Artificial intelligence is becoming operational infrastructure
Organizations are rapidly adopting artificial intelligence. Customer service platforms generate responses using large language models. Developers rely on AI-assisted coding tools. Security teams analyse alerts with AI-powered products. Finance departments automate reporting. Human resources departments screen résumés and CVs. Legal teams use AI to review contracts, conduct legal research, and assist with document drafting. Procurement uses AI to summarise contracts.
In many organizations, AI is no longer an experimental technology. It has become part of day-to-day operations. That shift creates a new challenge. Much of the discussion surrounding AI focuses on governance, ethics, model risk, and cyber security. These are important topics, but they overlook another question: what happens when the AI that supports important business services is unavailable, produces unreliable results, or changes unexpectedly? That is fundamentally an operational resilience question.
Organizations have spent years strengthening their resilience to failures affecting data centres, cloud providers, telecommunications networks, and critical third-party services. Where AI supports important business services, the resulting dependencies deserve the same level of attention. As AI becomes embedded in important business processes, organizations must identify where they depend on it, understand the risks those dependencies create, and incorporate those dependencies into operational resilience planning.
AI is becoming a business dependency
AI increasingly influences decision-making, customer interactions, and operational workflows. Examples include:
- Customer service agents using AI to draft responses.
- Security analysts relying on AI to prioritise alerts.
- Developers using AI-generated code.
- Risk managers using AI to summarise assessments.
- Legal departments reviewing contracts with AI assistance.
- Human resources using AI to analyse job applicants.
In many cases, employees gradually become dependent on these capabilities. Productivity may increase, manual skills may diminish, and AI may become embedded in normal business operations. Over time, what began as an optional productivity tool can become a critical operational dependency.
Operational resilience requires a different perspective
Operational resilience asks a straightforward question: can the organization continue to deliver important business services when something goes wrong?
Organizations routinely ask this question about:
- Cloud providers;
- Telecommunications;
- Payment systems;
- Third-party vendors;
- Facilities; and
- Cyber attacks.
The same question should now be asked about AI. Can customer support continue without AI? Can security analysts investigate incidents manually? Can developers continue coding if AI-assisted development tools become unavailable? Can compliance teams operate without AI-generated summaries? If the answer is no, then AI has become a dependency and needs consideration within operational resilience.
AI introduces operational risks that need consideration. These include:
Service availability
Many organizations rely on externally hosted AI services. Outages, API failures, or provider disruptions can affect multiple business processes.
Model changes
Unlike traditional software, AI models may change without obvious developments to the application interface. A provider may upgrade a foundation model, adjust safety controls, or modify response behaviour. Those changes can influence business outcomes even when no application code has changed.
Data dependency
AI systems depend on data quality. Incomplete, inaccurate, or biased information can reduce output quality and increase operational risk.
Human dependency
Employees may gradually lose proficiency in tasks previously performed manually. If AI becomes unavailable, the organization may discover that essential skills have deteriorated.
Third-party concentration risk
Multiple applications may rely on the same underlying AI provider. An outage affecting one provider could simultaneously affect customer service, software development, security operations, and business analytics.
Five questions every organization should ask
Rather than creating another governance framework, organizations should begin by asking practical questions:
Which business services depend on AI?
Maintain an inventory of important business services that rely on AI directly or indirectly. Understanding where AI is used is the foundation of resilience planning.
How critical is the dependency?
Not every AI capability requires the same level of resilience planning. Organizations should distinguish between:
- Productivity enhancement;
- Important operational support; and
- Mission-critical business services.
This prioritisation helps allocate resilience resources appropriately.
What happens if AI becomes unavailable?
Every AI-enabled process that supports an important business service should have documented contingency procedures. Examples include:
- Manual processing;
- Alternative software;
- Delayed processing; and
- Human review.
Business continuity planning should explicitly include AI service disruptions.
What happens if AI becomes unreliable?
As highlighted in the introduction one difficulty with AI is not just availability, it is also reliability. What happens when AI remains available yet produces unreliable results?
Operational resilience needs to consider this area and develop appropriate strategies in response.
Who owns the operational risk?
Technology teams may manage infrastructure and security teams may manage cyber security, but business leaders remain accountable for operational outcomes. Each AI-enabled process should have a clearly identified business owner responsible for evaluating the operational impact and ensuring that contingency plans are approved and tested.
How will changes be monitored?
AI systems can evolve. Organizations should establish processes for reviewing:
- Significant model updates;
- Vendor changes;
- New AI capabilities;
- Changes in acceptable use; and
- Operational incidents involving AI.
Monitoring change remains important after the initial implementation.
Integrating AI into existing resilience programmes
Organizations do not need separate resilience programs for AI; existing operational resilience capabilities already provide a strong foundation. AI considerations can be incorporated into:
- Business impact analyses;
- Business continuity plans;
- Disaster recovery planning;
- Third-party risk management;
- Change management;
- Incident response; and
- Operational risk assessments.
This approach can strengthen resilience while avoiding fragmented governance structures.
Operational resilience is a business responsibility
One of the lessons that organizations continue to learn is that resilience cannot be delegated solely to technology teams. AI supports business operations, therefore, resilience planning must involve:
- Business leadership;
- Operations;
- Risk management;
- Cyber security;
- Compliance; and
- Technology.
Operational resilience is strongest when these groups work together rather than independently.
Practical steps that organizations can take today
Organizations do not need to wait for new regulations before improving resilience. The following five practical actions can make an immediate difference:
- Develop an inventory of AI-enabled business processes.
- Identify which important business services depend on external AI providers.
- Include AI dependencies in business impact analyses.
- Update business continuity plans to address AI service disruptions.
- Review operational resilience exercises to ensure that they include AI failure and disruption scenarios.
These actions build on existing resilience practices rather than creating entirely new governance structures.
Looking ahead
Artificial intelligence will continue to transform how organizations operate. As dependence grows, resilience planning must evolve as well. The organizations that succeed will not necessarily be those with the most sophisticated AI capabilities. They will be the organizations that understand how AI supports their important business services, recognise where operational dependencies exist, and prepare for the day that those capabilities become unavailable or behave unexpectedly.
Technology will continue to change. Operational resilience remains the discipline that enables organizations to adapt, respond, and continue delivering essential services regardless of the technology involved.
Bibliography
- Basel Committee on Banking Supervision. (2021). Principles for operational resilience.
- National Institute of Standards and Technology. (2023). Artificial Intelligence Risk Management Framework (AI RMF 1.0).
- ISO 22301:2019. Security and resilience – Business continuity management systems – Requirements.
- ISO 31000:2018. Risk management – Guidelines.
- ISO/IEC 42001:2023. Information technology – Artificial intelligence – Management system.
The author
Larry Marks, MBA, CISSP, CISA, CISM, CRISC, CGEIT, CDPSE, CFE, PMP, AWS Certified Cloud Practitioner
Larry Marks is an independent cyber security, governance, and technology risk advisor to organizations. He has more than 35 years of experience helping financial institutions strengthen cyber security governance, operational resilience, enterprise risk management, and regulatory compliance.






