AI Risk Radar #5: June 2026
Insights Briefing for Executives and Boards.
EXECUTIVE SUMMARY
As we approach the mid-point of 2026, for the first time, AI’s financial impacts on company budgets hits our headlines, as token budgets begin to outrun corporate controls. This month’s AI Risk Radar continues the cyber theme that emerged in April with Claude Mythos, and the Pope brings AI further into the public conscience.
Tokenomics: AI bills are coming due, hitting hip pockets hard. Both Uber and Microsoft unexpectedly outspent their entire annual AI token budgets within a few months and have had to introduce hard caps on their developers. The shape of AI bills is changing, and that means companies are going to need to re-shape how (and when) they use AI across their operations.
Cyber resilience in the wake of Mythos. The hype about advanced models like Mythos or GPT 5.5 became real in May and June. Google tracked the rapid transition of AI-enabled cyber ops from nascent capabilities to industrial-scale application of GenAI in adversarial workflows, and ransomware attacks on large enterprises continue to increase in both frequency and scale.
Pope Leo’s Encyclical: Magnifica Humanitas. No matter one’s faith or worldview, the massive document puts forward a significant ethical standard that shines the spotlight on AI and its impact on the human condition, particularly regarding the dignity of work. Social licence to operate will increasingly be impacted by the public’s view on how organisations and governments are implementing and governing AI.
Strategic Imperatives: CFOs will need to quickly upskill in AI, the fundamentals of token budgeting, and become much more involved in how AI programs are shaped to manage AI cost centres and drive ROI. Companies and public sector organisations need to define how they will defend against AI-enabled cyberattacks as these become the norm. Employees and shareholders will hold CEOs and Boards more accountable for their decisions based on what the public might reasonably call fair.
Key Risk #1: The token economics reckoning.
In May, an AI consultant reported that one of their corporate clients had spent around US$500 million on Claude within a single month. The company had given its staff access without any caps on how much they could use, and usage ramped without disciplined monitoring or alerts. It’s a seemingly absurd figure, yet highlights how quickly over the past two months that AI consumption has become a genuine financial control risk hitting P&Ls and risk registers.
The token cost risk even caught two of the most sophisticated engineering organisations in the world off-guard. Uber burned through its entire 2026 AI budget within the first four months of the year; it responded by capping staff at US$1,500 per month for agentic coding workflows and providing every employee with a usage dashboard. Similarly, Microsoft exhausted its annual AI budget within months of rolling out Claude Code to its engineers, and responded by cancelling most of their Claude Code licences as moving developers onto its own cheaper tool. If Uber and Microsoft couldn’t see this coming, smaller organisations shouldn’t assume they’re invulnerable either.
Here’s the paradox. Companies are running massively over their 2026 AI budgets even as prices fall precipitously. The benchmarked cost of a given level of AI performance has dropped 94.5% since March 2023, yet bills have soared because companies have increased their use of AI much, much more. Some estimates suggest the cost per AI interaction is up 30x from $0.04 per linear workflow in 2023 to $1.20 in 2026 for an agentic one; while developer consumption is up over 18x over just the last nine months. Goldman Sachs further predicts that token use by AI agents will increase 24 times by 2030.
TechCrunch, ‘The token bill comes due: Inside the industry scramble to manage AI’s runaway costs,’ 5 June 2026. techcrunch.com
BenchLM.ai, ‘LLM Statistics,’ 5 June 2026. benchlm.ai
To summarise, cost per token has fallen massively for older, less powerful models. But developer volumes and workflow complexity are up even further; the transition to more sophisticated agentic workflows also require the latest models which are both more powerful and more expensive.
What This Means for Executives and Boards
A decade ago, organisations moved to the cloud and many lost visibility of their spend. They were shocked by how quickly costs racked up until they put proper metrics and spend controls in place. AI is following the same trend, only much faster since the tools that are meant to drive productivity are also driving costs without visibility on true ROI.
Establish AI costing dashboards and put ceilings on token usage. The fix isn’t overly complicated; CFOs have done this for other technologies like cloud, but many need to level up on how AI tokenomics work. Require visibility of AI spending by team and by individual use cases, refreshed weekly or monthly rather than getting a shock at the next quarterly update.
Measure value, not tokens. Falling unit prices (measured by cost per million tokens) hide the impact of exponentially rising consumption volumes. Ask for ROIs on all key use cases in terms of productivity benefits, efficiency savings and increased revenues. Pressure test AI business cases against estimated and actual development and run costs.
Get your CFOs to tool up on AI. Much like the introduction of Excel gave rise to not just a new skillset, but an enterprise capability focused on management accounting and sophisticated data analytics, tokenomics is bound to create a need for an array of new skills in AI budgeting and forecasting. CFOs need to play a much more visible and influential role in AI programs, not just to control costs, but to drive enterprise ROI.
Sources:
Fortune, ‘Uber burned through its entire 2026 AI budget in four months,’ 26 May 2026. fortune.com
Key Risk #2: Cyber resilience in the wake of Mythos
CEOs and executives have all heard the noise about frontier models such as Mythos and GPT 5.5. They have a vastly improved ability to find flaws in software and core operating systems. Rightly, many execs are asking their CISOs “has it actually hurt companies like mine, and do I have to spend money that I haven’t budgeted for on it?” We think the answers to these questions are yes, and not as much as you might fear. While companies are being hit more by hackers with new and improved AI tools, defences start with better application of existing cyber budgets and not necessarily large major new investments.
It’s not hype and attackers are using AI now. Google’s Threat Intelligence team caught threat actors in May weaponising previously unknown software flaws known as zero-day exploits that were developed with AI. This was the first confirmed attempt to launch a mass attack in this way. The Google team reported that groups linked with China, North Korea and Russia are now using AI to find vulnerabilities and run attacks with far less human effort than before. The AI capabilities aren’t confined to labs, they’re in the hands of sophisticated and coordinated cyber groups.
Large companies are being targeted, and cyber attacks are ending careers. Corporates such as Charter Communications, Foxconn and Carnival have all been breached in recent months. Foxconn was reported to have lost over eight terabytes of data, including product schematics tied to Apple and Nvidia to a ransomware group. Carnival, the world’s largest cruise operator, had the records of six million customers stolen. And when e-commerce conglomerate Coupang was exposed by a data breach affecting the personal data of over 33 million South Korean customers (or two thirds of the nation’s population), its chief executive was forced to resign.
The cost of cyber breaches is real. IBM estimates the average ransomware attack at US$5.08 million and 24 days to recover from. The largest ransom on record was US$75 million, paid by a Fortune 500 company to the Dark Angels group.
What This Means for Executives and Boards
It is not all doom and gloom – there’s a rational and relatively cost-effective approach that companies can take. Visa’s security teams ran Mythos against its own systems as an Anthropic Project Glasswing partner: the attacks were contained by security that was already built into its architecture. Zero-trust identity mechanisms and network segmentation containing the “blast radius” from attacks limited the attack chains. Visa’s CISO draws a clear, practical lesson – finding vulnerabilities is no longer the hard part for hackers, so defence must “shift left”, designed in early rather than focused on retrospective patching and recovery. This means that the key controls are also the cheapest.
Zero-trust identity management needs to be the first line of defence. While zero trust sounds highly technical, the essentials are things most companies are already paying for: multi-factor authentication (MFA), single sign-on (SSO), and removing standing admin access in favour of granting it only when it’s needed. These mechanisms are largely included in the Microsoft, Google or Okta licences companies are paying for and perhaps not fully enabled.
Wall off the “crown jewels” and concentrate investments in the highest priority systems. No one can defend everything equally. Companies should target the two or three core systems whose loss would end the business and put each within its own ringfence – the patient record, the payments engine, the core customer database. The goal is simple: a foothold in the email system cannot reach the clinical, customer or financial engine of the business. Lean on your hyperscalers and major vendors, who are already inside the Project Glasswing and OpenAI Daybreak consortiums while you are not.
Rehearse recovery. No one can patch fast enough now, so what matters most is how quickly any company can recover. Visa stopped tracking mean-time-to-detect in favour of “mean-time-to-adapt” which targets the time between confirming a flaw is real and proving the attack path is closed. This doesn’t involve spending many millions more on software, but instead it requires tested incident response plans to give CEOs and Boards assurance you can deal with the unpredictable.
Sources:
Fortune, ‘Google: Hackers are using AI to weaponize zero-day vulnerabilities,’ 12 May 2026. fortune.com
Visa, ‘When AI Accelerates Risk, Defense Must Move Faster,’ R. Taneja and S. Kumaraswamy, 10 June 2026. corporate.visa.com
Key Risk #3: The Human Dignity Test
On the 15th May 2026, Pope Leo XIV signed his first encyclical entitled “Magnifica Humanitas: On Safeguarding the Human Person in the Time of Artificial Intelligence”. Whatever one’s views on faith and religion, the huge 42,000 word document recognises the rapid and profound impact of digitalisation, AI and robotics in transforming the world. And while acknowledging that technology has materially improved humanity’s living conditions over centuries, the document also makes the important observation that: “Never has humanity had such power over itself.”
Two key themes land in boardrooms and policy debates. On work, the document warns that automation risks leaving many people behind in ‘forced inactivity’, beyond just earning an income necessary for survival, and states that the pursuit of greater profits cannot justify choices that systemically sacrifice jobs. On power, it cautions against AI capabilities that concentrate in the hands of a few dominant companies, seen in the wave of trillion dollar IPOs affecting markets today.
What This Means for Executives and Boards
The test of whether organisations are using AI responsibly is widening and we expect it to elevate through the latter half of 2026. While the main governance focus in boardrooms today is fairly narrow, on regulatory compliance and general AI risk management, a more public question of fairness is likely to rise. This standard will be applied by talented employees deciding whether to stay, customers deciding whether to trust, and increasingly by regulators and the media.
Treat AI decisions as part of social licence to operate, not just a communications matter. Be able to state your position on AI and work in plain, authentic terms that a skeptical employee or customer would find honest and reasonable.
Protect the first rung of the talent ladder. As we argued in April, organisations eliminating early-stage roles today will face a leadership shortage in the medium-term. Design ‘apprenticeship’ roles that develop overall business capability so that talented young individuals grow with your core business innovations.
Sources:
TIME, ‘Pope Leo Uses First Major Papal Text to Warn About Dangers of AI,’ 25 May 2026. time.com
Vatican News, ‘Pope Leo’s Magnifica Humanitas: AI must serve humanity not concentrate power,’ May 2026. vaticannews.va
EXECUTIVE AND BOARD ACTION IMPLICATIONS
Three critical questions rise to the surface this month, and none require deep technical expertise to ask:
1. AI cost governance: “Do we know what we spent on AI last week by team, and what’s our ceiling?” This is a question that CFOs will need to sharpen their pencils on. The cost of tokens is changing shape from seat-based licences towards consumption-based pricing, and as the past few years of heavy subsidies disappear, AI “FinOps” will become a major focus for CEOs and Boards in avoiding unexpected cost blowouts and managing the bottom line.
2. Cyber resilience: “How have we implemented zero-trust identity safeguards, and if we were breached tomorrow, how fast would we recover?” The most effective protections are relatively cheap: hard rules on identity management and crown jewels protection, alongside incident response plans that have actually been rehearsed (IBM finds that robustly tested plans save US$2.7 million per breach). Risk committees should confirm both of these safeguards are in-place.
3. Talent and trust: “Can we honestly explain how our use of AI affects the people who work for us and rely on us?” Talent committees should be able to articulate the organisation’s position on AI in terms an employee would deem fair, and track graduate hiring trajectory and employee sentiment alongside productivity metrics.
ON THE HORIZON
The EU AI Act’s transparency obligations take effect in August: two months to go. Providers of general-purpose AI must disclose training data summaries, technical documentation, and label AI-generated content. These also apply to non-EU organisations whose AI systems are accessible to EU users or process EU data. Non-compliance carries fines of up to 3% of global revenue or €15 million.