AI Makes the Breach More Complex. The Fundamentals Still Hold.

By Valerie Chan
At WIPL 2026 this week, Amy Juers and I led a data breach tabletop exercise for General Counsel. We asked the room to work through four hypothetical incidents drawn from common and emerging breach and fraud patterns: ransomware, an internal data exposure, an AI chatbot disclosing customer information and AI-enabled impersonation fraud.

AI does not require companies to throw out everything they know about crisis response. Experienced breach teams know the fundamentals: contain the incident, preserve evidence, determine what was affected, involve counsel, notify the insurance carrier, evaluate disclosure obligations and coordinate communications.

The first question is whether AI was the weapon used by a bad actor or part of the system in which the failure occurred. In the first case, the event may still be familiar fraud, impersonation, intrusion or data theft. In the second, the fundamentals still apply, but attribution, evidence and responsibility become harder to sort out.

The danger is allowing AI’s novelty to distract from the response.

When AI Is the Weapon

One of our hypothetical scenarios involved an attacker impersonating a vendor and requesting a change to payment instructions. The request was reinforced through an AI-generated video call, and the payment was released.

AI made the fraud more convincing, but it did not create a new category of crisis.

The company still needed to contact its bank, attempt to recall the payment, preserve evidence, notify the actual vendor, report the fraud to IC3 or other appropriate law enforcement and determine which insurance policies might respond.

What changed was the reliability of verification. A video call is no longer sufficient on its own. Seeing a familiar face and hearing a familiar voice do not prove who is on the other side.

Companies need an out-of-band verification process that does not depend on information provided in the suspicious communication. That may mean calling a known telephone number already on file, requiring approval from a second authorized person or automatically pausing banking changes and high-value payments.

The fundamentals remain. The verification process needs to evolve.

When AI Is Part of the Failure

The analysis becomes less familiar when the exposure occurs through an AI system and no bad actor is immediately evident.

In another hypothetical scenario, a customer-service chatbot built on a third-party AI model began surfacing snippets of one customer’s account information in another customer’s conversation.

There was no obvious attacker. The vendor characterized the problem as an unusual failure and pointed to its contractual liability provisions.

That may make attribution and responsibility less clear. It does not change the immediate response.

The company still needs to determine what information was exposed, who could see it, whether the exposure is continuing and whether the chatbot should be restricted or taken offline. It must preserve evidence and assess the possible customer, regulatory, contractual and insurance implications.

Whether the incident triggers breach-notification laws depends on the information involved, who accessed it and the jurisdictions that apply. But the absence of a hacker does not mean the company can assume that no reportable incident occurred.

A vendor-supplied tool does not automatically shift the company’s obligations. The company may still have direct responsibilities to customers and regulators.

Vendor responsibility matters when evaluating indemnification, defense costs and recovery. But its liability cap does not necessarily limit the company’s own legal or reputational exposure.

The response should begin with the impact, not an argument over labels.

Communications Is Part of the Response

Our ransomware scenario presented a more traditional problem: an attack was spreading while reporters were already asking the company to confirm it.

AI can make that situation move faster. Attackers can impersonate executives and spread false accounts before the company establishes what happened.

The communications fundamentals, however, remain familiar.

Legal, IT, Security, Communications and senior leadership need one verified set of facts, clear approval authority and a designated spokesperson for each audience. The board, employees, customers and insurance carrier should not learn material information from the news or inconsistent internal messages.

A company does not need a final forensic report before it communicates. It does need to distinguish among what is known, what is suspected and what remains under investigation.

“We are investigating a cybersecurity incident and have taken steps to protect our systems. We will share updates as appropriate.”

That is enough for a holding statement without getting ahead of the investigation.

The company should avoid saying that no information was accessed, AI caused the incident, the vendor was responsible or the event was immaterial before those conclusions can be supported.

AI may accelerate outside speculation. It should not accelerate the company into statements it may later need to retract.

Update the Plan Without Abandoning It

Companies do not need a separate crisis-management system for AI. They need to update existing plans for a world in which AI can be used by attackers, embedded in vendor tools or given access to sensitive systems.

That means testing verification procedures designed to withstand synthetic impersonation. It means knowing where AI touches customer, employee and financial data. It means preserving prompts, outputs, permissions, logs and vendor communications when they are relevant to an investigation.

It also means reviewing whether cyber, crime and other insurance policies cover the actual loss, rather than assuming the AI label determines coverage.

The best breach teams already know how to contain, investigate, escalate and communicate under pressure.

AI does not erase those fundamentals. It raises the stakes for applying them quickly, precisely and with discipline.

The question is not whether your organization needs to start over.

It is whether your existing crisis plan has been updated for the ways AI can now be used against you.

Share This Story With Friends & Colleagues.