Aon has called for stronger cyber risk management practices following an April 2026 open letter from the UK government to business leaders stating that AI is now capable of finding software weaknesses and writing exploits at a speed and scale that would have been impossible even a year ago. Rob Kemp, CEO of Commercial Risk in the UK for Aon, said the firm’s Global Risk Management Survey found cyber attacks and data breaches remain the top enterprise risk in 2026, expected to continue into 2028, with many businesses describing themselves as only somewhat prepared at best – citing fragmented governance and limited testing of AI-driven incident scenarios. Aon said AI has not changed the fundamentals of cyber risk management but has significantly increased the scale and likelihood of attacks, and is encouraging businesses to focus on core controls – patching, vulnerability remediation, staff training on phishing and social engineering – and stress-test them against AI-enabled scenarios including updating loss scenarios to check whether existing policies respond to AI-related incidents.