Cyber Crime

When the Classroom Goes Dark: Lessons From the Canvas Breach for Corporate Cyber Preparedness


On May 7, 2026, students across thousands of educational institutions arrived at their Canvas learning management system portals expecting course materials and exam submissions. Instead, they found a ransom message from ShinyHunters, the cybercriminal group responsible for what may be one of the largest educational data breaches in history. The incident struck during finals week at many institutions, compounding its operational disruption with acute reputational and regulatory consequences for Instructure, the platform’s owner, which ultimately paid a ransom on May 11, one day before ShinyHunters’ threatened data release deadline.

The breach was not a novel technical exploit. ShinyHunters exploited a structural design decision that allowed an unverified educator account program to share production infrastructure with institutional users. Within eight months, ShinyHunters had breached Instructure twice – first through its Salesforce business systems and now through the Canvas platform.

The most consequential breaches today do not require sophisticated offensive capabilities. They require patience, a structural opening and a victim organization that has not adequately stress-tested its assumptions.

This article examines how the Canvas breach unfolded, the threat model behind it and what it reveals about the evolving cyber risk environment. It also outlines how organizations should strengthen incident response (IR) planning, cross-functional governance and technical controls across SaaS and identity architectures.

See “Considerations for Improving Defenses to AI-Enabled Ransomware Attacks” (Jan. 14, 2026).

How a Design Risk Was Exploited at Scale

Instructure first detected unauthorized activity in Canvas on April 29, 2026. One week later, ShinyHunters gained additional access through a second vulnerability. Based on the understanding at the time of publication, the exposure window for this event totaled approximately one week.

Scope of Exfiltration

ShinyHunters claimed to have exfiltrated 3.65 terabytes of data covering approximately 275 million records from 8,809 educational institutions, including Harvard, Stanford, MIT, Columbia, and other Ivy League schools and major U.S. universities. Although Instructure has not independently confirmed the full scope of the claimed exfiltration, the company acknowledged exposure of usernames, email addresses, enrollment information and private messages. Instructure subsequently confirmed a ransom agreement under which the stolen data was reportedly destroyed.

Private messages on Canvas routinely contain sensitive student communications: accommodation requests, Title IX disclosures, mental health conversations with advisers and other personally sensitive information that falls outside the financial or government identifier categories organizations typically prioritize in breach impact assessments. That data profile creates distinct exposure under the Family Educational Rights and Privacy Act (FERPA) and a range of state privacy laws, and underscores that breach severity cannot be reduced to the presence or absence of Social Security numbers.

Attack Vector and Methodology

The attack vector was Canvas’ Free-for-Teacher program, which had a low-friction onboarding feature that permitted educators to open accounts on the platform without any credential check by their institutional employer. Public reporting indicates that because those unverified accounts ran on the same production infrastructure serving verified institutional users, no enforced architectural barrier separated the two populations at the trust level.

ShinyHunters exploited Canvas’ Free-for-Teacher infrastructure by presenting account behavior functionally indistinguishable from a verified educator, injecting malicious code that allowed it to obtain an authorization token and gain elevated access, thereby sustaining access without triggering detection controls. Early reporting also indicated that the attackers may have secured write-level permissions within the platform, as evidenced by the subsequent replacement of Canvas login pages with a ransom message, a capability that goes beyond passive data extraction.

This was also Instructure’s second confirmed compromise by ShinyHunters within eight months. As publicly reported, the September 2025 breach involved a social engineering–driven compromise of Instructure’s Salesforce business systems, rather than a vulnerability in the Canvas platform itself. By contrast, the May 2026 breach targeted a structurally distinct weakness in the Canvas platform. Two confirmed breaches of different attack surfaces by the same actor within eight months raise serious questions about the scope and effectiveness of post-incident remediation after the first compromise.

Understanding the ShinyHunters Threat Model

ShinyHunters has been active since at least 2020 and has operated with a consistency and sophistication that distinguishes it from opportunistic criminal actors. The group has claimed or been attributed responsibility for breaches at Ticketmaster, McGraw Hill, Panera Bread, Infinite Campus, Udemy and multiple Salesforce customer environments, among others. Core members are believed to be based in Canada and France.

Google Threat Intelligence has documented ShinyHunters’ evolution from bulk database theft to an operationally complex model that combines AI-enabled voice phishing, single sign-on credential harvesting, multi-factor authentication (MFA) bypass and cross-platform lateral movement. Analysts have described the group’s current capabilities as combining LLM-powered voice infrastructure with credential phishing in ways that allow synthetic calls to adapt mid-conversation, generating campaigns indistinguishable from authentic communications. The group has also been linked to collaborative operations with other threat actors, including Scattered Spider, reflecting an increasingly interconnected criminal ecosystem where initial access, data exfiltration and monetization are distributed functions rather than singular operations.

The Canvas breach reflects an evolution within that model. Unlike prior ShinyHunters operations that relied on social engineering for initial access, the Canvas intrusion exploited a structural platform design weakness. The group’s core extortion mechanics, including large-scale data exfiltration, timed ransom demands and public leak threats as leverage, remained consistent.

Against that backdrop, organizations should treat ShinyHunters as a sophisticated extortion enterprise targeting centralized platforms with large data footprints, not as an education-sector problem.

See “Mitigating Cyber Risks From AI and Ever-Stealthier Adversaries” (Apr. 8, 2026).

A Global Threat Environment That Demands Urgency

The Canvas breach is not an isolated event. The Verizon 2026 Data Breach Investigations Report documented a 60‑percent increase in third-party involvement in confirmed breaches, with such participation now present in 48 percent of all breaches. The IBM Cost of a Data Breach Report 2025 reflects that U.S. organizations reached a record average breach cost of $10.22 million in 2025, driven by regulatory penalties and detection delays. Security teams take an average of 181 days to identify a breach and another 60 days to contain it, for a total lifecycle of 241 days, according to IBM. These timelines represent weeks during which exfiltrated data is monetized, regulatory exposure accrues and legal obligations run.

Global cybercrime damages were estimated to reach $10.5 trillion annually by the end of 2025. In 2026, ransomware appears in nearly half of all breach chains. The World Economic Forum reports that 65 percent of large organizations identified third-party and supply-chain risk as their single biggest cyber resilience barrier. At the same time, AI is enabling attackers to automate and industrialize social engineering at a scale and fidelity that renders prior awareness training inadequate as a primary control. Organizations that treat cybersecurity solely as a compliance function rather than as both a compliance function and an operational risk management discipline will learn those lessons at increasing cost.

See “Leading Attack Vectors and Other Key Findings From Verizon 2025 Data Breach Investigations Report” (Jun. 25, 2025).

Building a Defensible Incident Response Program

Drafting and Maintaining an IR Plan That Performs Under Pressure

Most organizations have an IR plan. Fewer have one that performs under crisis conditions. The distinction lies in specificity and pre-authorization.

Identify Key Players and Communication Processes

A plan that says “notify legal” is not a sufficient IR plan. An effective plan specifies who notifies legal, via what channel, within what time frame, and who in legal receives the notification and has authority to act without escalation delay. It identifies the organization’s pre-vetted external forensics and IR provider, the conditions for activation and the designated authority to engage without waiting for additional approvals. Every hour spent identifying an IR vendor during an active incident is another hour the attacker spends inside the environment.

See “When the Phones Ring: What 100 Security Breaches Reveal About Candor, Fear and Trust in Crisis” (Apr. 1, 2026).

Include an Authorization Map

One persistent gap is the “authorization cliff” between detection and action. Organizations should identify in advance which response actions (e.g., network segmentation, credential resets or external notifications) require executive approval and which can be executed by the technical team under pre-delegated authority. The authorization map should be tested, not assumed.

Set Advance Approval for Extortion Scenarios

Effective plans also address extortion scenarios directly. Given the prevalence of ransom-based attacks (including Canvas itself), organizations should define in advance the financial thresholds and decision authority for ransom payment consideration, the legal and Office of Foreign Asset Controls/sanctions compliance review that must precede any payment authorization, and the role of the organization’s cyber insurance carrier in those decisions. Legal teams should be embedded in this pre-authorization matrix before an incident occurs, not called reactively after the attacker’s clock is already running.

Specify Notification Workflows and Legal Hold Protocol

Notification workflows require equivalent specificity. Pre-drafted notification templates should be segmented by regulatory regime, including applicable state breach notification laws, GDPR, FERPA, HIPAA and any sector-specific requirements. Templates should be version-controlled, reviewed after each material regulatory change and assigned a named owner.

The plan should also specify the legal hold protocol, including the time frame and the process for preserving forensic artifacts in a form usable in regulatory investigations and litigation without compromising the ongoing technical response.

See “What Companies Can Learn From Blackbaud’s Ransomware Experience: Lessons From the GC” (Jul. 23, 2025).

Tabletop Exercises: From Discussion to Rehearsal

The value of an IR plan depends entirely on how well it has been rehearsed. Tabletop exercises are well established in mature security programs and should focus on stress-testing the organization’s decision-making architecture.

Conduct Regular and Focused Exercises

Exercises should occur at least twice annually, with at least one exercise each year focused on the threat scenarios most relevant to the organization’s actual vendor and data ecosystem. For organizations that rely heavily on SaaS platforms, a third-party supply chain compromise scenario modeled on the Canvas breach is directly applicable and more useful than a generic ransomware scenario.

Inject Complications

Effective tabletop exercises use injects rather than scripted narratives. Facilitators should introduce evolving complications mid-exercise, such as a second affected system discovered after initial containment, a ransom deadline announced publicly before internal notification protocols are complete or a media inquiry arriving before the communications team has cleared messaging. These injects can help expose gaps in the escalation chain and notification workflow that might otherwise be missed.

Include All Stakeholders

Every exercise should include the full decision-making cohort, which should consist of technical IR personnel, the CIO, the CISO, in-house legal counsel (including privacy counsel), outside counsel, communications staff, and, at least annually, board members or executive leadership.

Board-level exercises ensure executive decision-makers understand the authority they will be asked to exercise and the tradeoffs they will face under real-time pressure. The Cybersecurity and Infrastructure Security Agency’s Tabletop Exercise Packages program provides customizable scenario frameworks, including supply chain compromise and ransomware scenarios that organizations can adapt to their specific risk profile.

Prepare Reports

Every tabletop should produce a written after-action report identifying specific gaps, named owners and remediation timelines with accountability checkpoints. Without that documentation, the exercise generates conversation but not organizational improvement.

See this two-part series on a mock cyber incident tabletop exercise: “Day One, Everything at Once” (Jun. 19, 2024), and “Day Two and Beyond” (Jun. 26, 2024).

Cyber Preparedness: Aligning the CIO, CISO, Legal and Privacy Functions

Organizational fragmentation remains the most persistent structural failure in corporate cybersecurity. Technical teams design controls without full visibility into the legal and regulatory exposure created by specific data types. Legal teams advise on notification obligations without understanding the technical timeline of breach detection and containment. Privacy teams conduct assessments that do not meaningfully reflect or inform the technical control architecture. The result is parallel tracks that converge only under crisis conditions, when the cost of fragmentation is highest.

Mapping Data

Minimizing fragmentation starts with a shared data map. Organizations cannot protect what they do not know they hold, and they cannot respond appropriately to a breach involving data they have not inventoried. Privacy teams typically own data mapping in the compliance context, but CISOs and CIOs must be partners in that mapping for access control design, segmentation priorities and monitoring coverage.

The Canvas breach is instructive here. The most sensitive data exposed – private student communications touching health, accommodation and Title IX contexts – fell outside the financial and government identifier categories that standard breach assessment frameworks prioritize. Organizations that rely solely on those standard categories will systematically underestimate their regulatory and reputational exposure from SaaS platform breaches.

Vetting Vendors

Vendor and third-party SaaS governance requires genuine joint ownership rather than sequential review. Procurement should include legal review of vendor contracts for audit rights, notification obligations (time-bound, not merely “prompt”) and SLA provisions for security incident disclosure, alongside the CISO’s technical assessment of authentication requirements and tenant isolation architecture. The Canvas breach illustrates what happens when institutional trust in platform vendors is extended without examining the underlying security architecture, including the decision to share production infrastructure across verified and unverified account types.

Coordinating Across Functions

Joint governance structures provide a mechanism for coordination that crisis conditions cannot substitute. A cross-functional working group – including CIO, CISO, legal and privacy leadership – should meet at defined intervals to review relevant threat intelligence, approve IR plan updates and oversee the tabletop exercise program. These groups should also establish unified escalation protocols that clarify who leads, who advises, and who communicates internally and externally at each phase of an incident, with that protocol reflected in the IR plan and rehearsed in tabletop exercises.

Outside counsel advising corporate clients should be integrated into this framework before an incident occurs. Outside privacy and cybersecurity counsel should review IR plans and participate in tabletop exercises. Pre-integration is critical when the ransom deadline clock starts running.

See “A Practical Cross-Functional Framework for Efficiently Driving Risk and Compliance Decisions” (Mar. 4, 2026).

Technical Protections: Moving From Policy to Architecture

Third-Party and SaaS Vendor Risk Management

A consistent attacker logic runs through the Canvas breach and the broader pattern of SaaS credential attacks. As organizations harden perimeter controls, adversaries pivot to the SaaS platforms operating inside the perimeter with legitimate credentials. Organizations should require phishing-resistant MFA as a baseline condition of any SaaS vendor relationship handling sensitive data.

Vendor contracts should specify enforceable security requirements, including MFA requirements for accounts with access to customer data, logging obligations and audit log retention periods, breach notification time frames and the right to audit vendor security posture through third-party assessors. These provisions must be periodically verified. Annual vendor security reviews or continuous monitoring through vendor risk management platforms operationalize the provisions to give them practical force rather than allowing them to become dormant boilerplate contractual language.

See “Benchmarking Threats and Approaches to SaaS Security” (Sep. 3, 2025).

Identity and Access Management

Internal architecture requires the same rigor as third-party risk management. Multi-tenant SaaS environments require explicit tenant isolation controls and low-friction onboarding programs, which must be evaluated against their security implications, not just their adoption goals. Canvas illustrates both points. CIOs and CISOs evaluating SaaS platforms should ask vendors directly how unverified or free-tier accounts are isolated from enterprise tenant infrastructure. Inadequate answers to that question should be treated as a material risk factor.

Internally, a least-privilege access architecture remains the most effective structural control against lateral movement once an attacker has obtained any valid credential. Privilege reviews should occur on a defined schedule, typically quarterly for elevated-access accounts and annually for standard accounts, and should be triggered by role changes. Application programming interface credentials and open authorization access tokens require particular attention. Long-lived service credentials and tokens are a persistent attacker target precisely because they are frequently provisioned and then forgotten. Rotating these credentials on a defined cycle and inventorying all active tokens should be executed as a recurring IT hygiene function.

See “Staying Ahead of Rising Identity-Based and Cloud Intrusions” (Mar. 19, 2025).

Detection, Logging and Visibility

Detection determines whether any of the aforementioned identity and access management measures are activated in time. The Canvas exposure window ran approximately one week. During that period, ShinyHunters is reported to have operated with access patterns that mimicked legitimate users. Effective detection under those conditions requires behavioral baselines capable of identifying anomalous activity even when credentials are valid. Security information and event systems combined with user and entity behavior analytics provide the visibility that signature-based detection alone cannot supply against insider-mimicry attack patterns.

Further, many organizations have logging architecture that was designed for on-premises or internal systems and does not extend comprehensively to the SaaS environments where data also resides. To address this visibility gap, cloud access security tools can assist with visibility and policy enforcement between the organization and its SaaS environment that direct platform logging may not adequately cover. Even with these tools, log retention policy should be set with regulatory investigation timelines in mind, because logs overwritten before a breach is detected are unavailable for forensic analysis, notification scoping and regulatory response.

The Canvas breach will not be the last large-scale SaaS platform compromise. The education sector was targeted because it holds centralized, high-value data in platforms with comparatively weaker security investment and limited tenant isolation. That attack calculus applies to every sector where SaaS platforms aggregate sensitive data at scale.

What differentiates outcomes is organizational preparedness. The organizations that contain breaches, notify accurately and on time, and preserve trust with regulators are not necessarily those that were never compromised. They are the organizations that rehearsed the response, integrated their legal and technical functions before the incident, and built governance structures that enable coordinated action when time pressure is imposed from outside.

The gap between organizations that navigate cyber incidents effectively and those that do not is rarely a technical capability gap alone. It is an organizational, legal and governance gap. Closing it requires investment before the ransom clock starts.

 

Lynn Parker Dupree is the leader of Finnegan’s privacy practice and focuses on privacy compliance, governance and counseling for clients navigating the dynamic privacy landscape. Prior to joining the firm, she served as the Department of Homeland Security CPO, responsible for advising the secretary of homeland security on a wide variety of matters involving privacy for the Department as well as ensuring its compliance with privacy laws, regulations and federal guidance. She provided advice on AI governance, the collection and use of biometric data, and the deployment of technologies that collect identifiable data. She was also responsible for the Department’s data breach response and remediation as well as privacy preparedness for cybersecurity breaches and incidents.

LaQuan Bates is an associate at Finnegan. He focuses on IP matters related to data privacy, AI, false advertising, trademark, copyright and technology law.

Nico Prentosito is a student law clerk at Finnegan.

Executive Orders

Breaking Down the Trump AI Executive Order and Its Implications for the Private Sector


President Trump’s June 2, 2026, executive order on AI and cybersecurity (AI EO) seeks to mobilize the federal government to strengthen cyber defenses across government information systems and critical infrastructure. It directs federal agencies to harness AI to develop defensive tools to help identify and eliminate emerging threats while establishing forums for AI developers to share information and improve collective response capabilities. The AI EO also signals a heightened federal law enforcement focus on threat actors who use AI to carry out cyberattacks.

This article, with expert insight from Jenner & Block, Mayer Brown and Pillsbury, provides an overview of the AI EO’s provisions, discusses its potential implications for private companies and offers key considerations for participation in the programs it aims to create.

See “Staying Compliant After Trump AI Executive Order Introduces Regulatory Uncertainty” (Jan. 14, 2026).

Three Main Initiatives

Through the AI EO, the “administration is making cyber defense a priority,” Brian Finch, a partner at Pillsbury, told the Cybersecurity Law Report.

The AI EO seeks to promote AI innovation and security by modernizing and hardening government and private information systems through public‑private collaboration, developing advanced AI capabilities, safeguarding U.S. systems and intellectual property from exploitation and theft, and cultivating the nation’s “advanced AI-enabled capabilities.” It furthers these objectives through three main initiatives: upgrading information systems for advanced AI, securing frontier model development and enhancing criminal enforcement against AI‑driven threats.

Upgrading Information Systems

Section 2 of the AI EO requires certain executive departments and federal agencies to take a variety of coordinated actions within 30 days to support the cybersecurity of National Security Systems (as defined in the Federal Information Security Modernization Act of 2014), civilian federal government information systems – which span the IT networks, hardware and software used by Federal Civilian Executive Branch agencies to deliver public services – and operators of critical infrastructure.

Through the provisions in Section 3 of the AI EO, the government is trying to address challenges similar to those that arise in the private sector, including selecting the best AI tools and managing outputs generated at a significantly faster pace, Stephen Lilley, a partner at Mayer Brown, told the Cybersecurity Law Report.

Prioritization of National Security System Cybersecurity

The AI EO directs the Committee on National Security Systems to “prioritize” the cyber defense of national security systems. In addition, the secretary of war must prioritize the cyber defense of Department of War information systems.

DHS Operational Directives

Furthermore, the AI EO requires the secretary of homeland security to issue binding operational directives to:

  • “expedite and prioritize the cyber defense of civilian Federal Government information systems”;
  • “establish or expand Federal programs and cybersecurity services that enhance AI-enabled defensive tools”; and
  • “facilitate access to cybersecurity tools and services including, where appropriate, covered frontier models for agencies, State and local authorities, and operators of critical infrastructure such as rural hospitals, community banks, and local utilities.”

The AI EO provides impetus to the Department of Homeland Security (DHS) “to move the needle on getting vulnerabilities addressed as soon as possible,” Finch said. “When DHS issues a binding directive, that makes things move a lot faster,” he added.

See “Eyewitness Accounts and Recommended Actions to Counter AI’s Strain on Cyber Defense” (May 6, 2026).

Creation of AI Cybersecurity Clearinghouse

The AI EO also commands the secretary of the treasury, in consultation with several departments and agencies, to establish an “AI cybersecurity clearinghouse” in collaboration with both the AI industry and critical infrastructure operators. The stated goals are to coordinate and deconflict scanning for software vulnerabilities, discover and validate those vulnerabilities, and prioritize patching, remediation and distribution.

The director of the Office of Management and Budget is to determine whether federal grant programs have funding for entities that develop advanced AI vulnerability detection. Also, the director of the Office of Personnel Management is directed to expand hiring and placement of U.S. Tech Force information cybersecurity specialists.

This is an area where the federal government is trying to share its learnings and “provide an ecosystem” regarding the cybersecurity implications for critical infrastructure in particular, Aaron Cooper, a partner at Jenner & Block, told the Cybersecurity Law Report.

Securing Frontier Model Development

Section 3 of the AI EO requires the Treasury Department, in consultation with the National Security Agency, the Cybersecurity and Infrastructure Security Agency and other entities, to implement processes for identifying frontier AI models that could participate with the federal government in a voluntary program granting the government pre-release access to the models. A classified benchmarking process will be used to establish a threshold for designation as a covered frontier model.

Although there will be some degree of public uncertainty about what will be covered, whatever objective criteria are ultimately used will likely be flexible enough to capture models of interest, Lilley posited.

The designated government entities are directed to work with AI developers to build a voluntary framework to determine what AI models under development are covered. Participating companies would grant the government access to their covered AI models for up to 30 days before releasing them to “trusted partners” chosen in collaboration with the AI developers and the federal government. The goal of access is to “promote secure innovation and strengthen the cybersecurity of critical infrastructure.”

The AI EO specifically states that it does not “authorize the creation of a mandatory governmental licensing, preclearance, or permitting requirement for the development, publication, release, or distribution of new AI models, including frontier models.”

It is uncertain whether this is a truly voluntary framework, Cooper maintained. Although the AI EO is clear that it does not create any mandatory government licensing scheme, the federal government is one of the biggest customers for frontier AI models, he noted. “It is the elephant in the room,” he said.

Criminal Law Enforcement

Section 4 of the AI EO requires the U.S. AG to prioritize the enforcement of applicable federal laws against threat actors who use AI to “illegally access or damage a computer without authorization,” or use “AI while engaged in such illegal access to further any other crime.” Enforcement will target breaches of both public and private IT systems, as well as anyone using AI agents “to unlawfully access data or information that is subsequently used for a criminal or unlawful purpose.”

The AI EO’s criminal enforcement directive provides that the tools that the DOJ has used to combat cyberthreats such as the anti-hacking statute - the Computer Fraud and Abuse Act – will also apply to the illegal and harmful use of AI, Cooper said.

It is a fairly broad directive to the DOJ to “put the hammer” to those using AI in a malicious manner, Finch observed.

See “What CCOs Should Know About the DOJ’s Efforts to Curtail Criminal Use of AI” (Oct. 9, 2024).

No New Obligations, but an Impetus for Action

The AI EO does not create new obligations for private companies developing or deploying AI tools, Finch said. “The administration is very clear that it does not want to regulate or increase standards when it comes to AI.” It is doing everything that it can to encourage development, he remarked.

Nonetheless, the processes prescribed by the AI EO may impact standards and expectations for AI companies.

If the government develops a vision of how AI tools should be integrated into the federal system, that vision could be incorporated into regulatory guidance or federal contracts, incentivize the private sector to act in a certain way and become a template for private companies, Lilley suggested.

The federal benchmarking standard is likely to become the private market norm for frontier AI developers, Finch predicted.

The AI EO’s focus on the cybersecurity risks of AI and taking action in response to them is a signal to private companies to follow suit, Cooper stated. Companies will be able to see how the government identifies and defends against AI risk and can “pick and choose” what might work for them, he offered.

Government contractors will pay more attention to the AI EO than other companies, but other companies still “absolutely need to consider” it, Finch advised.

Preparing for Participation in Cybersecurity Clearinghouse

Identifying Private-Sector Opportunities

The clearinghouse will present opportunities for both providers and users of AI cybersecurity tools.

The government’s focus on addressing its information system vulnerabilities with AI-powered defenses will create many opportunities for IT companies providing security tools, Finch said. On the user end, utilities that operate critical infrastructure will “lead the way” with respect to participation due to their concerns about AI risk and desire for access to government resources, he predicted.

As the federal government develops a clearer view of the tools it wishes to deploy and standards it expects, there will be an opportunity for the private sector to “help with the uplift,” Lilley said.

Companies involved in critical infrastructure should look for public announcements from the various federal departments and agencies to see what vulnerabilities are being shared and what the potential benefits of collaboration are, Cooper recommended.

Establishing Processes

Companies can prepare internally to participate in the clearinghouse by establishing communication channels within the organization for exchanging information, Cooper suggested. They should also assess what types of information they might wish to share with the government and weigh the risks of such sharing – including determining what laws may prohibit it or what protections may apply, such as the Cybersecurity Information Sharing Act of 2015 (CISA), he advised.

Participants in the clearinghouse will enhance the odds of the programs working out well for them by trying to build close relationships with relevant stakeholders within the government, maintaining effective channels of communication with them and understanding how to utilize available processes to build out the programs, Lilley said.

Deciding on Terms

The government is likely to dictate many of the terms of the agreements with companies that participate in the program, Finch asserted. The provisions that are most likely to be the subject of negotiations are the liability protections and antitrust exemptions, he predicted. However, companies will have at least some leverage. “The government is interested in having these companies participate,” he stressed, adding, “if nobody shows up, that’s a fail.”

To protect themselves from liability, participating companies may want to look to existing safe harbor statutes. For example, Finch noted, the Support Anti-Terrorism by Fostering Effective Technologies Act of 2002 allows companies offering physical and cybersecurity counterterrorism tools to apply to DHS to limit or eliminate tort liability in connection with terrorist attacks and cyberattacks, and CISA protects companies from liability for sharing cyber threat information, such as a vulnerability about a competitor’s product.

Preparing for the Frontier Developer Program

Determining Whether a Model Is Covered

The first step for companies wishing to participate in the voluntary AI framework, which grants the government access to their covered AI models for up to 30 days before releasing them, is to determine whether they operate a covered frontier model, Finch said.

The proposed benchmarking process that will be used to establish a threshold for what will be designated as a covered frontier model raises certain questions, Cooper noted. If the process is classified, it is unclear how a developer will know in advance whether the model it is developing meets the benchmark, or who at the company might have security clearance to understand the process, he said.

Considering Risks of Participation

Covered developers will have to decide whether they want to participate in the program. They should consider whether they are willing to risk tying an AI model to certain processes, Cooper noted. For example, participation might lock in certain protocols – such as what pre-release testing should involve or what confidentiality protections should look like – that may later be difficult to deviate from, he stated. On the other hand, a company may desire to shape the government’s approach, he suggested.

A developer wishing to participate in the voluntary framework should also consider other potential risks. It is speculative, but one potential downside is that collaboration could produce discoverable materials that could subject a company to liability, Lilley cautioned. The flip side is that the program will enhance security for all participants by turning out products that create less legal risk down the road, he said.

If a developer does participate, it needs to address the security risks posed by granting access, including insider threats and the possibility that government systems will be hacked, Cooper advised. Indeed, foreign adversaries could view the program as a vector, he cautioned.

Risk can be addressed in several ways: through program rules; contractually, using non-disclosure agreements or memoranda of understanding; or labelling that triggers legal and regulatory protections, Cooper affirmed. Technical measures could include controlling the systems on which the models reside, monitoring them during testing, controlling the testing parameters and limiting access to certain personnel, he suggested. Developers should take as many precautions as they can, he recommended, emphasizing that “nothing is really off the table.”

Planning for Engagement With the Government on Assessed Risks

Participating companies should prepare in advance for how to respond if the federal government concludes that their model has risks, Finch said. This will involve making business decisions as to whether to fight or assent to any requested changes, he explained. It should include analyzing what the changes could mean for the business - for example, how it may affect notification obligations – and whether they could slow or even halt monetization of the model, he recommended. And if the company does decide to engage, it should be prepared to discuss the model’s controls and the limitations that can be placed on them, as well as ensure that they have processes in place to make the modifications, he stated.

Enforcement Outlook

The criminal enforcement provisions of the AI EO are a signal of the DOJ’s future priorities around crimes involving the use of AI.

By targeting the “next frontier” – the malicious use of AI agents – the AI EO makes clear that bad actors cannot avoid culpability simply by acting through an AI agent, Cooper observed. The AI EO may also capture actors that do not commit the crime but provide a technology or infrastructure for criminal purposes, he posited.

Criminal prosecution is not an everyday occurrence in the cyber context, and the AI EO sends a signal that prosecution of cybercrimes should be prioritized, Lilley said. The likelihood of prosecution increases if AI is used in a harmful way, he opined. “However, it does not change the law, and this section of the EO is less likely to substantially affect companies,” he noted.

See our two-part series on AI agent security: “Companies See Rogue Incidents but Lag on Controls” (Mar. 18, 2026), and “What CISOs and GCs Need to Know to Defend the Enterprise” (Mar. 25, 2026).

Benchmarking

AlixPartners Survey Finds Companies’ Risk Readiness Lags Awareness


Many U.S. companies are not prepared to face several key business risks, even as compliance teams are aware of them, according to AlixPartners’ 2026 U.S. Risk Survey (Survey). The Survey found that the absence of prescriptive federal rules on AI is exacerbating risks, and that financial crime and corporate disputes are on the rise, but companies are not mitigating these risks effectively.

The Survey collates responses obtained in February from 500 U.S. senior executives in legal, compliance and regulatory roles. The U.S.-headquartered companies where they are employed span multiple sectors, particularly financial services, technology, healthcare and life sciences, manufacturing and retail.

Lisa Osofsky, a partner with the firm who was among the Survey’s authors, spoke to the Cybersecurity Law Report about the Survey results and what lessons companies should take away from the findings. This article distills insights from the Survey along with her comments.

See our two-part series on the AI laws in Colorado and Connecticut: “Mapping Scope and Core Provisions” (Jun. 10, 2026), and “Preparing to Comply” (Jun. 17, 2026).

Preparedness Lags Awareness of Issues

The Survey shows that, despite respondents being aware of several key areas of risk, they feel their companies’ preparedness for those risks lags behind that awareness.

There is “so much info coming in to leaders and yet they do not feel prepared,” Osofsky noted. Several findings in the Survey indicate that the level of risk awareness is not matched by “execution to alleviate or ameliorate the risk,” she commented. She described this as “a challenging place to be,” analogous to “sitting on a ticking time bomb.”

While company executives are aware that their companies are vulnerable to key risk areas, they face challenges with resourcing and technology to address those, Osofsky remarked.

Executives “who sit in many different chairs within corporates” are conscious of this discrepancy, Osofsky said. “Boards and leaders do not necessarily feel they have the tools to manage some of these risks, wherever they sit within the organization,” she commented.

Regulatory Confusion Around AI

The Survey identifies AI as one area of confusion and risk facing companies today.

Lax Federal Rules Disorient Executives

The absence of prescriptive federal rules creates a compliance risk, according to the Survey. The second Trump administration has opted for a “relaxed framing” with an “innovation-first” approach and reduced regulatory oversight, the Survey says.

The Survey points to the administration’s December 2025 executive order, which states an aim to establish a “minimally burdensome national standard” for AI regulation. The Survey also highlights the White House’s March 2026 issuance of a national policy framework on AI, directing Congress to regulate AI via existing rulemaking bodies, not to create a new federal entity, and to preempt state AI laws “that impose undue burdens.”

In this sense, federal policy on AI has shifted significantly under the second Trump administration, according to the Survey. Eight in 10 respondents said the way in which federal AI policy is developing poses strategic risk to corporate compliance efforts.

Companies believe they are disadvantaged by the ambiguity that comes from not having prescriptive rules, Osofsky maintained. It raises uncertainty as to how company leaders are supposed to prioritize compliance resources, she argued.

See “Staying Compliant After Trump AI Executive Order Introduces Regulatory Uncertainty” (Jan. 14, 2026).

Federal, State and Foreign AI Rules Differ

In contrast with the federal government, some U.S. states have been enforcing increasingly stringent guidelines on AI, and the E.U. is advancing more prescriptive AI requirements, the Survey notes. This means companies find themselves navigating a patchwork of different regulations, it says.

The Survey found that 80% of respondents described this fragmented regulatory landscape as putting their compliance efforts at risk.

Clear rules are helpful for compliance, Osofsky emphasized. Compliance is much harder when “many different types of regulators” apply contrasting rules, she said.

However, the patchwork of different regulations “can be managed,” Osofsky stressed. There are areas in which businesses already “manage that sort of divergence,” she pointed out. The insurance industry works across multiple U.S. states and successfully manages the challenges of “different regulators and different levels of regulation,” for example.

See “Recent Developments and Upcoming Obligations Under the E.U. AI Act” (Feb. 4, 2026).

Many Companies Lack AI Governance Structures

The Survey raises the alarm that, even as AI penetrates further into U.S. businesses, almost half of respondents say their companies lack key elements of AI governance. Nearly half (45%) of respondents said their companies do not have their own AI governing body or committee, board engagement with the topic, external AI consultants helping them or a person designated as head of AI.

Many corporations have not fully “gotten their arms around AI governance,” Osofsky noted. Many have yet to install “escalation processes around issues that might get raised in this area.”

A trend the survey uncovers is that many companies lack “proactive parameters” around AI use, Osofsky said. Among the questions that remain largely unanswered is: “What sorts of professional skills are needed within our organization to combat these issues?”

See “AI Governance: Striking the Balance Between Innovation, Ethics and Accountability” (Feb. 12, 2025).

Training Versus Outsourcing

While companies could benefit from working with more professionals with specific AI training, they need to weigh whether this means training their own employees or hiring outside consultants, according to Osofsky.

“Part of the problem is headcount restrictions,” Osofsky explained. For some companies, a better option is to “go outside” and hire consultants “who come in and can do some of the work.”

Cybersecurity and Data Privacy Rank High Among Worries

Cybersecurity incidents rank as an increasingly concerning risk event in the next 12 months, and data privacy concerns are rising too, the Survey found. Sixty-five percent of respondents described cybersecurity incidents as being “among the most concerning risk events for their organization over the next 12 months,” while 58% said the same about data privacy events. In a year-over-year comparison, both these figures were up substantially from AlixPartners’ corresponding study a year earlier, rising from 49% and 33%, respectively.

Concerns Around Cyberattacks

The Survey results “confirm my view that cyber is on the minds of many board members,” Osofsky said. This is a field in which there can be “big breaches, important issues and big financial ramifications,” she commented.

The past year has seen “major ransomware attacks by state-sponsored actors, supply-chain incursions exploiting third-party software, and a surge in AI-powered phishing scams,” the Survey relates.

Only 48% of respondents described themselves as “very prepared” to address cyber threats in 2026, while 52% said the same in connection with data privacy.

“It would help corporate leaders wherever they sit, especially if they sit in a board or CEO spot where they are making decisions, if they felt they had enough of the right tools,” Osofsky commented.

The Survey termed AI-powered cyberattacks “a critical risk frontier.” Survey respondents who cited this as a top cybersecurity concern represented 34% of the total, doubling from 17% last year. At the same time, the Survey notes that “nearly 75% have not yet completed system upgrades to address such threats.”

See “Understanding and Mitigating Six Key Cyber Threats” (May 6, 2026).

Data Privacy Challenges

Survey respondents indicated some consensus about ways to address data privacy challenges, but there is a shortfall in implementation. While 73% said enhancing data encryption is one of the most important measures, putting it at the top of that list, only 50% said their companies are already doing this or planning to in 2026.

The second and third most-agreed-upon data privacy strategies showed a similar shortfall between recognition and implementation. Deploying privacy-enhancing technology is something 65% of respondents deemed important but only 54% are putting into action. The third most-affirmed option was collaborating with the government and regulators with a view to keeping abreast of pending enforcement actions. While 65% of respondents said this was important, only 53% said they were taking steps in that direction.

Data privacy, like AI, is an area where companies have to navigate a patchwork of contrasting rules, the Survey notes. “Federal data privacy approaches have shifted toward more voluntary compliance,” but “many states have moved forward with their own laws.”

See “Vermont’s Stringent Privacy Law and Louisiana’s Fast Compliance Timeline Amplify Enforcement Risk” (Jun. 24, 2026).

Financial Crime Poses a Serious and Rising Risk

Financial crime, including fraud and money laundering, is a major risk area that only 48% of respondents feel “very prepared” to address in 2026, despite fraud being on the rise, the Survey says.

Enforcement Is Shifting

Concerns about financial fraud arise against a backdrop of shifting U.S. enforcement, the Survey notes. Federal entities, including the DOJ, are placing more emphasis on investigating fraud involving public funds, and on tariff evasion and customs issues, but scaling back efforts in traditional white-collar crime areas like foreign bribery, it elaborates.

U.S. fines for money laundering and sanctions breaches fell an estimated 61% last year, while other countries are stepping up enforcement in those areas, according to the Survey. This raises concerns for U.S. multinationals operating across different jurisdictions, it says.

Confidence in Risk Detection Technologies Falls

Risk detection technologies that can help identify financial crime enjoy the confidence of only 36% of respondents. This contrasts with last year, when the firm conducted similar research and 56% of respondents voiced confidence in them, the Survey says.

There have been successful applications of technology in areas including transaction monitoring, sanctions monitoring, know-your-customer and third-party risk exposure, Osofsky noted. “There has been an incredible use of technology in a very positive way,” she said.

While AI can be used to detect financial crime, it is also something that is being used by perpetrators of financial crime with increasing sophistication, creating what the Survey termed an “arms race.”

AI is an important example of technologies that can aid in combating financial crime, Osofsky mentioned. However, executives feel “a lack of confidence” in what AI can do for them, “which is why human oversight is critical in this process,” she said.

Sanctions Risks Reflect Geopolitical Upheaval

In the area of sanctions, many companies are evidently unready for ongoing changes and geopolitical impacts, according to the Survey. This is especially concerning since, according to the Survey, sanctions “impact virtually every sector.”

“People are more and more worried” about sanctions, an area in which there is much “volatility” and “very rapid change,” Osofsky commented.

The 35% of respondents who said their organizations are “very prepared” for potential changes in sanctions is down from 44% in 2025.

These statistics may be less of a reflection of the systems companies have in place to deal with sanctions, and more of a reflection of the constant changes in the geopolitical landscape. Companies are “getting increasingly sophisticated around sanctions generally” but still feel “underprepared, even compared to last year,” Osofsky observed. A company may have excellent systems to monitor sanctions issues, but still have difficulties, because sanctions are changing quite rapidly all over the world, she said.

In the U.S., sanctions enforcement remains a priority, the Survey notes. In the first half of 2026, the Department of the Treasury’s Office of Foreign Assets Control has sanctioned entities and individuals linked to activities “ranging from stealing U.S. trade secrets to funding terrorism to narcotics trafficking,” it says.

The Survey also found a rising lack of preparedness concerning other risks that stem from international and trade tensions. Sixty-five percent of organizations are not “very prepared” to address geopolitical and trade impacts on operations, up from 61% in 2025, it reports. It also found that 68% are not “very prepared” to address supply chain disruptions, down from 59% last year.

Corporate Disputes Are an Escalating Concern

Corporate disputes represent a rising area of corporate risk, according to Survey respondents. The Survey defines the category as “commercial litigation and arbitration outside of government regulatory actions.”

Although corporate disputes are already at “multi-year highs,” 63% of respondents anticipate an increase in the coming year.

This expectation is unsurprising given “major market swings, whipsawing trade policy, and record class-action settlements,” the Survey suggests.

Corporate executives are worried about disputes as they believe “there will be a complete boom in litigation,” Osofsky warned. She voiced agreement with many of the Survey respondents “in seeing more to come rather than less to come,” she said, particularly in the areas of sanctions and AI.

The Survey mentions securities and shareholder litigation, contract disputes, patent and intellectual property cases, and possible disputes stemming from a surge of M&A deals in 2025, such as “private antitrust fights and post-close disputes.” The Survey also highlights “continued momentum in class-action filings from the plaintiff’s bar as federal regulatory enforcement eases and some states enact stricter laws governing data privacy, AI, and labor and employment matters.” Moreover, the Survey emphasizes the possible corporate disputes that arise in the fields of cybersecurity and data breach risks, with 47% of respondents predicting more disputes in cybersecurity and data privacy.

See “Litigation Landscape for Cookie and Tracking Technology Claims Brought Under Federal Privacy Statutes” (Jan. 21, 2026).

Cryptocurrency Safeguards Are Lacking

Cryptocurrency is coming into increasing use in organizations’ payments and transactions, and, according to the Survey, “a lack of safeguards creates new risk.”

About a quarter (26%) of organizations are already using crypto for payments or settlements, and a further 33% have been testing use cases around crypto. Another 27% of respondents said their organizations are considering use, without a defined timeline for implementation yet.

The Survey found that 69% of the organizations that are currently using or testing crypto use cases have real-time or near-real-time monitoring for high-risk activity, and 67% of those organizations have enhanced due diligence for crypto-related clients or partners in place. However, the share who have more involved risk controls is lower: just 45% have escalation and off-ramp procedures in place, and 44% have third-party risk assessments for banking as a service and fintech partners, according to the Survey.

See “Illusory Systems Settlement Shows FTC Active and Focused on Crypto” (Feb. 4, 2026).

Takeaways

Osofsky identified a number of lessons she hoped professionals would take away from the Survey.

Risk Assessment Must Inform Prioritization

Companies need to conduct risk assessments so that they can prioritize their resources in addressing the multiple risks, Osofsky stressed. “Real risk assessment needs to be done, because there has to be a prioritization,” she explained. Each of the risks detailed in the Survey may sound like the “house is burning,” she noted, but companies need to make decisions on resource allocation based on a “proper risk assessment.”

AI Does Not Replace Human Judgment

The usefulness of AI in addressing risks, especially in the financial crime area, does not mean machines are “going to take over and there won’t be a need for people in decision-making,” Osofsky emphasized. The importance of “professionals trained in analyzing financial crime is critical to reviewing the results of any outputs of technology,” she said. There will always be a need for experienced humans when it comes to making “value judgments,” she predicted. Such professionals’ judgment is irreplaceable in “shaping where resources should go and shaping governance structures of companies.”

The Importance of Compliance

The Survey will hopefully reassure compliance professionals that their analyses of the risk environment are accurate and widely shared, Osofsky said. Moreover, the Survey may support compliance professionals in the arguments they wish to bring to company boards, she added.

Getting necessary resources “is ever more challenging,” partly due to “the global nature of business,” Osofsky said. The Survey may help compliance professionals see that “they are not the only compliance department that feels underprepared.”

The Survey can also serve to underline the danger of “letting AI get ahead of compliance,” Osofsky observed, and the need for governance structures. In addition, it can provide helpful back-up for compliance professionals highlighting the risks related to cryptocurrency, she suggested. “With the huge use of crypto, I would hope that compliance officers could bring these kinds of findings, and these kinds of identifications of risk, to their boards.” Across various risk categories, she hopes that the Survey will embolden compliance professionals in bringing issues to company leadership.