I stopped saying "AI and cybersecurity" somewhere in the last two years, not because the phrase is wrong, but because the word "and" was doing damage. It tells the listener these are two adjacent topics you can staff separately, budget separately, and think about separately. That was never true, and now it is expensive to keep pretending otherwise.
This article is grounded in current advisory work, not retrospective analysis. Mark Lynd is a 5x CEO/CIO/CISO with Thinkers360 Top 10 global rankings across Cybersecurity and Artificial Intelligence and was ranked #1 globally in Cybersecurity in 2023. He is currently Head of Executive Advisory and Strategy at Netsync, advising enterprise C-Suites and boards on the AI and cybersecurity questions moving fastest in 2026. The frameworks and patterns referenced here are from active engagements this quarter.
Why the Word "And" Is the Problem
Language shapes structure faster than most executives want to admit. Call something "AI and cybersecurity" and you get two budget lines, two steering committees, two sets of KPIs, and eventually two people who each assume the other is covering the gap between them. Call it one intersection and you get a single risk register entry, one accountable owner, and a much harder time hiding the fact that nobody has actually looked at what happens when an AI system is also the attack surface.
The World Economic Forum's Global Cybersecurity Outlook 2026 found that 94 percent of surveyed leaders identified AI as the most significant driver of change they expect in cybersecurity this year, and 87 percent named AI-related vulnerabilities as the fastest-growing category of cyber risk. Those are not two separate findings from two separate surveys. They are the same respondents, in the same report, describing the same thing from two angles. The practitioners who actually sit with this problem every day do not experience it as two topics. They experience it as one, and the industry's habit of splitting it into separate tracks at conferences and separate lines in the org chart is a lag effect, not a reflection of how the risk actually behaves.
I have sat through enough advisory conversations this year to notice a pattern that repeats regardless of industry. A company builds an AI capability under one sponsor, ships it, and only later loops in the security team, usually after something forces the question, a customer complaint, an auditor's finding, an incident that could have been caught earlier. When I ask why security was not in the room from the start, the answer is almost never "we decided AI risk was out of scope for security." It is "nobody thought to ask." That is a framing failure before it is a process failure. If the company's mental model treats AI as a product initiative and cybersecurity as a separate compliance function, nobody thinks to ask, because the two things live in different sentences in people's heads.
A manufacturer working through this pattern is a useful stand-in for what I see across sectors. Picture a plant operations team that adopts an AI-based predictive maintenance system, sourced and configured entirely inside operations, with no involvement from IT security because the system does not touch customer data and therefore does not, on paper, look like a security matter. Eighteen months later the security team is doing a routine network segmentation review and finds the maintenance system has a persistent connection into the plant's industrial control network, authenticated with a shared credential that was never rotated, because nobody owned that responsibility. Nothing in that story required malice or incompetence. It required only that "AI project" and "security review" were two different sentences in two different people's heads, filed under two different departments, until an unrelated audit happened to connect them.
That gap is the direct cost of treating AI and cybersecurity as adjacent rather than overlapping. It is also, I think, the reason the industry keeps producing frameworks, maturity models, and reference architectures for "AI security" as a bolt-on discipline rather than treating security as a default property of how AI gets built in the first place. A bolt-on discipline is easier to sell and easier to staff as a separate practice area. It is also, by construction, always a step behind whatever shipped before the bolt-on team got involved.
The Honest Counterargument
The strongest objection to this whole framing is that it is just vocabulary, and vocabulary does not fix anything. A critic would say, correctly, that plenty of companies talk about "AI and security convergence" in every board deck and still ship ungoverned AI systems with no security review, because renaming the problem does not staff the review, fund the tooling, or change anyone's incentives. What matters is the org chart, the budget, the actual gate in the deployment pipeline. Calling it "the intersection" instead of "AI and cybersecurity" is a rhetorical move, and rhetoric is cheap. I take this seriously because I have watched companies adopt the language of convergence in their communications while changing nothing about who signs off on what. A relabeled slide is not a control.
But the objection proves too much if you push on it. Words are cheap right up until they determine what gets a budget line, and in a large organization, what gets a budget line is not decided by an engineer weighing the technical merits in isolation. It is decided by whoever wrote the initial charter document, and that document's categories become the categories everyone downstream inherits. If AI risk is filed under "innovation" and cybersecurity risk is filed under "compliance," those two categories get different executive sponsors, different risk appetites, and different review cadences, and that split persists for years after the person who wrote the original charter has moved on. Framing is not a substitute for structure. But framing is very often the thing that decided the structure in the first place, quietly, before anyone noticed a decision had been made.
I also take the critic's point that relabeling can become an excuse for inaction, a way for an organization to feel it has addressed convergence by putting the word in a strategy document without changing a single reporting line. That happens, and it is worth naming as a failure mode, because a company that adopts intersection language without adopting intersection structure is arguably worse off than one that never claimed convergence at all. It has given itself the appearance of having solved a problem it has not touched. The honest version of this argument is not that framing replaces structure. It is that framing is upstream of structure, and getting it wrong upstream makes the downstream fix slower and more expensive than it needed to be.
What This Means for Leadership and the Board
This is not an argument for merging every AI team and every security team into one department. Most organizations still benefit from dedicated AI expertise and dedicated security expertise, because the two disciplines require genuinely different technical depth. It is an argument for making sure the language your organization uses does not accidentally tell people the two are unrelated when the evidence says otherwise.
Leadership and the board should ask whether the company's AI governance policy and its cybersecurity policy are two separate documents written by two separate teams that have never compared drafts. They should ask whether the person who approves a new AI system's budget is the same person, or even in regular contact with the person, who approves its security review. They should ask how many of this year's AI initiatives were scoped and staffed before security had a seat at the table, and whether that was a deliberate choice or simply what the org chart made easiest. They should ask, bluntly, whether their next AI incident and their next security incident would even be classified as the same event, or whether two different teams would investigate them separately and never compare notes.
I write about this intersection instead of writing about AI in one place and cybersecurity in another because I have not found a company yet where the two stayed separate for long. The risk does not respect the org chart. Eventually the org chart has to catch up to the risk, and the companies that catch up first are the ones that stopped calling it "and" before an incident forced the question.