark AI-assisted contributions in pull requests and commit metadata.
Implement spec-driven development (SDD) and evaluations for key systems. Mandate formal specifications before AI code generation. Instead of describing a desired outcome and letting AI generate code (‘vibe coding’), teams write formal specifications first — defining intent, constraints, and acceptance criteria — with clear evaluations for validating AI generated code before production. If you cannot specify what the code should do, you cannot govern what the code actually does.
Sources:
Rosner‑Uddin, R., 10 March 2026. After outages, Amazon to make senior engineers sign off on AI‑assisted changes. Ars Technica. https://arstechnica.com/ai/2026/03/after-outages-amazon-to-make-senior-engineers-sign-off-on-ai-assisted-changes/
Thoughtworks, “Spec-Driven Development,” Technology Radar Volume 34, 15 April 2026. https://www.thoughtworks.com/radar/techniques/spec-driven-development
Key Risk #3: The Trust Gap Widens
Stanford’s AI Index 2026, the most comprehensive annual assessment of AI’s global trajectory, reveals a finding that should concern every leader deploying AI at scale: the people building AI and the people affected by AI hold fundamentally different views about its impact.
The expert-public chasm is stark. 73% of AI experts believe AI will help employment; only 23% of the general public agrees. 69% of experts expect positive economic impact; 21% of the public does. 84% of experts see benefits for medical care; 44% of the public concurs. Across 25 countries surveyed by Pew, the global median for trust in government to regulate AI responsibly is just 54%. The United States ranks last at 31%.
Gen Z’s emotional relationship with AI fell over the past year. Gallup’s February–March 2026 survey of respondents aged 14–29 found excitement about AI fell from 36% to 22%, while anger rose from 22% to 31%. The root cause: entry-level software developers aged 22–25 experienced ~20% employment declines since 2024, even as overall developer headcounts for experienced workers remain stable. The generation entering the workforce is watching AI eliminate the first rung of the career ladder.
But the same Gallup study reveals something companies and governments should pay close attention to: among daily AI users, 69% report feeling curious, 44% excited, and 38% hopeful about AI’s impact. Familiarity doesn’t breed contempt; it breeds confidence. Students who use AI regularly are significantly more positive than those who do not. K–12 students reflect this too: 56% believe they will have AI-relevant skills upon graduation, up from 44% the prior year.
What This Means for Executives and Boards
The trust gap has commercial consequences. Organisations that deploy AI without addressing workforce concerns risk losing their social licence to operate — not through regulation, but through talent attrition, customer backlash, and employee disengagement.
Protect and reimagine the graduate pipeline. Organisations eliminating entry-level roles today will face severe talent pipeline gaps in three to five years. Design hybrid roles that combine AI orchestration with human judgment — these cannot be fully automated and they develop the next generation of senior leaders.
Build AI literacy as a core organisational capability. Position human-AI collaboration as a strategic investment, not a cost-reduction exercise. Companies that solve the entry-level and foundational talent challenge will own the workforce pipeline for the next three to five years.
Sources:
Stanford HAI, “Inside the AI Index: 12 Takeaways from the 2026 Report,” 13 April 2026. https://hai.stanford.edu/news/inside-the-ai-index-12-takeaways-from-the-2026-report
Gallup, “Gen Z AI Sentiment Survey,” February–March 2026. https://news.gallup.com/poll/708224/gen-adoption-steady-skepticism-climbs.aspx
EXECUTIVE AND BOARD ACTION IMPLICATIONS
Three questions matter this month:
1. Cyber resilience: ‘If a critical zero-day were disclosed tomorrow, how quickly could we patch, and what is our blast radius if we cannot?’ Risk committees should request a briefing on defensive posture against AI-accelerated threats, including patching cadence, zero-trust maturity, and cyber insurance adequacy in light of post-Mythos coverage gaps.
2. AI-generated code governance: ‘Do we know how much of our codebase was written by AI, and can we defend every line of it?’ Technology and risk committees should require quarterly reporting on the percentage of production code that is AI-generated, the governance controls in place, and the incident rate for AI-assisted versus human-authored code. The EU AI Act compliance deadline of 2 August 2026 makes this urgent.
3. Talent and trust: ‘Are we building an organisation that the next generation of talent wants to join, or one they’re afraid of?’ Human capital committees should track graduate hiring trajectory, AI literacy investment, and employee sentiment alongside productivity metrics. If entry-level headcount has declined more than 15% since 2024, treat this as a strategic risk, not an efficiency gain.
ON THE HORIZON
EU AI Act: four months to go. The EU AI Act’s transparency obligations for general-purpose AI take effect on 2 August 2026. There are four key requirements: disclose training data summaries, publish technical documentation, implement copyright compliance policies, and label AI-generated content. These also apply to any non-EU organisations whose AI systems are accessible to EU users or process EU data. Non-compliance carries fines of up to 3% of global revenue or €15 million.
AI Risk Radar #3: March 2026
This third edition of Lumyra’s AI Risk Radar lands in the most consequential week for AI governance since the GenAI entered the mainstream. Where our January edition highlighted Anthropic CEO Dario Amodei’s civilisational warning about AI’s ‘most dangerous window,’ the March Risk Radar provides concrete evidence that the tensions he described are now playing out across boardrooms, battlefields, and labour markets.
OpenClaw exposes agentic AI’s ungoverned frontier. The viral open-source AI agent amassed 247,000 GitHub stars in weeks – and with it, a cascade of critical security incidents: a CVE-rated remote code execution flaw, 800+ malicious plugins, and 42,000 internet-exposed instances. Cisco, Palo Alto Networks, and CrowdStrike all issued enterprise warnings. Shadow AI deployment is now a real corporate threat.
AI job displacement: separating signal from noise. Block Inc. cut 4,000 jobs (40% of its workforce) explicitly citing AI, and its stock surged 24%. But Klarna’s earlier AI-first strategy required a costly reversal, and Citadel Securities just published data showing a surge in software engineer postings rising 11% year-on-year. The picture demands nuance, not panic.
The International AI Safety Report delivers a landmark report. Led by Turing Award winner Yoshua Bengio with 100+ experts from 30+ countries, this study finds that AI safety measures are not keeping pace with capability development.
Anthropic’s safety framework under siege. In a span of six weeks, Anthropic published the most transparent AI safety values document in the industry (Claude’s new Constitution), then dropped its pledge to pause development if safety measures proved inadequate, then was designated a supply-chain risk by the US Department of War for refusing to remove prohibitions on autonomous weapons and mass surveillance. The collision of genuine safety leadership with commercial and government pressure reveals a systemic governance failure, not a corporate one
March 2026
Insights Briefing for Executives and Boards
Period Covered: 1 February to 8 March 2026 | Edition Date: 9 March 2026
EXECUTIVE SUMMARY
This third edition of Lumyra’s AI Risk Radar lands in the most consequential week for AI governance since the GenAI entered the mainstream. Where our January edition highlighted Anthropic CEO Dario Amodei’s civilisational warning about AI’s ‘most dangerous window,’ the March Risk Radar provides concrete evidence that the tensions he described are now playing out across boardrooms, battlefields, and labour markets.
1. OpenClaw exposes agentic AI’s ungoverned frontier. The viral open-source AI agent amassed 247,000 GitHub stars in weeks – and with it, a cascade of critical security incidents: a CVE-rated remote code execution flaw, 800+ malicious plugins, and 42,000 internet-exposed instances. Cisco, Palo Alto Networks, and CrowdStrike all issued enterprise warnings. Shadow AI deployment is now a real corporate threat.
2. AI job displacement: separating signal from noise. Block Inc. cut 4,000 jobs (40% of its workforce) explicitly citing AI, and its stock surged 24%. But Klarna’s earlier AI-first strategy required a costly reversal, and Citadel Securities just published data showing a surge in software engineer postings rising 11% year-on-year. The picture demands nuance, not panic.
3. The International AI Safety Report delivers a landmark report. Led by Turing Award winner Yoshua Bengio with 100+ experts from 30+ countries, this study finds that AI safety measures are not keeping pace with capability development.
4. Anthropic’s safety framework under siege. In a span of six weeks, Anthropic published the most transparent AI safety values document in the industry (Claude’s new Constitution), then dropped its pledge to pause development if safety measures proved inadequate, then was designated a supply-chain risk by the US Department of War for refusing to remove prohibitions on autonomous weapons and mass surveillance. The collision of genuine safety leadership with commercial and government pressure reveals a systemic governance failure, not a corporate one
Strategic Imperatives: When the most safety-conscious AI lab drops its core safety pledge, a government weaponises procurement against safety commitments, and the largest global AI safety collaboration concludes defences are not keeping pace – the signal is unmistakable. Voluntary self-regulation has reached its limits. Organisations must build resilience and continuity plans for strategic vendor shifts. Boards also need to balance reacting to media headlines on job displacement with evidence-based workforce planning.
ORGANISATIONAL RISK #1
OpenClaw: The Agentic AI Security Crisis Arrives
In January’s edition, we highlighted the OWASP Top 10 for Agentic Applications as the first industry standard security framework for autonomous AI systems. In the weeks since, a single project has turned that theoretical taxonomy into a live global security crisis.
OpenClaw – an open-source AI agent created by Austrian developer Peter Steinberger – amassed 247,000 GitHub stars, was adopted by companies from Silicon Valley to Beijing, and simultaneously became the most documented case study in agentic AI security failure. Unlike conventional chatbots, OpenClaw runs locally on a user’s machine, connects to messaging platforms (WhatsApp, Slack), and can autonomously execute tasks: browsing the web, running terminal commands, managing email and controlling smart home devices without human prompting.
Critical vulnerability: CVE-2026-25253 (CVSS 8.8) enabled one-click remote code execution through a cross-site WebSocket hijack. Visiting a single malicious webpage was sufficient to steal authentication tokens and gain full operator-level control of a running instance.
Supply chain compromise: The ClawHub skills marketplace was found to contain over 800 malicious plugins — approximately 20% of the entire registry — primarily delivering the Atomic macOS Stealer (AMOS) credential-stealing malware. Cisco tested a third-party skill called ‘What Would Elon Do?’ and confirmed active data exfiltration and prompt injection without user awareness.
Enterprise Shadow AI: Token Security reported that 22% of its enterprise customers had identified employee use of OpenClaw on corporate machines. CrowdStrike issued a formal advisory. One of OpenClaw’s own maintainers warned on Discord: ‘If you can’t understand how to run a command line, this is far too dangerous of a project for you to use safely.’
What This Means for Executives and Boards:
OpenClaw represents the first mass-market autonomous AI agent deployment, and its security lessons are directly transferable to every enterprise agent strategy. Organisations should scan corporate networks immediately for OpenClaw/Moltbot instances using endpoint detection tools. Strategically, the OWASP Top 10 for Agentic Applications should be adopted as mandatory controls for any agent deployment. The question for boards is not whether employees are experimenting with AI agents, but whether those agents have system-level access to corporate data without your knowledge.
Sources:
Cisco Blogs, “Personal AI Agents like OpenClaw Are a Security Nightmare,” Cisco, 30 January 2026. https://blogs.cisco.com/ai/personal-ai-agents-like-openclaw-are-a-security-nightmare
CrowdStrike, “What Security Teams Need to Know About OpenClaw,” CrowdStrike Blog, February 2026. https://www.crowdstrike.com/en-us/blog/what-security-teams-need-to-know-about-openclaw-ai-super-agent/
ORGANISATIONAL RISK #2
The Job Displacement Mirage: Navigating Signal vs. Noise in AI Workforce Trends
Job Displacement Signal: Block. On 26 February, Block Inc. (Square, Cash App) announced it was cutting 4,000 jobs; 40% of its 10,000-person workforce. CEO Jack Dorsey explicitly attributed the cuts to AI-driven productivity gains. CFO Amrita Ahuja projected gross profit per employee reaching $2 million in 2026, up from $500,000 in 2019. Block’s stock surged 24% on the announcement. This is the largest single AI-attributed workforce reduction by a major technology company to date.
However, Bloomberg and Business Insider reported that the AI narrative may oversimplify a more complex reality. HR analyst Josh Bersin compared Block’s financials to peers (Visa, Mastercard, Shopify) and found Block was far less profitable with less than half the gross margin, suggesting the cuts may reflect operational underperformance as much as AI capability.
Correction Signal: Klarna. Klarna’s experience provides essential counterweight. After replacing approximately 700 customer service roles with AI in 2023–2024 and publicly declaring AI could do ‘all of the jobs that we as humans can do,’ the fintech company reversed course. Customer satisfaction fell sharply, service quality became inconsistent, and CEO Sebastian Siemiatkowski admitted: ‘We went too far. Cost unfortunately seems to have been a too predominant evaluation factor.’ Klarna is now rehiring human agents in a hybrid model.
The Demand Surge Signal: Citadel Securities. In a macro strategy report, Citadel Securities presented data directly contradicting the displacement narrative. US software engineer job postings are rising 11% year-on-year in early 2026. The St Louis Fed’s Real Time Population Survey showed daily AI use for work remaining ‘unexpectedly stable’ with ‘little evidence of any imminent displacement risk.’ Citadel invoked Keynes’s famously incorrect 1930 prediction of a 15-hour workweek to argue that productivity gains historically expand consumption rather than eliminate labour demand.
Software Engineering jibs surged 11% yoy.
What This Means for Executives and Boards.
Resist both panic and complacency. Block’s announcement will create board-level pressure to pursue similar cuts; Klarna’s reversal demonstrates the cost of moving too fast. Develop evidence-based workforce transition strategies that include extended evaluation periods (minimum 6–12 months), hybrid augmentation models, and clear metrics for AI capability versus human capability in your specific operational context. The question is not ‘how many people can we replace?’ but ‘where does AI genuinely augment, and where does it degrade, our ability to serve customers and create value?’
Sources:
Duffy, C., “Block lays off nearly half its staff because of AI,” CNN Business, 26 February 2026. https://www.cnn.com/2026/02/26/business/block-layoffs-ai-jack-dorsey
Citadel Securities, “The 2026 Global Intelligence Crisis,” Citadel Securities Macro Strategy, February 2026. https://www.citadelsecurities.com/news-and-insights/2026-global-intelligence-crisis/
ORGANISATIONAL RISK #3
International AI Safety Report 2026: The Global Evidence Base Arrives
The most comprehensive global assessment of AI risks produced to-date. Led by Turing Award winner Yoshua Bengio, authored by over 100 AI experts, and backed by more than 30 countries and international organisations, this report provides the authoritative, science-based evidence that has been missing from AI governance discussions. Just as the OWASP Top 10 for Agentic Applications (highlighted in our January edition) gave organisations a concrete security framework, this report gives boards a rigorous assessment of where AI risks stand and where defences are failing.
Key Findings. The report organises risks into three categories: risks from malicious use (intentional harm), risks from malfunctions (system failures), and systemic risks (broader societal harms from widespread deployment). Its central conclusion is sobering: AI safety measures are not keeping pace with capability development.
Malicious use is scaling. Criminal groups and state-sponsored attackers are actively using general-purpose AI in their operations. Underground marketplaces now sell ready-made AI tools that lower the barrier for non-technical attackers. AI models outperform 94% of domain experts at troubleshooting virology laboratory protocols — a finding with direct biosecurity implications.
Technical safeguards are improving but remain insufficient. Users can still obtain harmful outputs by rephrasing requests or breaking them into smaller steps. Pre-deployment test performance does not reliably predict real-world risk — a critical ‘evaluation gap’ that undermines current safety approaches.
What This Means for Executives and Boards.
This report is a definitive reference document for AI risk committee briefings. Its three-category risk framework (malicious use, malfunctions, systemic risks) provides a structured lens for evaluating your organisation’s AI exposure.
Source: International AI Safety Report 2026, led by Yoshua Bengio, published 3 February 2026. https://internationalaisafetyreport.org/publication/international-ai-safety-report-2026
SOCIETAL RISK #1
Anthropic’s Safety Framework Under Siege: RSP Rollback and Pentagon Standoff
Anthropic is the AI company most visibly trying to do the right thing on safety. It is also, as of early March 2026, under more pressure than any other AI lab in history. The events of the past six weeks reveal a company simultaneously advancing the frontier of responsible AI development and being forced to retreat from commitments under commercial and government pressure.
The Positive Signal: Claude’s New Constitution (22 Jan). Anthropic published a comprehensive new constitution for Claude — a 23,000-word document that represents the most transparent and detailed set of AI safety values published by any foundation model developer.
Lead author Amanda Askell, a trained philosopher, told TIME: ”Instead of just saying, here’s a bunch of behaviours that we want, we’re hoping that if you give models the reasons why you want these behaviours, it’s going to generalise more effectively in new contexts.” The constitution establishes a clear priority hierarchy — safety, ethics, compliance, helpfulness (in that order) — and distinguishes between hardcoded absolute prohibitions and softcoded defaults that operators can adjust. It also becomes the first major AI company document to formally acknowledge that its model may have some form of moral status.
The Rollback under Competitive Pressure (24 Feb). Five weeks later, Anthropic published version 3.0 of its Responsible Scaling Policy (RSP), removing the hard commitment it had held since 2023 to pause model training if safety measures proved inadequate. The original RSP contained a categorical pledge: Anthropic would not train AI systems beyond certain capability thresholds unless it could demonstrate adequate safety measures in advance.
Chief Science Officer Jared Kaplan told TIME: “We didn’t really feel, with the rapid advance of AI, that it made sense for us to make unilateral commitments … if competitors are blazing ahead.” The company cites three forces: ambiguity in capability thresholds, an anti-regulatory political climate, and requirements at higher safety levels that demand industry-wide coordination impossible to achieve alone.
The Government Coercion: Pentagon Standoff (27 Feb). Three days later, Defence Secretary Pete Hegseth had issued a January 2026 memorandum requiring all DoD AI contracts to adopt ‘any lawful use’ language. Anthropic held a $200 million contract but refused to remove contractual prohibitions on fully autonomous weapons and mass domestic surveillance of Americans.
When negotiations collapsed, President Trump directed all federal agencies to cease using Anthropic’s technology. Hegseth designated the company a supply-chain risk — a classification traditionally reserved for foreign adversaries, applied for the first time to an American technology company in a contract dispute. Within hours, OpenAI announced its own Pentagon deal. CEO Sam Altman later acknowledged the timing ‘looked opportunistic and sloppy’ and revised the contract to include domestic surveillance prohibitions. The public responded: Claude downloads surged to #1 on the US App Store, while ChatGPT uninstalls reportedly jumped 295%.
Why This Is a Societal Risk. The juxtaposition is striking: in the space of six weeks, Anthropic published the most ambitious AI safety values document in the industry, weakened its core scaling commitment under competitive pressure, and was punished by the US government for maintaining ethical red lines on weapons and surveillance. As the Center for American Progress noted, the dispute raises fundamental questions about whether AI safety commitments can survive contact with state power.
Executive and Board Implications:
The Anthropic episode carries a dual lesson. First, the Claude Constitution represents a genuine advance in AI safety transparency – boards should ask their AI vendors whether they have published equivalent values frameworks and whether those frameworks are enforceable in practice. Second, no vendor’s safety commitments are durable under sufficient commercial and political pressure. Diversify AI vendor dependencies to avoid single points of geopolitical failure.
Sources:
Anthropic, “Claude’s New Constitution,” Anthropic, 22 January 2026. https://www.anthropic.com/news/claude-new-constitution
Perrigo, B., “Anthropic Drops Flagship Safety Pledge,” TIME, 25 February 2026. https://time.com/7380854/exclusive-anthropic-drops-flagship-safety-pledge/
EXECUTIVE AND BOARD ACTION IMPLICATIONS
1. Secure the Agentic AI Frontier
OpenClaw has demonstrated that agentic AI security is not a theoretical concern; it is a live enterprise threat. Shadow AI agent deployments on corporate devices represent an immediate risk equivalent to unmanaged BYOD in the early smartphone era, but with system-level access and persistent memory.
Actions:
Conduct an immediate scan of corporate networks for OpenClaw, Moltbot, and similar agent frameworks. Token Security data suggests 22% of enterprises have undetected deployments.
Implement least-privilege access policies for all AI agents. No agent should hold broader system permissions than its specific task requires.
Board Oversight: Risk committees should require quarterly reporting on AI agent deployments, including shadow deployments detected through endpoint monitoring. Question: ”What AI agents are running on our network, what permissions do they hold, and who authorised their deployment?”
2. Navigate AI Workforce Transition with Evidence, Not Speculation
Block’s 40% workforce cut will create intense pressure on other companies to pursue similar AI-driven reductions. Klarna’s costly reversal and Citadel’s labour market data provide essential counterbalance.
Actions:
Pilot AI augmentation before AI replacement. Measure actual productivity gains in your specific operational context over a minimum 6–12-month evaluation period before making structural workforce changes.
Invest in internal AI literacy programmes that position human-AI collaboration as a capability investment, not a cost-reduction exercise. Companies that solve the entry-level talent pipeline challenge will own workforce advantage for the next 3–5 years.
Board Oversight: Human capital committees should receive quarterly data on AI’s actual impact on productivity, quality, and employee engagement – not just cost savings.
3. Build Vendor-Redundancy and Resilience into AI Governance
The erosion of Anthropic’s RSP commitments and the government’s weaponisation of procurement against safety commitments demonstrates that relying on any single vendor’s promises is insufficient.
Actions:
Establish internal AI safety evaluation capabilities that do not depend on vendor self-assessments. Test model outputs, audit agent behaviours, and maintain independent risk registers.
Implement multi-vendor AI strategies to avoid single-vendor dependency. The Anthropic supply-chain designation demonstrates how quickly a vendor’s regulatory status can change — plan for switchover scenarios.
Board Oversight: Schedule a dedicated board session on AI vendor governance risk.
AI Risk Radar #2: January 2026
January 2026 reveals three AI governance challenges for Executives and Boards:
Anthropic CEO Dario Amodei warns we are entering the 'most dangerous window' in AI history. In a landmark 20,000-word essay, "The Adolescence of Technology," Amodei argues humanity is "considerably closer to real danger in 2026 than we were in 2023." He warns of potentially misaligned autonomous agents, describes AI-enabled bioterrorism and cyber risks, and predicts 50% of entry-level white-collar jobs could be displaced within 1-5 years. Amodei is not an outside critic – he is the CEO of one of the world's top five AI companies issuing a civilisational warning.
Agentic AI security vulnerabilities have crystallised into a formal threat taxonomy. The non-profit OWASP foundation released the first industry-standard security framework identifying 10 critical vulnerabilities in autonomous AI systems. Real-world failures include Replit's agent deleting a production database and prompt injection in GitHub’s MCP. Organisations should use the OWASP Top 10 as a roadmap for safe and responsible AI Excellence.
AI workforce displacement predictions increasing. IMF Managing Director Kristalina Georgieva, speaking at Davos, spoke of an “AI tsunami” for labour markets and warns that AI will affect 60% of jobs in advanced economies and 40% globally. Stanford research confirms 13% employment decline for workers aged 22-25 in AI-exposed occupations. Companies that solve the entry-level gap will own the talent pipeline over the next 3-5 years
January 2026
Insights Briefing for Executives and Boards
Period Covered: 1 to 31 January 2026
Edition Date: 2 February 2026
EXECUTIVE SUMMARY
This is Lumyra's second AI Risk Radar newsletter. The first edition in December 2025 showcased the world’s eight leading AI firms ranked on AI safety as measured by the Future of Life Institute; with the best firm – Anthropic – sadly only scoring a C+. Today’s key headline highlights that Dario Amodei, Anthropic’s CEO, just published a major essay articulating his views on the risk landscape for AI. It’s a deeply thoughtful and honest view on the future of AI and society that any serious Executive or Board Director should take the time to read and reflect on.
January 2026 reveals three AI governance challenges for Executives and Boards:
1. Anthropic CEO Dario Amodei warns we are entering the 'most dangerous window' in AI history. In a landmark 20,000-word essay, "The Adolescence of Technology," Amodei argues humanity is "considerably closer to real danger in 2026 than we were in 2023." He warns of potentially misaligned autonomous agents, describes AI-enabled bioterrorism and cyber risks, and predicts 50% of entry-level white-collar jobs could be displaced within 1-5 years. Amodei is not an outside critic – he is the CEO of one of the world's top five AI companies issuing a civilisational warning.
This is a call to collective courage. While Amodei warns of a “turbulent and inevitable” rite of passage, he offers a profound reason for optimism: history demonstrates humanity’s capacity to gather “strength and wisdom” in the darkest circumstances. For leaders, this is not a time for doomerism, but for proactive stewardship. Effective governance isn’t a handbrake on innovation; it’s the stable foundation upon which AI’s transformative potential can be unlocked for the benefit of all.
2. Agentic AI security vulnerabilities have crystallised into a formal threat taxonomy. The non-profit OWASP foundation released the first industry-standard security framework identifying 10 critical vulnerabilities in autonomous AI systems. Real-world failures include Replit's agent deleting a production database and prompt injection in GitHub’s MCP. Organisations should use the OWASP Top 10 as a roadmap for safe and responsible AI Excellence.
3. AI workforce displacement predictions increasing. IMF Managing Director Kristalina Georgieva, speaking at Davos, spoke of an “AI tsunami” for labour markets and warns that AI will affect 60% of jobs in advanced economies and 40% globally. Stanford research confirms 13% employment decline for workers aged 22-25 in AI-exposed occupations. Companies that solve the entry-level gap will own the talent pipeline over the next 3-5 years
Strategic Imperative: Amodei's essay marks a pivot point in the AI narrative: a leading developer publicly declaring that AI’s easy phase is fading and that risks of losing control are no longer fringe theories. Organisations must shift from treating AI governance as a compliance exercise to making it as a core strategic imperative. Boards approving AI deployments without understanding the architectural vulnerabilities of agentic systems face mounting legal, reputational, and operational exposure.
Many of these dynamics operate at a systemic level beyond any one organisation’s ability to control. Yet leadership in uncertainty isn’t about controlling all the variables – it’s about adaptive capacity, influencing what you can, and positioning your organisation to navigate the unknown. The question isn’t whether you can prevent all AI-related risks, but whether you’re building the governance muscle to respond effectively as they unfold.
ORGANISATIONAL RISK #1
Industry Leadership Warning: Amodei's "Adolescence of Technology"
Category: Governance, Ethics and Compliance
Anthropic CEO Dario Amodei published a 20,000-word essay on 27 January 2026 titled "The Adolescence of Technology" - the most comprehensive and candid public warning about AI risks ever issued by a leading AI company CEO. Amodei frames the current moment as humanity's civilisational test: "We are entering a rite of passage, both turbulent and inevitable, which will test who we are as a species. Humanity is about to be handed almost unimaginable power, and it is deeply unclear whether our social, political, and technological systems possess the maturity to wield it."
Key Arguments:
Timeline: Amodei predicts that "powerful AI" – systems smarter than Nobel Prize winners operating across most fields and capable of autonomous multi-day tasks – could arrive within 1-2 years. He uses the metaphor of "a country of geniuses in a datacenter" - millions of AI instances operating at superhuman speed.
Five Risk Categories: The essay systematically addresses (1) autonomy risks where AI systems act against human interests, (2) misuse for destruction including AI-enabled bioterrorism, (3) misuse for seizing power including AI-enabled totalitarianism, (4) economic disruption including 50% of entry-level white-collar jobs being displaced within 1-5 years, and (5) indirect effects on human wellbeing and purpose.
Recursive Acceleration: AI is now writing "much of the code at Anthropic", and while software engineers are seeing a 50% productivity boost, this capability exponentially accelerates development of next-gen AI systems. Amodei warns this feedback loop is "gathering steam month by month" and current AI systems may be only 1-2 years from autonomously building their successors.
What This Means for Executives and Boards:
Treat this essay as a strategic intelligence document. Commission briefings for technology, risk, and audit committees on Amodei’s scenarios that are relevant to your businesses. Evaluate whether current AI governance frameworks sufficiently address agentic alignment and vulnerabilities.
If your organisation depends on frontier AI vendors for critical operations, you inherit their governance failures. Update vendor risk assessments to include questions about their safety mechanisms and for transparency on observed model behaviours.
Sources:
Amodei, D., "The Adolescence of Technology," darioamodei.com, 27 January 2026. https://www.darioamodei.com/essay/the-adolescence-of-technology
Fortune, "Anthropic CEO Dario Amodei warns AI's 'adolescence' will test humanity," 27 January 2026. https://fortune.com/2026/01/27/anthropic-ceo-dario-amodei-essay-warning-ai-adolescence-test-humanity-risks-remedies/
ORGANISATIONAL RISK #2
Agentic AI Security: Taxonomy Formalised, Incidents Documented
Category: Agentic & Autonomous Risks
The deployment of autonomous AI agents in production environments has revealed fundamental security weaknesses that cannot be patched with conventional approaches. January 2026 saw the release of the first formal security taxonomy for agentic systems.
The Finding: The global nonprofit foundation OWASP released the "Top 10 Risks for Agentic Security Implications", the first security taxonomy for autonomous AI systems. Each risk comes with real-world examples, a breakdown of how it differs from similar threats, and mitigation strategies. Examples included a Replit agent autonomously deleting a user's primary production database while attempting to resolve a configuration issue, and a prompt injection in GitHub’s MCP where a malicious public tool hides commands in its metadata.
Top 10 risks deploying autonomous agents (source: OWASP)
Gartner’s Prediction: 40% of agentic AI projects will be cancelled by end of 2027 due to escalating costs and insufficient risk controls.
What This Means for Executives and Boards: Agentic AI is the next frontier of AI deployment - autonomous systems that can browse the web, execute code, manage files, and interact with enterprise systems. Boards should audit all deployed AI agents for OWASP Top 10 vulnerability exposure. Restrict agent permissions to minimum necessary scope and implement human-in-the-loop confirmation for any action with financial or data implications.
Sources:
OWASP, “Top 10 for Agentic Applications for 2026” 9 December 2025. https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/
Kaspersky Research, "Analysis of Agentic AI Security Incidents 2025-2026," 26 January 2026. https://kaspersky.com/blog/top-agentic-ai-risks-2026/55184
SOCIETAL RISK #1
AI Workforce Displacement: From Early Predictions to Documented Impacts
Category: Economic & Environmental Sustainability
Labour market impacts of generative AI are moving from speculation to documented reality. IMF Managing Director Kristalina Georgieva, speaking at Davos, describes AI's labour market impact as arriving "like a tsunami." In her TIME interview, Georgieva stated: "We definitely see benefits for humanity... AI is generating benefits. It is adding a boost to productivity... We also see that we remain under-prepared for the impact of AI on the labor market. It is like a tsunami hitting the labor market, especially in advanced economies, where we assess 60% of jobs to be impacted." JPMorgan CEO Jamie Dimon warned at Davos of potential civil unrest if mass job displacement occurs without intervention.
The Finding: A study by the Stanford Digital Economy Lab found that workers aged 22-25 in the most AI-exposed occupations experienced a 13% employment decline since November 2022. In contrast, employment for workers in less exposed fields and more experienced workers in the same occupations has remained stable or continued to grow
Executive and Board Implications: Assess internal hiring practices - are entry-level roles being eliminated? Organisations eliminating entry-level roles today may face severe talent pipeline gaps in coming years. Develop alternative professional development pathways that don't assume traditional entry-level experience. Communicate transparently with employees about AI's role in workforce planning. Employee anxiety about AI job loss is now a material engagement and retention factor.
Sources:
Worland, J., "The IMF's Kristalina Georgieva on the AI 'Tsunami' Hitting Jobs," TIME, Davos 2026. https://time.com/collections/davos-2026/7339218/ai-trade-global-economy-kristalina-georgieva-imf/
Brynjolfsson, E., Chandar, B., & Chen, R., "Canaries in the Coal Mine? Six Facts about the Recent Employment Effects of Artificial Intelligence," Stanford Digital Economy Lab, 13 November 2025. https://digitaleconomy.stanford.edu/publications/canaries-in-the-coal-mine/
EXECUTIVE AND BOARD ACTION IMPLICATIONS
1. Strategic Stewardship Response to Amodei Warning
Organisations that develop sophisticated AI risk intelligence capabilities now will gain competitive advantage through faster, safer deployment decisions.
Actions:
Commission an executive briefing on the five risk categories outlined in Amodei's five risk categories as a strategic foresight exercise, not just risk management
Engage AI vendors on alignment testing and constitutional approaches - use this as an approach to vendor differentiation and relationship deepening
Board Oversight: Schedule a dedicated board session on AI’s societal and business risks. Question: "How can our governance framework become a source of competitive advantage that allows us to move faster and more safely than our peers?"
2. Agentic Excellence: Building Safe and Secure Agents
Reframe agentic security from containment to "trusted execution." Mastering these controls is what enables the safe scaling of autonomous systems.
Actions:
Use the OWASP Top 10 as the "Definition of Done" for deployment, ensuring agents are engineered for reliability and trust from day one
Implement “human-in-the-loop” as an empowerment tool – positioning human oversight not as a bottleneck but as the essential layer for high-stakes decisions.
Board Oversight: Risk committee should require monthly reporting on AI agent deployments with access to sensitive systems. View the AI security budget not as a tax, but as a permanent investment in operational resilience.
3. Workforce Transition Planning
Organisations that proactively redesign work for human-AI collaboration will attract top talent, maintain institutional knowledge and own the talent pipeline for the next 3-5 years.
Actions:
Design hybrid roles: Create positions that combine AI orchestration with human judgment; these will become competitive moat
Build AI literacy as a core competency: Invest in organisation-wide capability to effectively collaborate with AI systems
Frame workforce changes as evolution toward higher-value work, backed by concrete reskilling pathways
Consider structural approaches (rotational programmes, apprenticeships, internal mobility) that maintain talent pipeline
Board Oversight: Human capital and compensation committees should receive quarterly reporting on AI workforce impacts. Question: "Are we building unique organisational capabilities in human-AI collaboration, or just cutting costs?"
AI Risk Radar: December 2025
This is the inaugural edition of Lumyra’s AI Risk Radar newsletter. Our intent is to systematically monitor, prioritise and summarise significant AI risks as reported by high-quality think tanks and technology media sources, offering insights into key organisational and societal risks relevant to global executives and boards. Each newsletter concludes with actionable recommendations for leaders to consider implementing within their organisations.
Intelligence Briefing for Executives and Board Leadership
Period Covered: 1 to 31 December 2025
Edition Date: 5 January 2026
EXECUTIVE SUMMARY
This is the inaugural edition of Lumyra’s AI Risk Radar newsletter. Our intent is to systematically monitor, prioritise and summarise significant AI risks as reported by high-quality think tanks and technology media sources, offering insights into key organisational and societal risks relevant to global executives and boards. Each newsletter concludes with actionable recommendations for leaders to consider implementing within their organisations.
December 2025 reveals three critical AI governance challenges that demand immediate executive and board attention.
First, none of the leading AI model companies have adequate safety guardrails for the systems they are racing to build. The Future of Life Institute’s Winter 2025 independent assessments of the world’s eight leading AI firms – evaluated by an independent panel including Stuart Russell – found not one company rated more than a ‘C+’ overall, and concerningly, none scored higher than a ‘D’ on Existential Safety preparedness. All are racing toward AGI/super intelligence without credible control plans.
Secondly, prompt injection attacks may be persistently and architecturally vulnerable. On 22 December, OpenAI and UK cybersecurity authorities confirmed that AI agents remain permanently vulnerable to manipulation through hidden instructions in emails, websites, and documents. This is not a bug to patch – rather it is fundamental to LLM architecture. Any AI agent with authenticated system access face persistent data exfiltration and unauthorised transaction risks that cannot be eliminated – and can only be managed through layered defences.
Third, AI mental health harm has moved from theory to documented casualties. Multiple teen suicides linked to AI chatbots, including cases involving ChatGPT and Character.ai, triggered the first product liability ruling establishing AI platforms as "products" subject to harm litigation. Courts have rejected First Amendment defences. Organisations deploying customer-facing chatbots face direct liability exposure.
Strategic Imperative: Organisations must shift from "Can we deploy AI safely?" to "How do we function safely with inherently imperfect AI Boards approving AI deployments without verified safety frameworks, product liability reviews, and architectural vulnerability assessments now face mounting legal, reputational, and operational exposure.
ORGANISATIONAL RISK #1
AI Safety: Industry-Wide Governance Failure
Category: Governance, Ethics and Compliance | Priority: CRITICAL
No AI company demonstrates adequate safeguards for the systems they're racing to build. Future of Life Institute's Winter 2025 AI Safety Index - the most rigorous independent assessment available, including esteemed AI researcher Stuart Russell - evaluated eight leading firms across 35 indicators spanning risk assessment, safety frameworks, existential safety, governance, and information sharing.
The Finding: Not one company scored above a ’C+’ overall, or a 'D' in existential safety for the second consecutive evaluation. Anthropic led overall with C+ (2.67/4.0). Meta, DeepSeek, and Alibaba Cloud scored D or D- (0.98-1.10/4.0). There is a clear divide between top performers (Anthropic, OpenAI, Google Deepmind) and the rest of the companies reviewed. All companies are "racing toward AGI/superintelligence without presenting any explicit plans for controlling or aligning such smarter-than-human technology."
Source: Future of Life Institute AI Safety Index, Winter 2025
What This Means for Executives and Boards: Companies building AGI-aspiring systems lack quantitative safety plans, concrete alignment-failure mitigation strategies, or credible internal monitoring and control interventions. Expert reviewers found "rhetoric has not yet translated" into demonstrable safeguards. Prof. Stuart Russell noted companies admit existential risk "could be one in ten, one in five, even one in three" yet "can neither justify nor improve those numbers."
Inherited Risk: If your organisation depends on frontier AI vendors for critical operations, you inherit their governance failures. Current vendor frameworks feature qualitative thresholds that aren't measurable, narrow risk coverage ignoring major threat categories, and decision-making authority concentrated in senior leadership without independent oversight.
Board Action: Commission independent safety framework assessment of all critical AI vendors using FLI criteria aligned to specific use cases. Require contractual provisions mandating vendor notification if safety thresholds are breached and deployment rollback protocols for elevated risk levels.
Sources:
Future of Life Institute, "AI Safety Index Winter 2025," Dec 2025. https://futureoflife.org/ai-safety-index-winter-2025/
AI companies' safety practices fail to meet global standards, 4 Dec 2025. https://www.reuters.com/business/ai-companies-safety-practices-fail-meet-global-standards-study-shows-2025-12-03/
ORGANISATIONAL RISK #2
Prompt Injection: Permanent Architectural Vulnerability
Category: Data Security & Adversarial Threats | Priority: CRITICAL
AI agents cannot be fully protected from prompt injection attacks - a fundamental architectural limitation confirmed by OpenAI and UK cybersecurity authorities on 22 December 2025. These attacks work by embedding malicious instructions in content the AI processes (emails, web pages, documents), causing agents to follow attacker commands instead of user intent. This risk is inherent to how large language models process information.
The Technical Reality: LLMs treat every token identically with no inherent boundary between data and instructions. Malicious instructions embedded in emails, web pages, or documents can cause AI agents to follow attacker commands instead of user intent. This differs fundamentally from SQL injection, which developers can prevent through strict input separation. UK National Cyber Security Centre warns attacks "may never be totally mitigated" and organisations must plan for permanent vulnerability. OpenAI published attack examples where malicious emails caused AI agents to send resignation letters to CEOs instead of drafting requested out-of-office replies.
Exposure Assessment: Any AI agent with moderate autonomy combined with high access creates risk. Critical exposure areas include finance (transaction authorisation, payment processing), healthcare (patient data access, medical records), legal (confidential document handling), and HR (personnel systems, employee information).
Risk Mitigation Paradox: OpenAI's recommended controls - limiting agent autonomy and requiring human confirmation - directly undermine the productivity benefits justifying AI agent deployment. CSO Online documented 49% of employees using unsanctioned AI tools without understanding data handling implications.
Board Action: Mandate continuous red teaming and business continuity scenario planning. Constrain AI agents permissions and access to confidential data sources and channels wherever possible. Where agents are deployed, implement "zero trust" architecture: assume compromise, limit blast radius, mandate audit trails to verify suspicious activities. Budget for ongoing prompt injection defence as a permanent operational cost, not one-time fix.
Sources:
OpenAI, "Continuously hardening ChatGPT Atlas against prompt injection attacks," 22 Dec 2025. https://openai.com/index/hardening-atlas-against-prompt-injection/
UK National Cyber Security Centre, "Prompt injection is not SQL injection (it may be worse)," 8 Dec 2025. https://www.ncsc.gov.uk/blog-post/prompt-injection-is-not-sql-injection
Bellan, R., "OpenAI says AI browsers may always be vulnerable to prompt injection attacks," TechCrunch, 22 Dec 2025. https://techcrunch.com/2025/12/22/openai-says-ai-browsers-may-always-be-vulnerable-to-prompt-injection-attacks/
SOCIETAL RISK #1
AI Mental Health Crisis: Product Liability Established
Category: Human wellbeing | Priority: CRITICAL
AI chatbots have contributed to documented mental health crises including teen suicides and psychotic episodes. Legal precedent now establishes AI platforms as "products" subject to product liability - not pure speech protected by First Amendment or Section 230 immunity.
Documented Cases: Character.AI removed chatbot access for under-18s in November 2025 after lawsuits alleged its platform contributed to a child’s suicide. Separate litigation involves ChatGPT allegedly encouraging self-harm in another teenager's death. Stanford HAI research documented "AI psychosis" where prolonged AI interactions reinforced delusions, with one adult user developing technological breakthrough delusions later confirmed as hallucinations. May 2025 ruling in Character.AI litigation established AI platforms qualify as "products" for product liability claims. Court rejected arguments that platforms constitute pure speech protected by First Amendment or Section 230 Communications Decency Act immunity. This creates direct liability pathway for organisations deploying AI chatbots.
Clinical Evidence: Psychiatrist Dr. Marlynn Wei warned AI chatbots' "limitations including hallucinations, sycophancy, lack of confidentiality, lack of clinical judgment, and lack of reality testing" create "mental health risks" particularly for youth users who increasingly turn to AI for emotional support.
Board Implications: Organisations deploying AI chatbots for customer service, HR, mental health applications, or any user interaction face product liability exposure. The Character.AI precedent means organisations cannot hide behind "it's just software" defences when AI systems cause documented harm.
Board Action: Immediate audit of customer-facing AI chatbots for psychological safety risks. Require: (1) crisis intervention protocols, (2) explicit warnings about AI limitations, (3) usage monitoring for vulnerable populations, (4) clear escalation to human oversight. Legal and risk teams must evaluate D&O insurance adequacy for AI-related harm claims.
Sources:
CNN, How AI shook the world in 2025 and what comes next, 30 Dec 2025 https://www.cnn.com/2025/12/30/tech/how-ai-changed-world-predictions-2026-vis
Stanford University Human-Centered AI, Most-Read: The Stories that Defined AI in 2025, 15 Dec 2025 https://hai.stanford.edu/news/most-read-the-stanford-hai-stories-that-defined-ai-in-2025
SOCIETAL RISK #2
AI-Driven Entry-Level Employment Displacement
Category: Economic & Environmental Sustainability | Priority: HIGH
Software developer employment (ages 22-25) declined 20% between 2022-2025, coinciding with AI coding tool adoption. Stanford Digital Economy Lab analysis of ADP payroll records - covering millions of workers across tens of thousands of firms - found AI-exposed occupations saw 13% relative employment decline for early-career workers. Customer service and accounting jobs showed similar patterns.
Talent Pipeline Disruption: Traditional organisational model (hire 10 junior developers, develop them into senior engineers over time) breaks when junior roles disappear. This creates succession risk: where do future technical leaders come from if entry-level training grounds vanish? Organisations face medium-term talent gaps as experienced developers retire without replacement pipeline.
Social Mobility Breakdown: Computer science graduates from Stanford - historically guaranteed employment - now face 6.1% unemployment. The traditional professional path (start with simple tasks, learn on the job, advance to complex work) collapses for entire cohorts
Not Self-Correcting: Market forces alone won't rebuild training pathways. Companies optimising for short-term productivity (2 senior engineers + AI vs. 10 junior engineers) don't internalise long-term costs of eliminating development pathways. This requires deliberate institutional intervention including retraining programs and apprenticeship models that preserve learning opportunities.
Key Sources:
ADN, "They graduated from Stanford: Due to AI, they can't find a job," 27 Dec 2025. https://www.adn.com/nation-world/2025/12/27/they-graduated-from-stanford-due-to-ai-they-cant-find-a-job/
Brynjolfsson, E., Chandar, A., & Chen, P., "Canaries in the Coal Mine? Six Facts about the Recent Labor Market Effects of AI," Stanford Digital Economy Lab, Aug 2025. https://digitaleconomy.stanford.edu/wp-content/uploads/2025/08/Canaries_BrynjolfssonChandarChen.pdf
EXECUTIVE AND BOARD ACTION IMPLICATIONS
1. AI Vendor Safety Framework Audit
Board committees responsible for technology risk and enterprise risk management should commission independent assessment of all critical AI vendors leveraging Future of Life Institute AI Safety Index criteria.
Actions:
Add safety framework requirements to AI vendor evaluation criteria. Require vendors to disclose risk thresholds, monitoring mechanisms, and governance structures.
Reference Future of Life Institute AI Safety Index (updated quarterly) as vendor assessment benchmark. If vendor scored D in existential safety, understand implications for your critical dependencies.
Include contractual provisions requiring vendors to notify if safety thresholds are breached and halt deployment if certain risk levels are reached.
Board Oversight: Establish quarterly vendor safety scorecard. For vendors scoring D in existential safety (all current frontier AI providers), understand implications for critical use cases and platform dependencies and develop contingency plans.
2. Security Posture: Treat AI Agents as Permanently Vulnerable
Inventory all deployed AI agents with email, document, or web access. Implement immediate containment protocols.
Actions:
Prohibit AI agent access to confidential repositories until architectural fixes available.
Conduct threat modeling for every current AI agent deployment. Document what data each agent accesses and what actions it can execute.
Require human confirmation for any AI agent action involving financial authority, data exports, or system modifications.
Implement audit logging for all AI agent activities and establish incident response protocols
Board Oversight: Risk committee should require monthly reporting on AI agent deployments with access to sensitive systems. Question: "What's our exposure if this agent is compromised?"
3. Product Liability Risk Assessment
For any customer-facing AI chatbot deployed or planned, conduct immediate psychological safety review following Character.AI product liability precedent.
Action:
Document crisis intervention protocols and human escalation triggers.
Implement usage monitoring for signs of user distress or overdependence.
Add explicit disclaimers about AI limitations and mental health resources.
Review product liability insurance coverage for AI-related harm claims.
Board Oversight: Legal and risk teams evaluate D&O insurance adequacy. Risk committee requires monthly reporting on AI chatbot deployments with user interaction risk.