Close Menu
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
More items
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
X (Twitter) LinkedIn
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
Login
LinkedIn Bluesky
Resilience Forward
Subscribe Now
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
Resilience Forward
You are at:Home»Managing resilience»AI resilience»Operational resilience in an AI-dependent enterprise (Page 3)
AI resilience

Operational resilience in an AI-dependent enterprise

Larry Marks argues that AI should now be recognised as an operational dependency requiring the same operational resilience planning applied to other important business services. He provides practical guidance for resilience professionals on identifying AI dependencies and incorporating AI into operational resilience programs without creating additional organizational structures.
August 26, 20267 Mins Read
AI enabled business processes concept.

Artificial intelligence is becoming operational infrastructure

Organizations are rapidly adopting artificial intelligence. Customer service platforms generate responses using large language models. Developers rely on AI-assisted coding tools. Security teams analyse alerts with AI-powered products. Finance departments automate reporting. Human resources departments screen résumés and CVs. Legal teams use AI to review contracts, conduct legal research, and assist with document drafting. Procurement uses AI to summarise contracts.

In many organizations, AI is no longer an experimental technology. It has become part of day-to-day operations. That shift creates a new challenge. Much of the discussion surrounding AI focuses on governance, ethics, model risk, and cyber security. These are important topics, but they overlook another question: what happens when the AI that supports important business services is unavailable, produces unreliable results, or changes unexpectedly? That is fundamentally an operational resilience question.

Organizations have spent years strengthening their resilience to failures affecting data centres, cloud providers, telecommunications networks, and critical third-party services. Where AI supports important business services, the resulting dependencies deserve the same level of attention. As AI becomes embedded in important business processes, organizations must identify where they depend on it, understand the risks those dependencies create, and incorporate those dependencies into operational resilience planning.

AI is becoming a business dependency

AI increasingly influences decision-making, customer interactions, and operational workflows. Examples include:

  • Customer service agents using AI to draft responses.
  • Security analysts relying on AI to prioritise alerts.
  • Developers using AI-generated code.
  • Risk managers using AI to summarise assessments.
  • Legal departments reviewing contracts with AI assistance.
  • Human resources using AI to analyse job applicants.

In many cases, employees gradually become dependent on these capabilities. Productivity may increase, manual skills may diminish, and AI may become embedded in normal business operations. Over time, what began as an optional productivity tool can become a critical operational dependency.

Operational resilience requires a different perspective

Operational resilience asks a straightforward question: can the organization continue to deliver important business services when something goes wrong?

Organizations routinely ask this question about:

  • Cloud providers;
  • Telecommunications;
  • Payment systems;
  • Third-party vendors;
  • Facilities; and
  • Cyber attacks.

The same question should now be asked about AI. Can customer support continue without AI? Can security analysts investigate incidents manually? Can developers continue coding if AI-assisted development tools become unavailable? Can compliance teams operate without AI-generated summaries? If the answer is no, then AI has become a dependency and needs consideration within operational resilience.

AI introduces operational risks that need consideration. These include:

Service availability
Many organizations rely on externally hosted AI services. Outages, API failures, or provider disruptions can affect multiple business processes.

Model changes
Unlike traditional software, AI models may change without obvious developments to the application interface. A provider may upgrade a foundation model, adjust safety controls, or modify response behaviour. Those changes can influence business outcomes even when no application code has changed.

Data dependency
AI systems depend on data quality. Incomplete, inaccurate, or biased information can reduce output quality and increase operational risk.

Human dependency
Employees may gradually lose proficiency in tasks previously performed manually. If AI becomes unavailable, the organization may discover that essential skills have deteriorated.

Third-party concentration risk
Multiple applications may rely on the same underlying AI provider. An outage affecting one provider could simultaneously affect customer service, software development, security operations, and business analytics.

Five questions every organization should ask

Rather than creating another governance framework, organizations should begin by asking practical questions:

Which business services depend on AI?

Maintain an inventory of important  business services that rely on AI directly or indirectly. Understanding where AI is used is the foundation of resilience planning.

How critical is the dependency?

Not every AI capability requires the same level of resilience planning. Organizations should distinguish between:

  • Productivity enhancement;
  • Important operational support; and
  • Mission-critical business services.

This prioritisation helps allocate resilience resources appropriately.

What happens if AI becomes unavailable?

Every AI-enabled process that supports an important business service should have documented contingency procedures. Examples include:

  • Manual processing;
  • Alternative software;
  • Delayed processing; and
  • Human review.

Business continuity planning should explicitly include AI service disruptions.

What happens if AI becomes unreliable?

As highlighted in the introduction one difficulty with AI is not just availability, it is also reliability. What happens when AI remains available yet produces unreliable results?

Operational resilience needs to consider this area and develop appropriate strategies in response.

Who owns the operational risk?

Technology teams may manage infrastructure and security teams may manage cyber security, but business leaders remain accountable for operational outcomes. Each AI-enabled process should have a clearly identified business owner responsible for evaluating the operational impact and ensuring that contingency plans are approved and tested.

How will changes be monitored?

AI systems can evolve. Organizations should establish processes for reviewing:

  • Significant model updates;
  • Vendor changes;
  • New AI capabilities;
  • Changes in acceptable use; and
  • Operational incidents involving AI.

Monitoring change remains important after the initial implementation.

Integrating AI into existing resilience programmes

Organizations do not need separate resilience programs for AI; existing operational resilience capabilities already provide a strong foundation. AI considerations can be incorporated into:

  • Business impact analyses;
  • Business continuity plans;
  • Disaster recovery planning;
  • Third-party risk management;
  • Change management;
  • Incident response; and
  • Operational risk assessments.

This approach can strengthen resilience while avoiding fragmented governance structures.

Operational resilience is a business responsibility

One of the lessons that organizations continue to learn is that resilience cannot be delegated solely to technology teams. AI supports business operations, therefore, resilience planning must involve:

  • Business leadership;
  • Operations;
  • Risk management;
  • Cyber security;
  • Compliance; and
  • Technology.

Operational resilience is strongest when these groups work together rather than independently.

Practical steps that organizations can take today

Organizations do not need to wait for new regulations before improving resilience. The following five practical actions can make an immediate difference:

  • Develop an inventory of AI-enabled business processes.
  • Identify which important business services depend on external AI providers.
  • Include AI dependencies in business impact analyses.
  • Update business continuity plans to address AI service disruptions.
  • Review operational resilience exercises to ensure that they include AI failure and disruption scenarios.

These actions build on existing resilience practices rather than creating entirely new governance structures.

Looking ahead

Artificial intelligence will continue to transform how organizations operate. As dependence grows, resilience planning must evolve as well. The organizations that succeed will not necessarily be those with the most sophisticated AI capabilities. They will be the organizations that understand how AI supports their important business services, recognise where operational dependencies exist, and prepare for the day that those capabilities become unavailable or behave unexpectedly.

Technology will continue to change. Operational resilience remains the discipline that enables organizations to adapt, respond, and continue delivering essential services regardless of the technology involved.

Bibliography

  • Basel Committee on Banking Supervision. (2021). Principles for operational resilience.
  • National Institute of Standards and Technology. (2023). Artificial Intelligence Risk Management Framework (AI RMF 1.0).
  • ISO 22301:2019. Security and resilience – Business continuity management systems – Requirements.
  • ISO 31000:2018. Risk management – Guidelines.
  • ISO/IEC 42001:2023. Information technology – Artificial intelligence – Management system.

The author

Larry Marks, MBA, CISSP, CISA, CISM, CRISC, CGEIT, CDPSE, CFE, PMP, AWS Certified Cloud Practitioner

Larry Marks is an independent cyber security, governance, and technology risk advisor to organizations. He has more than 35 years of experience helping financial institutions strengthen cyber security governance, operational resilience, enterprise risk management, and regulatory compliance.

Africa Asia Asia Pacific Australasia Europe Middle East North America UK
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email WhatsApp
Previous ArticleThe silo problem: why resilience disciplines keep reinventing each other’s wheels
Next Article Head of Enterprise Risk Management

Related Posts

An exploding digital padlock illustrates the requirement for post-quantum cryptography.

Research breakthrough brings reliable quantum computers and Q-day closer to reality

September 10, 2026
A danger sign on a digital background.

New blob URL phishing technique evades detection by using legitimate Microsoft services

September 10, 2026
AI risks

Unmanaged AI workflows expose EMEA organizations to rising compliance and data risks

September 9, 2026
City skyline at sunset with bright light trails and a translucent blue smart-city grid overlay and GPS pins indicating locations.

AI world models: future possibilities for organizational resilience?

September 7, 2026
DRJ and BCI logos

DRJ and BCI publish guidance for governing, managing, and using AI in resilience

September 7, 2026
Decision making with over whelming information.

AI can find the vulnerability. Accountability still sits with your crisis leadership

September 7, 2026
Advertisement
Resilience First
This week's most read articles
Logos of the Amazon cloud services AWS on a heap on a table.

New Level 1 DORA Workbook released for AWS customers regulated under DORA

November 26, 2024
Close-up of a green-brown iris peering through a jagged tear in dark paper or wall material.

The blind spots in business continuity

September 2, 2026
AI risks

Unmanaged AI workflows expose EMEA organizations to rising compliance and data risks

September 9, 2026
Latest resources
A woman with blonde hair and a ponytail looking at colourful sticky notes on a wall.

The stories behind the organization: how cultural narratives shape resilience

August 7, 2026
Load More

Subscribe to Updates

Get our Resilience Updates newsletter.

Most Popular Feature Articles
Three dark coloured light bulbs on a black background illustrate the concept of The Dark Triad in Crisis Management.

The Dark Triad in crisis management

Five stage crisis management framework

A five stage framework for a crisis management process

Blue interconnected gears and network nodes symbolizing automation and complex machinery.

Agent zero – the 2028 digital pandemic

Latest Reports
A futuristic red warning alert icon with glowing exclamation mark.

Cloud Security Alliance publishes Hugging Face Incident Initial Post-Mortem

A person hold a building door open for a person behind who is tailgating to get unauthorised access.

Security Culture: A Strategic Capability That Builds Resilience in a Volatile World

An identity icon with a map marker on it, indicating the concept of identity as a target for attackers. The icon is on a generic IT background predominantly in black and orange.

Identity-based approaches dominate initial access for ransomware attacks

A promo box for an article about resilience governance.
© 2026 Resilience Forward
  • About Resilience Forward
  • Newsletter
  • Newsfeed
  • Advertise
  • Call for Papers
  • Contact
  • Privacy Policy and Cookie Use
  • AI Use Policy

Type above and press Enter to search. Press Esc to cancel.

Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Ad Blocker Enabled!
Ad Blocker Enabled!
Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.

Sign In or Register

Welcome Back!

Login to your account below.

Lost password?