AI and Cybersecurity Rules Drive Shift in Corporate Governance
New U.S. SEC cybersecurity disclosure rules will make boards of public companies personally liable for oversight, exposing gaps in current compliance reporting. AI-driven governance tools often assume control mappings across standards like SOC 2, ISO 27001, PCI DSS and HIPAA are equivalent, a premise that NIST’s Set Theory Relationship Mapping shows is rarely true. This creates a risk that AI agents will affirm coverage that does not exist, misleading executives.
In Nigeria, company secretaries are being urged to move beyond record‑keeping to become strategic advisers who balance legal duties, cybersecurity threats, ESG demands and rapid technological change. While AI can automate data analysis, experts stress that human judgment, integrity and emotional intelligence remain essential for effective board governance and risk management.