How AI is creating a new era of business vulnerability for Indian corporates

By Apurva Gopinath, Cyber Leader and Vice President, Financial Services & Professional Group, India, Aon

Artificial intelligence is moving rapidly from experimentation to enterprise adoption. For Indian companies, the opportunity is significant: AI can improve productivity, accelerate innovation and strengthen competitiveness. Yet as adoption expands, AI is also reshaping the risk landscape, creating new vulnerabilities across cyber security, data privacy, governance, supply chains and reputation.

Aon’s Human Capital Trends Study findings for India show that 43 percent of organisations in India have already deployed AI, with a further 20 percent piloting programmes. This momentum is supported by confidence in talent availability, with 39 percent of organisations in India reporting confidence in sourcing skilled AI talent compared with 21 percent across Asia Pacific and 24 percent globally.

This pace of adoption makes governance a business priority. The key question for boards and management teams is no longer whether AI will be adopted, but whether it can be adopted safely, responsibly and with a clear view of the financial, operational and reputational risks it may create.

Beyond productivity, a broader risk agenda
The conversation on AI risk needs to move beyond job displacement. AI is changing how businesses operate, how decisions are made and how risk travels across an organisation. It can increase the speed and scale of cyber-attacks, amplify social engineering and fraud, create questions around model bias and expose gaps in data governance.

Aon’s 2025 Global Risk Management Survey ranks cyber attack or data breach as the top current and future global risk, while artificial intelligence enters the top ten future risks for the first time. For India, while “cyber attack or data breach” continues to top the list, artificial intelligence moves up to take the second spot. This points to an important shift. Technology-related exposures are no longer only operational issues. They are strategic risks that can affect enterprise value, stakeholder confidence and business resilience.

Cyber exposure is evolving quickly
AI is changing the nature of cyber and physical security. Deepfakes, data poisoning, automated phishing and AI-enabled fraud can affect customer trust, operational continuity and financial resilience. Aon’s 2025 Cyber Risk Report found that in Asia Pacific, cyber incident frequency rose 29 percent year over year and 134 percent over the four years from 2020 to 2024. AI-driven deepfake attacks contributed to a 53 percent increase in social engineering incidents, while claims involving social engineering and fraud increased by 233 percent.

These trends show why traditional controls are no longer enough. Indian companies need an integrated approach that brings together cyber security, business continuity, governance, data protection and insurance strategy. Risk teams also need better analytics to understand potential losses before incidents occur.

The need to quantify AI risk
One of the biggest challenges for corporates is that AI risk can be hard to quantify. The impact of a model failure, data breach, bias claim or operational disruption may not be immediately visible, but it can create significant financial and reputational consequences. Aon’s Global Risk Management Survey found that only 14 percent of respondents quantify their exposure to the top ten risks and only 19 percent use analytics to evaluate the value of their insurance programmes.

This gap between awareness and action is especially important for AI. Companies need scenario analysis, loss modelling and clear risk ownership to translate AI exposures into financial terms that boards, investors and insurers can assess. Without this, organisations may underestimate the scale of their exposure or misalign their insurance and risk transfer strategy.

Governance must extend beyond the organisation
AI risk does not sit only within an organisation’s own systems. Third-party tools used for HR screening, credit scoring, customer analytics, fraud detection or supply chain optimisation can create exposure if models are not reviewed, contracts are unclear or vendor controls are weak. Many companies may not have full visibility of where AI is being used across their vendor ecosystem.

A risk-commensurate approach to third-party relationships is essential, particularly where vendors host, store, process, transmit or access information. For AI, this means reviewing contractual protections, privacy obligations, security controls, model oversight and incident response plans before vulnerabilities become losses.

Data privacy is becoming a critical fault line
AI can intensify data privacy risk when organisations use personal or sensitive data without clear governance, documentation or oversight. Aon’s Responsible AI Policy highlights the need to handle personal and confidential data in line with applicable policies, justify the processing of personal data and maintain human review of AI-generated outputs, particularly for client-facing communications, services or key internal decisions.

For Indian companies, this becomes more important as the Digital Personal Data Protection Act, 2023, paired with requirements from RBI, IRDAI, SEBI, and sectoral regulators, increases expectations around consent, data handling and accountability. Organisations need to understand where AI tools access personal data, how that data is used, what consent basis applies and whether protection measures are aligned to the exposure.

Legacy data can be particularly challenging where AI models are trained on customer information collected before newer consent or privacy frameworks were introduced. Without clear audit trails, documentation and governance, organisations may face legal, regulatory and reputational risk.

Embedding accountability into AI adoption
Responsible AI adoption requires more than policy statements. Companies need audit trails that document notices, consents, data usage, model purpose, vendor involvement and human oversight. They should embed privacy and security controls into design processes, strengthen governance and ensure teams understand ethical AI practices, escalation protocols and incident response obligations.

This requires collaboration across legal, compliance, privacy, cyber security, risk, technology, procurement and insurance teams. AI accountability cannot sit with technology teams alone. It needs to be integrated into enterprise risk management and board-level decision-making.

Building resilience into the AI opportunity
AI adoption in India is accelerating, supported by strong talent availability and growing enterprise deployment. The opportunity is clear, but so is the need for disciplined governance. Indian corporates should conduct regular AI risk assessments, map AI tools and data flows, strengthen vendor oversight & readiness tests, quantify potential losses and align risk transfer with their evolving risk profile.

The companies best positioned to benefit from AI will be those that treat resilience as a strategic advantage. By combining innovation with transparent governance, stronger cyber controls, data-led risk quantification and insurance alignment, organisations can adopt AI with greater confidence and protect long-term value.

Comments (0)
Add Comment