A new survey of compliance professionals at investment advisory firms has produced a striking result: artificial intelligence is now the top compliance concern for 85% of firms, while cybersecurity registers as a top concern for only 37%. The gap of roughly 50 percentage points is the most dominant single response the survey has recorded in its 21-year history, and AI's share jumped 28 points from the prior year. One of the survey's authors noted the firm had never seen a single topic command that kind of separation from everything else.

The natural way to read this is that AI has become a more dangerous threat than cyberattacks. That reading is almost certainly wrong, and the truth is more useful. AI did not top the list because it is the biggest threat to these firms. It topped the list because it is the biggest uncertainty, and compliance concern tracks uncertainty far more closely than it tracks actual danger. Understanding the difference explains both why AI dominates the survey and why the ranking should not be mistaken for a map of where the real risks lie.

Concern tracks unsettled rules, not realized harm

Cybersecurity and AI are not the same kind of compliance problem, and conflating them is what makes the survey result look more dramatic than it is. Cybersecurity is a mature compliance domain. It has established regulatory frameworks, recognized standards, a long catalog of known threats, and well-developed controls and testing regimes built up over many years. Firms largely know what they are supposed to do about cyber risk, even if doing it perfectly remains hard.

That maturity is precisely why cyber generates less compliance anxiety, and it is a mistake to read the lower ranking as cyber ceasing to matter. It has not. The same survey found that 58% of firms increased their cybersecurity testing, and separate industry research indicates that a large majority of financial institutions experienced breaches involving AI-enabled attacks. Cyber remains a live and damaging threat. But a threat with known frameworks and proven controls commands less worry than one without them, because compliance professionals lose sleep over the situations where they do not know whether they are doing enough, not the ones where the playbook is settled. Cyber is a problem firms know how to work on; that is different from a problem that is going away.

AI is the opposite: an immature compliance domain. The regulatory framework is unsettled and shifting, with federal approaches in flux and a patchwork of state activity, there is no established consensus on what good AI governance looks like, and the controls and testing practices are still being invented. So AI dominates the concern ranking not because it causes the most harm today but because it is the domain where compliance officers have the least settled guidance and the most exposure to getting it wrong. The survey measures anxiety, and anxiety concentrates where the rules are unwritten. Read correctly, the 85% figure is a statement about how unsettled AI compliance is, not a statement that AI is more dangerous than hackers.

Why AI is genuinely, and not just novelly, hard

None of this means the concern is misplaced, and it would be equally wrong to swing to the dismissive view that AI is merely the shiny new worry. There are real, structural reasons AI is a genuinely difficult compliance problem, and they go beyond its novelty.

The deepest is that AI inverts the direction the threat comes from. Cybersecurity compliance is fundamentally a perimeter-defense discipline: it is about protecting the firm against external attackers and controlling who gets access to what. AI compliance is about governing the behavior of the firm's own adopted tools. An AI system that gives a client bad advice, hallucinates a fact, embeds a bias in its recommendations, mishandles confidential data, or acts autonomously in a way no one intended creates liability from within, from a tool the firm deliberately chose to deploy. As the reporting on this survey put it, the biggest threat is now coming from inside. That is a categorically different kind of risk from an intruder at the gate, and the compliance apparatus that firms built over decades is largely designed for perimeter defense, not for supervising the judgment of their own software. Existing compliance muscle does not straightforwardly transfer, which is a real reason AI is hard, not merely an unfamiliar one.

Compounding that, the difficulty is urgent because adoption is racing ahead of governance. Roughly 80% of these firms have already formally adopted AI tools, driven by genuinely large upside, with major institutions suggesting AI could let advisers triple the number of clients they serve or run investing agents that outperform standard portfolios. The tools are being deployed fast because the payoff is real, while the frameworks to govern them are being assembled on the fly, which is exactly why 72% of firms increased AI compliance testing, the largest jump of any topic tracked. The 85% concern figure is, at bottom, a measure of that gap: firms are using these tools before anyone is confident how to govern them, and their compliance officers know it. The survey's framing of a move from awareness to action captures the moment, firms adopted first and are now scrambling to build the controls that should have accompanied adoption.

The misreading to avoid

The practical danger in a survey like this is that a headline number invites a resource-allocation error. Reading "AI is now 85%, cyber is only 37%" as a signal to shift attention and budget away from cybersecurity toward AI would be a mistake, and an expensive one. Cyber is not less dangerous than it was; it is less uncertain, and those are different things. The breaches keep coming, increasingly powered by AI on the attackers' side, and a mature threat that has stopped generating anxiety is exactly the kind of threat that gets quietly under-resourced until it produces an ugly surprise.

The reassuring detail is that these firms do not appear to be making that error, since a majority increased cyber testing even as AI dominated their stated concerns, which suggests they are treating the two as additive rather than substitutive. But the framing risk is real for anyone reading the ranking from the outside, and the correct interpretation is that both domains are serious: cybersecurity is mature but still dangerous, and AI is immature and genuinely new. The survey is not telling firms to trade one for the other. It is telling them where the unwritten rules are, and the unwritten rules are around AI.

How to read it

The right way to understand AI's historic margin in this survey is as a snapshot of the maturity gradient across compliance domains, not as a ranking of threats by how much damage they do. AI sits at the top because it is new, because its rules are unsettled, because it introduces a categorically different risk that comes from within rather than from outside, and because it is being adopted faster than it can be governed. Every one of those is a legitimate reason for intense attention. None of them is the same as AI being the largest source of actual harm, which, on the available evidence, cyber may well still be.

The useful discipline is to treat concern surveys as maps of uncertainty rather than danger, and to resource threats according to their real risk rather than their novelty. That means giving AI the governance attention its genuine, structural difficulty warrants, while continuing to fund the mature threats that have simply stopped generating headlines. It also suggests a prediction worth watching: if AI compliance follows the path cybersecurity did, it will gradually acquire settled frameworks, recognized standards, and proven controls, and as it does, it will slide down the concern ranking even if the underlying technological risk keeps growing, because familiarity, not safety, is what quiets compliance anxiety. The day AI stops topping this survey will not necessarily be the day it stops being risky. It will be the day firms finally feel they know what to do about it. This analysis takes no position on any firm's specific compliance choices; the point is only that the loudest concern and the largest danger are not the same measurement, and this survey is measuring the first.

Primary sources

  1. American Banker and Financial Planning for the finding that AI was a top compliance priority for 85% of responding firms versus 37% for cybersecurity, the framing that the biggest threat is now coming from within, the survey of compliance professionals at 411 investment adviser firms, Privacy/Reg S-P as the third-highest concern at 35%, and the Morgan Stanley and JPMorgan estimates that AI could let advisers triple their client load or that AI investing agents could beat a standard 60-40 portfolio.
  2. WealthManagement.com for ACA Group President Carlo di Florio's observation that no single topic had commanded that kind of separation in 21 years of the survey and the 28-percentage-point year-over-year increase.
  3. NAPA-Net and the ACA Group release for the 2026 Investment Management Compliance Testing Survey details, including that 72% of firms increased AI compliance testing, the largest year-over-year increase of any topic, cybersecurity and Privacy/Reg S-P testing each rising at 58%, vendor due diligence at 48%, an ESG testing decrease, 80% of firms formally adopting AI tools, and 86% having acceptable-use policies.
  4. The AlixPartners 2026 U.S. Risk Survey and Corporate Compliance Insights for context on the shifting federal and state AI regulatory landscape and the SEC's 2026 examination priorities elevating AI and cybersecurity.
  5. Gigamon's 2026 survey via Cybersecurity Insiders and Security MEA for the findings that about two-thirds of financial firms let AI security automation act autonomously and that a large majority experienced breaches involving AI.