Skip to content
Preprint

The AI Resilience Gap: Bringing Artificial Intelligence Inside the Operational Resilience Perimeter

Jul 2026 · 0 citations · 17 references
Computer Science

TL;DR

It is argued that AI adoption creates a resilience obligation that is distinct from, and inadequately covered by, the trustworthy AI stack, and that United Kingdom financial authorities are already closing this gap through the Financial Policy Committee's systemic analysis, the Critical Third Parties regime, and the May 2026 joint statement on frontier AI and cyber resilience.

Abstract

The rapid adoption of artificial intelligence across regulated firms has produced an extensive governance response oriented around trustworthiness: the EU AI Act, ISO IEC 42001, the NIST AI Risk Management Framework, and the United Kingdom's principles-based approach all address safety, fairness, transparency, and model risk. That response is necessary but incomplete. It does not, on its own, address operational resilience: the continuity of important business services under severe but plausible disruption, the substitutability of AI components, and the concentration of dependency on the small number of firms that supply frontier models. This paper argues that AI adoption creates a resilience obligation that is distinct from, and inadequately covered by, the trustworthy AI stack, and that United Kingdom financial authorities are already closing this gap through the Financial Policy Committee's systemic analysis, the Critical Third Parties regime, and the May 2026 joint statement on frontier AI and cyber resilience. We map the two regulatory logics, identify the structural gap between them, and propose the AI Resilience Framework: a regime-agnostic method for bringing AI dependencies inside the operational resilience perimeter through dependency mapping, a criticality-substitutability tiering, the extension of impact tolerances to AI-specific failure modes, an explicit fallback doctrine, and provider level concentration management. The framework gives chief information security officers, security architects, and boards an actionable route from AI governance policy to demonstrable resilience. This work extends a companion analysis of the United Kingdom cyber resilience regulatory stack into the artificial intelligence dimension.

View source

Similar papers

Aug 2026

A strategic analysis of operational resilience and the mandate for antifragility: Integrating agentic artificial intelligence within volatile financial ecosystems

The financial services sector stands at a critical inflection point where traditional models of operational resilience are no longer adequate for the velocity and complexity of modern risk. This paper examines the strategic imperative for financial institutions to transition from reactive, compliance-centric risk management towards a state of anti-fragility: the capacity not merely to withstand systemic stress, but to improve because of it. Drawing upon empirical industry data, regulatory developments, and a practical case study from Atom Bank, the paper explores how agentic artificial intelligence is fundamentally reshaping the disciplines of operational resilience, third party risk management, and cyber security. Key themes include the maturity gap in configuration management database infrastructure, the systemic threat posed by supply chain vulnerabilities, the rise of artificial intelligence (AI)-enabled adversarial actors and deepfake fraud, and the concentration risk inherent in hyperscaler dependency. The paper challenges the prevailing assumption that anti-fragility is a well-established or universally accepted framework, presenting it instead as an aspirational model that demands significant cultural, technological, and governance transformation. Readers will gain a structured understanding of the current threat landscape, practical strategies for active resilience, and a framework for integrating AI-driven workflows into a unified institutional risk architecture. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.

Mohammed Randeree · 0 citations
Jul 2026

Addressing the Artificial Intelligence Governance Gap in Environmental, Social, and Governance Standards

It is argued that ESG frameworks, which evolved through incremental adjustment, may prove insufficient for governing algorithmic systems and proposed adding a fourth pillar, Algorithmic Governance, within an extended ESGA framework to address risks that transcend traditional governance categories.

Pitabas Mohanty, Supriti Mishra · 0 citations
Open access Jul 2026

EU Artificial Intelligence Act: risks and opportunities for the European system

This paper examines the European Union Artificial Intelligence Act (AI Act) as a strategic regulatory response to the rapid and pervasive diffusion of artificial intelligence technologies. Starting from a conceptual framing of AI as an instrument of augmented intelligence rooted in bounded rationality, the contribution highlights how contemporary AI systems adopt satisficing logics through heuristics and large-scale data processing rather than pursuing optimal solutions. The analysis situates the AI Act within the broader EU digital strategy and discusses its risk-based regulatory architecture, which classifies AI systems according to the severity and likelihood of potential harm to fundamental rights, safety, and democratic values. Particular attention is devoted to high-risk AI systems, whose stringent compliance obligations raise significant legal, technical, and economic challenges, especially for SMEs and start-ups. While acknowledging the risks of regulatory rigidity, innovation slowdown, and market entry barriers, the paper also emphasizes the strategic opportunities generated by the AI Act. These include the consolidation of a trustworthy, human-centric AI ecosystem, the strengthening of the Digital Single Market, and the potential emergence of a global regulatory benchmark through the so-called “Brussels effect.” Ultimately, the AI Act is interpreted not merely as a compliance burden, but as a long-term investment capable of transforming regulation into a competitive advantage for the European system.

Enrico Maggiora, Claudia Iacobino · 0 citations
Jul 2026

The regulatory trilemma of AI-driven cybersecurity in the European Union: reconciling the AI Act, DORA, and fundamental rights

: The European Union has enacted two landmark frameworks that impose partially divergent obligations on financial entities deploying artificial intelligence (AI) in cybersecurity. The AI Act (Regulation (EU) 2024/1689) establishes a risk-based classification system subjecting AI systems to graduated transparency, explainability, and human-oversight duties. The Digital Operational Resilience Act (DORA, Regulation (EU) 2022/2554) requires financial entities to maintain robust Information and Communication Technology (ICT) risk-management capabilities, including rapid, automation-capable threat detection and incident response. This article argues that, for systemically significant financial actors, the combined operation of these two regimes together with the EU Charter of Fundamental Rights produces what it terms a regulatory trilemma: a three-cornered tension

F. Teichmann, B. Sergi · 0 citations
Aug 2026

Decision integrity under attack: Artificial intelligence and the future of business continuity planning

Artificial intelligence (AI) is increasingly embedded in organisational systems, shaping decision making, resource management, and crisis response. Achieving AI-resilient continuity is not just about faster recovery or stronger systems; it involves maintaining decision integrity, governance quality, and human judgment during intelligent disruptions. While AI enhances efficiency and resilience, it also introduces risks that traditional continuity planning does not fully address. Unlike conventional disruptions, AI-enabled attacks may not cause immediate system failures, yet they can degrade decision accuracy, situational awareness, and governance even while operations appear normal. This paper examines how AI alters the nature of disruption and challenges assumptions about visibility, human oversight, and linear recovery. Through practical scenarios, it illustrates how data poisoning, adversarial inputs, compromised models, platform dependencies, and misinformation threaten organisational continuity. The paper proposes principles for AI-resilient planning that protect decision integrity, enable human override, strengthen governance alignment, and incorporate AI-specific exercises. This framework provides practitioners with actionable guidance for sustaining reliable decision making under AI-driven disruption. This article is also included in The Business & Management Collection which can be accessed at https:// hstalks.com/business/.

S. Haynes · 0 citations
Open access 2026

The dependency divide: how frontier AI redistributes cyber risk across the SME ecosystem

Frontier artificial intelligence is fundamentally altering the cybersecurity landscape by compressing defensive windows and lowering the threshold for offensive skills. While current policy discourse predominantly treats frontier AI security as a concern for large enterprises and critical national infrastructure, small and medium enterprises (SMEs) are systemically exposed. Drawing upon the Dynamic Capabilities View, this paper challenges the prevailing logic that AI will act as a universal equalizer. Instead, it argues that SMEs face a severe “capability shock” because they lack the internal absorptive capacity required to synchronize human-paced governance with machine-paced exploitation cycles. The paper introduces the “dependency divide” to demonstrate how frontier AI creates simultaneous defensive uplift and structural asymmetry. SMEs receive an “inherited defence” dividend when embedded in hyperscale commercial platforms, but face “persistent exposure” in bespoke, “long-tail” niche software. These niche applications often lack the Software Bill of Materials and code transparency required for automated AI remediation, making them highly attractive targets for automated exploitation. Because compromised SMEs act as transmission points for rapid supply-chain propagation, their cyber resilience must be treated as a systemic merit-good. To prevent permanent cyber inequity, policymakers must move beyond generic advice and couple “Secure by Design” mandates with targeted technical enablers—such as open-source AI security agents—to protect the vulnerable long tail of the digital economy.

Marta F. Arroyabe, Ignacio Fernandez de Arroyabe, Carlos F. A. Arranz · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.