Cyber security is moving from a technical best practice to a mandated legal obligation. This month, we look at the structural and regulatory shifts defining 2026.
From the "confused deputy" risk of prompt injection and the rise of autonomous security agents, to the tightening grip of UK and EU resilience laws. Whether in your code or in the boardroom, the message is the same: architecture without accountability is no longer an option.
That comparison is misleading.
In a December 2025 blog, David C of the National Cyber Security Centre explains why this is not simply another input validation problem.
If you are deploying generative artificial intelligence in your organisation, this distinction matters.
Why The Analogy Breaks Down
SQL injection exploits a failure to separate data from instructions.
That class of flaw was mitigated through parameterised queries and secure engineering defaults.
Large language models do not operate with a built in boundary between data and instructions.
They predict the next token based on probability.
This creates a structural limitation:
This is not poor coding. It is how technology works.
The Real Risk: Inherently Confusable Systems
Prompt injection is better understood as a confused human deputy problem.
A privileged system can be manipulated into acting on behalf of an untrusted party.
If your model can:
Then prompt injection risk becomes tool privilege risk.
If an attacker can influence the model output, they may influence downstream actions.
What This Means For Business Leaders
You cannot fully eliminate prompt injection.
You can only reduce likelihood and impact.
That requires architectural controls outside the model itself:
The key question is not whether your prompts are well written.
It is whether your design can tolerate model failure.
Final Thought
SQL injection took years of breaches before secure defaults became standard.
Generative artificial intelligence is being embedded rapidly into recruitment, finance, healthcare and customer operations.
If prompt injection is treated as a minor coding issue rather than a structural risk, we will repeat that cycle.
Innovation is not the problem.
Architecture without control is.

Artificial intelligence is no longer confined to dashboards and decision support tools. We are now seeing the rise of agentic artificial intelligence systems that can act autonomously across security environments.
These systems do not simply detect threats. They make decisions. They initiate actions. They adapt in real time.
This represents a significant shift in how cyber security operations are designed and governed.
Why Agentic Artificial Intelligence Is Rising
According to Gartner, oversight of agentic artificial intelligence is emerging as a leading cyber security trend. Organisations are moving beyond passive analytics towards systems capable of continuous monitoring and automated response.
Research indicates that artificial intelligence agents are increasingly capable of:
For overstretched security operations centres, the appeal is obvious. Speed improves. Noise reduces. Response times shrink.
However autonomy introduces a different category of risk.
The New Risk Surface
When an artificial intelligence agent can act without human validation at each step, the risk profile changes.
You must consider:
Autonomous capability expands both defensive potential and attack surface.
If an attacker manipulates inputs into an agent driven system, the output is no longer just analysis. It may be action.
Oversight Is Not Optional
Agentic systems require governance frameworks that go beyond traditional model validation.
Security leaders should ensure:
Oversight must be continuous, not periodic.
What This Means For Business Leaders
Autonomous security operations can be a force multiplier. They can also create unmanaged exposure if deployed without architectural discipline.
The strategic question is not whether artificial intelligence can improve your security posture. It can.
The question is whether your governance model is mature enough to manage systems that act independently within your infrastructure.
Agentic artificial intelligence is not just another tool in the stack. It is a delegated decision maker. And delegated decision making always requires accountability.

Cyber security is no longer an operational discussion confined to the technology team. It is a board level risk with legal, financial and reputational consequences.
Regulatory complexity is increasing. Disclosure expectations are tightening. Supervisory scrutiny is becoming more assertive. Resilience is no longer optional. It is being mandated.
The Shift From Best Practice To Legal Obligation
Across the United Kingdom and the European Union, organisations are facing expanding requirements relating to cyber resilience, incident reporting and product security.
Emerging frameworks such as the European Union Cyber Resilience Act are reshaping expectations around security by design principles, vulnerability management and supply chain accountability.
This changes the conversation. Cyber security controls are not simply defensive measures. They are evidence of governance.
Boards must now understand:
Failure in these areas is not just a technical issue. It is a governance failure.
Disclosure And Accountability
Incident reporting requirements are becoming more structured and time bound. Regulators increasingly expect transparency, traceability and documented decision making.
This has several implications:
The era of informal cyber governance is closing.
The Supply Chain Pressure Point
Modern regulation extends beyond the organisation itself. It places expectations on how you select, monitor and contract with suppliers.
If your vendors introduce vulnerabilities, regulators may still look to you for accountability.
This requires:
Resilience is collective. Liability often is not.
What This Means For Leadership
Cyber and legal leaders can no longer operate in parallel. They must operate in partnership.
Security strategy must map directly to regulatory exposure. Compliance programmes must reflect technical reality.
Boards should be asking:
Regulation is not slowing innovation. It is formalising accountability. Organisations that treat compliance as a strategic enabler will build trust.
Those that treat it as an afterthought will face penalties and reputational damage that far exceed the cost of preparation.

