started · updated
Companies grapple with AI‑driven risk and compliance challenges
By 2026, enterprises face a digital landscape where artificial intelligence (AI) amplifies both cyber threats and defensive capabilities. In Brazil, the rise of AI‑powered ransomware, deepfakes and sophisticated social‑engineering attacks is prompting firms to adopt advanced firewalls, AI‑based threat detection and multi‑factor authentication. The country’s data‑privacy law, LGPD, overseen by the ANPD, makes compliance a legal imperative, turning cybersecurity into a core business concern.
A Boston Consulting Group (BCG) study of more than 100 senior risk and compliance executives across seven regions found that over 90 % of organisations plan to increase investment in digital tools, advanced analytics and automation. Yet, generative AI use in risk functions remains largely experimental. Executives cite three forces reshaping risk agendas: fragmented geopolitics and regulations, vulnerable supply chains, and rising technological risks such as cyber‑security and data protection. As BCG’s Pedro Pereira noted, “Hoje, o risco já não pode ser gerido apenas através da conformidade.” Companies are urged to shift toward “AI‑first” operating models, redesigning risk and compliance processes from the ground up while ensuring algorithmic transparency, human oversight and ethical standards.