Share

On October 1, 2026, Mayer Brown hosted The Risk Mosaic: A Roundtable on Cybersecurity, Privacy, AI and Resilience in an Era of Global Disruption in the Chicago office, kicking off Cybersecurity Awareness Month. During this event, participants representing both security and legal teams across a range of industries discussed how AI—and especially agentic AI—is reshaping cybersecurity risk and privacy compliance in the US and abroad.

KEY TAKEAWAYS

1. Importance of Cross-Functional Collaboration

Due to the unique, multifaceted nature of artificial intelligence, participants discussed the advantages of developing teams that bring together IT security, business stakeholders and legal counsel. Having these teams collaborate throughout the platform’s lifecycle, from contracting to deployment, has helped organizations better understand and manage associated risks.

2. Back to Basics: AI Amplifies Existing Vulnerabilities

Participants noted that malicious actors’ use of AI tools does not necessarily create new categories of cyber risk; rather, it accelerates and magnifies familiar ones. Foundational security practices on both technical and legal fronts, such as patch management, coordinated vulnerability disclosure programs, access management, penetration testing and aligning cyber policies with current practices, remain critical foundations for resilience.

3. Agent Ownership, Accountability and Lifecycle Governance

As organizations deploy AI agents, participants noted the benefits of having clear rules around who creates agents, who owns them, and who is accountable for their behavior. Participants discussed the advantages of having governance committees involved in developing standards for enterprise-wide sharing and establishing lifecycle protocols. This includes taking into account various contingencies, such as having procedures to address when an agent’s creator departs the organization.

4. Learn from Existing Processes on Governance

Participants discussed how they leverage current privacy- and cyber-compliance infrastructure, such as impact assessments and third-party risk management frameworks, to address AI governance. Building on existing experience can help address coordination and accountability challenges across teams as AI governance develops.

5. Emerging Exposure Areas: Third-Party AI, Shadow AI, and Records Retention

Participants discussed the range of risks related to deploying AI—particularly agentic AI—present, from internal investigations, to reputational harm to litigation. Based on these risks, the group highlighted the importance of ensuring companies use every lever at their disposal to manage the risk, across contracting, preparedness (including tabletop exercises), technical configuration, and governance. The group also discussed emerging exposure areas, including supply-chain risks that arise when vendors embed AI features into existing products. Participants shared the ways they have addressed limited leverage regarding these changes, including by through robust due diligence. They also noted the difficulties of enforcing AI policies, especially with shadow AI use, and emphasized the importance of clear policies, that require any exceptions to be in writing and that are incorporated into trainings. Finally, the participants discussed the benefits of proactively setting record retention policies for prompts, outputs, and ephemeral messaging before usage patterns become entrenched.

Related Services & Industries

Stay Up To Date With Our Insights

See how we use a multidisciplinary, integrated approach to meet our clients' needs.
Subscribe