Aug. 26, 2026

A Collection of Articles on Core Cybersecurity Strategies for AI-Related Risks

The rapid integration of AI into enterprise operations is reinforcing the importance of cybersecurity fundamentals that have long served as the foundation of effective security programs. AI can accelerate attacks and amplify the risks associated with misconfigurations, third-parties and governance gaps, but the most effective defenses remain rooted in proven practices such as strong security governance, rigorous vendor oversight, access controls, vulnerability management, incident preparedness and reasonable security measures tailored to organizational risk. This collection of Cybersecurity and AI Law Report articles offers a roadmap for strengthening the cybersecurity measures that matter most as organizations navigate the AI era.

Updating Cybersecurity Fundamentals for the Frontier AI Era

Frontier AI models are transforming the cybersecurity landscape by enabling attackers and defenders to identify vulnerabilities, develop exploits and respond to threats at machine speed. As governments and regulators increasingly warn about AI-enabled cyber risks, organizations are being urged to reassess whether their existing cybersecurity programs remain adequate for a rapidly evolving threat environment. Rather than requiring entirely new security frameworks, many of these expectations build on longstanding risk-based approaches and established cybersecurity fundamentals. In this guest article, Covington partner Caleb Skeath and associate Ali Cooper-Ponte examined guidance from regulators and cybersecurity agencies on addressing AI-related cybersecurity risks, explored how AI changes the compliance implications of more traditional cybersecurity controls, and discussed practical approaches organizations can take to evaluate and strengthen their cybersecurity posture to reduce legal and regulatory risk.

State Cybersecurity Laws: How to Meet the Rising Standard for Reasonable Security

Regulators across the 50 states are applying a higher and more elaborate standard for “reasonable cybersecurity” than in prior years. Certain issues remain key enforcement priorities while state AGs and sectoral regulators are also scrutinizing routine practices such as logging, alert monitoring and vulnerability patching more closely. This final article in a three-part series published in collaboration with IAPP shared leading defense practitioners’ advice on how companies can address the investigators’ sharper probes of foundational cybersecurity measures. It also illuminated the emerging impact of AI issues on enforcers’ interrogation of companies. Part one, authored by the managing director of IAPP’s Cybersecurity Law Center, examined breakthrough state legislative developments gaining force in 2026. Part two presented recommended steps companies can take to prepare for regulators’ initial post-incident questions.

When the Classroom Goes Dark: Lessons From the Canvas Breach for Corporate Cyber Preparedness

A single design decision can turn a widely trusted platform into an enterprise-wide liability. When students logged into Canvas in May 2026 expecting coursework, they instead encountered a ransom message from ShinyHunters revealing an attack that disrupted thousands of institutions during finals week and forced the platform’s owner to pay under threat of data release. The breach was not driven by technical sophistication, but by a structural flaw. In this guest article, Finnegan partner Lynn Parker Dupree, associate LaQuan Bates and law clerk Nico Prentosito examined how the breach unfolded, the threat model behind it and what it reveals about the evolving cyber risk environment. They also outlined how organizations should strengthen incident response planning, cross-functional governance and technical controls across SaaS and identity architectures.

Eyewitness Accounts and Recommended Actions to Counter AI’s Strain on Cyber Defense

Leading incident responders and defenders shared firsthand lessons from recent attacks at the Incident Response Forum 2026, highlighting how adversaries are using AI to accelerate exploits and evolve ransomware while defenders struggle to keep pace. They cautioned that defenders face a difficult year as vulnerabilities surge faster than teams can keep pace with, even amid accelerating innovation in security tools such as Anthropic’s Claude Security platform. This article explored the AI threat landscape and offered practical cyber defense and incident response priorities, drawing on commentary from Cooley, Davis Wright Tremaine, FTI Consulting, Kirkland, Morgan Lewis, MOXFIVE, Orrick and Palo Alto Networks.

Mitigating Cyber Risks From AI and Ever-Stealthier Adversaries

Today’s cyber threat landscape is marked by speed, scale and sustained evasion. Adversaries increasingly are using a combination of trusted access paths, AI-enabled acceleration and cross-domain movement to avoid detection, according to CrowdStrike’s 2026 Global Threat Report (Report). The key themes covered by the Report include AI issues, use of cross-domain attacks to deploy ransomware, China-nexus adversaries’ focus on network perimeters, use of supply chain attacks to evade traditional defenses, how adversaries’ objectives influence the zero-day vulnerabilities they exploit and increasing targeting of the cloud. This article synthesized the significant takeaways from the Report and the insights provided by CrowdStrike senior vice president Adam Meyers in a related webinar.

Contracting With Vendors to Mitigate Third-Party AI Risk

When companies and law firms purchase an AI tool from a vendor, they need to consider the risks and controls they can put in place to mitigate them. They will have no control over associated risks without proper contracts. “Your AI governance program cannot work unless the vendor agreement gives the rights needed to enforce that governance,” William Galkin, partner and founder of Galkin Law, LLC, said during a recent BARBRI program. This article synthesized insights from Galkin and technology executives at BillingNav and MorriganAI regarding risks from the use of third-party AI tools and considerations for approaching contracting with vendors. It also offered practical advice on six key AI vendor contract clauses to help companies transform an AI governance program from just policy statements into enforceable operational safeguards.

Mitigating Risks of Shadow AI and Navigating Related SEC Disclosure Requirements

The surge in AI use has heightened cybersecurity risks, including shadow AI – the unauthorized use of AI tools or misuse of approved ones. Illustrating how those risks can manifest, CB Financial Services, Inc. (CB Financial) filed a Form 8‑K with the SEC on May 7, 2026, disclosing that its wholly owned subsidiary had experienced a material cybersecurity incident arising out of the use of an unauthorized AI application. The filing was apparently the first Form 8‑K to disclose a shadow AI incident. This article examined the CB Financial filing, the relevant SEC obligations and how organizations can mitigate the compliance risks associated with shadow AI, with commentary from partners at Debevoise & Plimpton, Wilson Sonsini and Goodwin.