FL Fredrik Lindstrom

I Predicted This Cybersecurity Reckoning in 2018. Here's What I'm Predicting for AI.

In 2018 I predicted the SEC would require public companies to disclose cyber risk. The rule landed in 2023 — five years later than I thought. Here's what the structural calls got right, the timing calls got wrong, and three predictions for AI governance in the next 24 months.


Hero — I Predicted This Cybersecurity Reckoning in 2018. Here's What I'm Predicting for AI.

In January 2018, I wrote that the SEC was considering new regulation requiring publicly traded organizations to account for cyber risks they were facing — including stricter breach disclosure rules. I wrote that this could lead boards to require a different approach, pushing organizations to hire serious professionals throughout the IT function. I wrote that compliance would not equal security, but that improving regulation combined with stricter enforcement could finally drive the change IT desperately needed.

In July 2023, the SEC adopted exactly that rule. Public companies are now required to disclose material cyber incidents within four business days. Annual filings must describe the company’s cyber risk management, strategy, and governance — including board oversight.

I called the structural shift correctly. I called the timing wrong by five years.

I bring this up not to take a victory lap but to set up what I am about to do, which is make three predictions about AI governance in the next 24 months. The structural calls in 2018 turned out to be more reliable than the timing calls. AI governance is following the same pattern.

The Promise

What I underestimated in 2018 was the durability of the gap between deployment and oversight. I assumed the regulators would arrive within 12 to 18 months, because the breaches were already disclosing themselves at scale and the cost was already material. The regulators took five years. The breaches kept happening. The cost kept being absorbed. The market did not self-correct.

The optimistic read is that this same gap exists for AI today, but the regulatory infrastructure is arriving faster. The EU AI Act becomes operational in 23 days from this writing. SEC AI-related disclosure expectations are tightening. The NACD, IAPP, NIST, and ISO have all published AI-specific governance frameworks in the last 24 months. The infrastructure that took a decade for cybersecurity is being built for AI in roughly three years.

That means the prediction window is shorter and the consequences hit faster.

The Risk

Here are the three predictions, in order of confidence.

Prediction one — high confidence. Within 18 months, board-level AI literacy will be a litigated issue. Not theoretically. In actual proceedings. There will be a Caremark-style claim — Delaware fiduciary oversight law — alleging that directors failed to implement reasonable oversight over AI systems that produced foreseeable harms. The plaintiff’s bar has been waiting for this case. The conditions for it now exist: AI deployed in customer-facing decisions, demonstrable harms, board minutes that do not document AI risk discussion. Whether or not the plaintiff wins, the case itself will reset board behavior the way the early Caremark cases reset cybersecurity board behavior.

Prediction two — medium-to-high confidence. Within 24 months, vendor concentration in foundation models will be reframed as a systemic risk on the order of how cloud concentration was reframed after the 2017 AWS S3 outage. Three or four companies provide the foundation models that increasingly underpin enterprise AI workflows. When one of them has a serious failure — security, accuracy, availability — the second-order effects will be measured in entire industries, not individual enterprises. Boards will start asking the model concentration question before regulators ask it for them, but only after the first incident makes the question impossible to ignore.

Prediction three — medium confidence. Within 24 months, AI governance certifications will function the way CISSP did between 2005 and 2015 — a credibility signal that hiring managers and boards use to filter for serious operators. IAPP AIGP is the early leader. NIST AI RMF Architect is plausible. The market is currently flooded with vendor-specific badges that will not survive contact with serious recruiting standards. The framework-fluent certifications will. By mid-2027, “AI Governance Lead” will be a commonly recruited role, and the candidate pool will sort cleanly between the certified and the uncertified.

The Verdict

In 2018 I argued that compliance does not equal security, but that regulation could create the conditions where serious work gets done. That was right then. It is right now for AI. The EU AI Act will not produce safe AI. But it will produce the operational conditions — inventory, documentation, board oversight, vendor accountability — under which safe AI becomes possible.

The pattern that repeats is this: the regulation gets the budget approved. The framework adoption is what actually changes the organization. The certification market follows about 24 months later. And by the time everyone agrees the work was necessary, the organizations that started early have already absorbed the operational learning curve while the rest are still arguing about scope.

I missed the timing on the SEC cyber rule by five years. For AI, my calls are tighter — 18 to 24 months — because the regulatory infrastructure is moving faster than it did for cybersecurity. If I am right, the next two years define which organizations enter the post-AI-Act era with operational maturity and which ones enter it with debt that compounds for the rest of the decade.

If you remember nothing else from this piece, remember the structural call from 2018, which still holds: the work that gets done before the deadline is materially cheaper than the work that gets done after. Start now.