What happened
A World Economic Forum white paper (Chief Risk Officers Dialogue Series, September 2026) based on CRO consultations and an original survey of chief risk officers, arguing that legacy enterprise risk management 'may not work well anymore' as uncertainty becomes 'structural rather than episodic.' The headline statistics: '80% of CRO respondents believe risk management will be "somewhat to far more challenging" in 2035 compared to today' while 'only 10% of CROs describe their organization as "very prepared to respond to risks that can't be modelled with historical data."' The paper identifies four shifts defining the next generation of risk management — prediction to preparedness, compliance to strategic enablement, periodic reviews to continuous AI-enabled risk intelligence, and 'AI to complement human intelligence, not substitute it' — including the use of AI-powered digital risk twins to continuously simulate interconnected scenarios.
Why it matters
Gives boards and CISOs a forward-looking, quantified case for shifting ERM from static risk registers toward continuous monitoring and AI-human oversight exactly as agentic and AI-accelerated threats break the historical-data assumptions of current frameworks.
Action needed
Use the 80%/10% CRO gap to brief the board on closing the gap between risk-cadence and AI-era risk velocity, and scope a digital-twin stress-testing pilot.