Executive Brief | March 9, 2026
Last week, AI agents started to look more real inside big companies. This week, the risks became much harder to ignore.
We are moving from AI as a helper to AI as an operator. That means AI is not just answering questions or writing content. It is starting to take actions, manage tasks, and work across systems. In some cases, it can affect uptime, security, and money in real time.
At the same time, AI models are getting stronger fast. They can handle more information, work across longer tasks, and even use computers more directly. The problem is that most companies still do not have strong enough rules, controls, or oversight to manage this safely.
For CEOs, boards, and other senior leaders, this changes the conversation. AI is no longer only about innovation or productivity. It is now also about control. The real question is no longer just, “Where can AI help us?” It is, “How much power can we safely give it, and who is responsible if something goes wrong?”
1. AI mistakes are no longer just bad answers. They can cause real business problems.
One of the clearest examples this week came from reporting around AWS and its Kiro coding tool. Reports said a 13-hour outage in late 2025 may have been linked to Kiro deleting and rebuilding part of an environment. Amazon said the issue was caused by user error and poor access controls, not the AI itself. Either way, the lesson is the same: once AI has real permissions, the risk is no longer just wrong text or weak analysis. It can become a real operations problem. (theguardian.com)
The signal: AI systems are getting close enough to real production systems that mistakes in permissions or oversight can lead to downtime.
The shift: The risk is moving from “bad content” to “bad actions.”
2. AI is helping attackers move faster
Cyber risk also became more serious this week. CloudSEK reported that more than 60 Iranian-linked groups became active after the February 28 escalation, and that AI is making it easier to scan and study exposed US critical infrastructure. Other reporting showed that US banks and agencies are on higher alert for possible Iranian cyber retaliation. (cloudsek.com)
Why does this matter? Because AI is helping people move faster. It can help with discovery, sorting targets, and preparing attacks. Things that once took more skill and more time are getting easier.
OpenAI also publicly described its agreement with the Department of War, showing that top AI systems are now part of national-security discussions too. (openai.com)
The signal: AI is becoming a speed tool for cyber attackers, not just defenders.
The shift: Security teams cannot rely only on slow, human-paced monitoring anymore.
3. AI is getting cheaper and more powerful at the same time
The AI race is no longer only about building bigger systems. It is also about building smarter ones.
Ai2’s new OLMo Hybrid model reached the same MMLU benchmark score as OLMo 3 while using 49% fewer tokens. That matters because it suggests AI models may become much more efficient, which could change the economics faster than many companies expect. (allenai.org)
At the same time, OpenAI’s GPT-5.4 introduced native computer use and support for up to 1 million tokens of context. In simple terms, that means AI can work across longer tasks, use much more information at once, and do more inside software environments. (openai.com)
Put simply, AI is improving in two ways at once: it is getting cheaper to run, and it is able to do more.
The signal: AI capability and AI economics are both moving very fast.
The shift: Companies should avoid locking themselves too deeply into one model, one vendor, or one setup too early.
4. Many companies are still not getting the full value from AI
McKinsey’s research shows that companies getting the most value from AI are not just adding tools. They are changing how work gets done. They redesign workflows, align leaders, improve adoption, and put better management and governance in place. PwC’s 2026 AI outlook makes a similar point: value comes from redesigning work, not just layering AI on top of old processes. (mckinsey.com)
This is the real “AI dividend” challenge. Saving time is good, but time savings alone do not create business value. If those saved hours are not turned into growth, speed, innovation, or better customer experience, then the value never really shows up.
That is why many companies are at risk of falling into what could be called efficiency theater, looking more productive without actually creating more impact. (mckinsey.com)
The signal: The main problem is no longer the technology. It is execution.
The shift: Leaders need a clear plan for where AI-created capacity will go.
5. AI governance is becoming a real board responsibility
Board oversight is also getting more serious. Axios reported in January that boards are scrambling to adjust to AI and that more formal governance playbooks are starting to emerge. (axios.com)
At the same time, state-level AI rules are becoming real. Texas’s Responsible AI Governance Act took effect on January 1, 2026. This is part of a bigger shift away from loose AI principles and toward real expectations around accountability, compliance, and oversight.
This does not mean every board needs a separate AI committee tomorrow. But it does mean AI can no longer sit only inside IT or innovation teams. If AI can affect operations, decisions, compliance, or customer outcomes, then it belongs inside the same board-level risk system used for cyber, audit, and enterprise risk.
The signal: AI governance is becoming formal.
The shift: AI risk is becoming a true board issue, not just a tech issue.
What CEOs and boards should do in the next 30 days
1. Run an AI permission audit.
Find every AI tool, assistant, or agent that has the power to write, approve, execute, provision, or delete. Review exactly what it can do and what happens if it gets something wrong.
2. Define the AI dividend clearly.
Ask each business leader not just where AI is saving time, but where that saved time is being used. If nobody knows, the value is probably not being captured.
3. Put AI inside formal risk governance.
Be clear about which committee oversees AI, how incidents are escalated, who approves high-risk use cases, and how serious AI risks are reported to the board.
Bottom line
AI systems are getting more powerful.
They are getting more operational.
And they are getting more access.
But in many companies, the management systems around them are still too weak.
The winners in the next phase of AI will not just be the companies that move fastest. They will be the ones that build the controls, governance, and discipline to move fast without losing control.
Disclaimer: This work includes use of AI.
