AI-enabled discovery of cyber vulnerabilities emerged as the most critical emerging risk facing organisations worldwide in the second quarter of 2026, according to Gartner.
The Gartner Quarterly Emerging Risk Report series compiles insights and perspectives from enterprise risk management (ERM) leaders, risk professionals, auditors and senior executives on emerging and future risks. In this latest report, Gartner surveyed 316 senior executives and risk managers across a range of sectors and regions in April and May 2026.
“The ability of AI to increase the efficiency and accessibility of vulnerability discovery is making it increasingly difficult for traditional risk management approaches to keep pace,” says Kevin Mercado, senior principal analyst: research, in the Gartner Risk & Audit Practice. “Without corresponding improvements in governance, security operations, and remediation capabilities, AI-driven vulnerability may outpace organisational disruption.”
Top Emerging Risks of 2Q26

Source: Gartner (August 2026)
While many organisations express confidence in their preparedness for AI-driven cyber threats, the speed and sophistication of AI innovation mean that vulnerabilities can be discovered and weaponized faster than ever, requiring organisations to be more agile and proactive in their response.
To maintain true preparedness, Gartner recommends four ways for organizations to begin updating their cyber response and broader risk management assumptions:
- Recalibrate risk impact assessments to account for amplified exposures
- Update risk appetite to reflect the ongoing nature of vulnerability discovery
- Strengthen third-party risk controls to ensure vendors are not introducing new risks
- Accelerate cyber response strategies to enable faster patching and automated remediation to keep pace with the speed of AI-driven threats
Beyond cyber vulnerabilities, the report also highlights the prevalence of agentic AI, which involves autonomous systems that operate beyond organizational oversight, and the growing threat to information integrity posed by unreliable data and AI-generated content. In addition, many organisations continue to face significant gaps in workforce preparedness for AI-related technologies, while geopolitical shocks remain a disruptive force in global energy supply chains.
To address this, organisations should update their AI governance strategies, strengthen workforce planning to close AI skill gaps, and adapt risk management practices to keep pace with a rapidly changing environment.
“AI’s growing capabilities are creating new and complex challenges for cybersecurity, operational resilience and organizational trust,” says Mercado. “To anticipate and counter the risks associated with each, leaders must recognize the impact potential and be prepared for better response.”