AI Is reshaping cyber risk. Boards need to manage the threat.
What: Retailers face escalating cyber threats from AI-driven innovation, requiring urgent updates to security and board oversight.
Why it is important: The evolving threat landscape demonstrates that only retailers with robust oversight and adaptive strategies can sustain growth and customer trust.
AI is rapidly transforming the retail sector, driving operational efficiency and customer engagement while simultaneously introducing a new spectrum of cyber risks. As retailers deploy advanced AI systems to optimize everything from supply chains to customer service, the speed of technological adoption is outpacing the development of effective cybersecurity measures. This imbalance has left the majority of retailers vulnerable to sophisticated attacks, such as prompt injection and AI agent manipulation, which can compromise sensitive data and disrupt operations without traditional hacking methods. Boards and executive leadership are now under pressure to strengthen governance frameworks, implement real-time monitoring, and ensure comprehensive staff training to address these evolving risks. Regulatory scrutiny is also intensifying, particularly around algorithmic pricing and the ethical use of customer data, compelling retailers to prioritise transparency and responsible AI deployment. Ultimately, the sector’s ability to sustain growth and maintain customer trust will depend on its capacity to integrate robust security, adaptive governance, and ethical innovation in an increasingly complex digital environment.
IADS Notes: In March 2026, RH-ISAC reported that only 18% of retailers have achieved mature digital core security, highlighting a widening gap between AI innovation and cybersecurity preparedness. That same month, Harvard Business Review emphasised the risks posed by AI agents that can be manipulated like malware, underscoring the need for real-time monitoring and robust governance. The Robin Report in August 2025 detailed the vulnerability of retail AI systems to prompt injection attacks, which can compromise operations without traditional hacking. INSEAD’s January 2026 analysis noted that while board-level oversight is increasingly essential, many retailers still struggle to unlock the full value of AI due to organisational and leadership challenges. Finally, Forbes in December 2025 examined how regulatory developments around algorithmic pricing and surveillance are compelling retailers to balance technological innovation with transparency and ethical responsibility.
AI Is reshaping cyber risk. Boards need to manage the threat.
