AI is not another topic for the awareness calendar. It is changing how people think, decide, create, communicate and work—and agentic AI is about to make the human side of that change considerably more consequential. This is exactly the kind of problem Human Risk Management should be built to handle.
Quick answer: Why should AI workforce risk be part of Human Risk Management?
AI enablement, AI governance and AI workforce risk belong squarely inside the Human Risk Management conversation because AI is changing the conditions under which people make decisions, exercise judgment, handle information, follow controls and perform work.
That does not mean the Human Risk Management team should suddenly own enterprise AI governance. It means HRM should become a serious partner to the CISO, AI governance function, AI transformation team and wider business on the part of AI risk that sits between policy and actual human behavior.
AI literacy matters. Policies matter. Technical controls matter. But organizations also need to understand whether people know when to trust AI, when to challenge it, what to delegate, what to verify, when to intervene, how their role is changing, whether workarounds are appearing, where capability is falling behind technology, and how culture and incentives are shaping real behavior.
That is human risk.
And if Human Risk Management is going to become the strategic discipline its advocates say it can be, this is the moment to prove it.
AI is not another cybersecurity awareness topic
There is a fairly comfortable version of AI security that many organizations could adopt.
Write an acceptable-use policy. Decide which tools are approved. Tell employees not to paste sensitive information into public models. Create some guidance on hallucinations, intellectual property and data handling. Add a module called Using AI Safely. Perhaps run an AI-themed campaign during Cybersecurity Awareness Month.
None of those things are bad ideas. Some are necessary.
They are simply nowhere near sufficient for what is happening.
AI is not merely introducing another technology that employees need to learn how to use securely. It is beginning to alter the mechanics of work itself. An August 2026 International Labour Organization report describes AI adoption as changing the cognitive, socioemotional and digital skills workers use to perform their jobs, with increasing importance placed on higher-order cognitive skills, adaptability, resilience and human agency. Recent NBER research similarly finds generative AI use spreading across a wide range of occupations and tasks, even though adoption remains uneven among people doing similar work.
That distinction matters enormously for security.
For years, Human Risk Management has been concerned with questions such as whether someone recognizes a threat, follows a process, protects information, reports an incident or makes a safer decision. AI does not replace any of those questions, but it changes the circumstances in which they are being answered. An employee may now be making a decision with an AI system advising them, relying on it to summarize the source material, draft the communication, interpret the data or write some of the code behind the work. As organizations move further into agentic systems, the AI may also begin carrying out parts of the task rather than simply helping a person think through it.
That makes the human-risk picture considerably more complicated. It is no longer always enough to ask what the employee knew, what they clicked or whether they followed the stated process. We increasingly need to understand how the person and the AI worked together: what was delegated, what was trusted, what was checked, what was missed, where judgment still sat and whether the human remained meaningfully in control of the outcome. Those are exactly the kinds of questions a mature Human Risk Management capability should be preparing to answer.
The unit of risk is beginning to change from what did the person do? to how did the person and the AI system arrive at what happened?
AI governance already has a human problem
The NIST AI Risk Management Framework explicitly treats AI as a socio-technical risk problem. NIST's guidance addresses human roles and responsibilities, operator proficiency, human oversight, cognitive bias, human-AI configurations, training and the difficulties inherent in human-AI teaming. Its AI RMF Playbook recommends establishing policies and procedures around human-AI roles, tracking risks associated with human-AI configurations and establishing proficiency standards for people operating or overseeing AI systems.
The interesting question, then, is not whether governance recognizes the human.
It is who operationalizes that part of governance once AI reaches the workforce?
A policy can say that employees remain accountable for AI-assisted decisions. Someone still needs to determine whether those employees have enough understanding, visibility and authority to exercise meaningful accountability.
A governance framework can require human oversight. Someone needs to understand whether the designated human knows what failure looks like, recognizes when intervention is necessary, has sufficient confidence to challenge the system and is working in an environment where stopping the process is realistically possible.
A policy can prohibit certain information from being entered into an AI system. Someone needs to understand why employees are doing it anyway. Is it poor awareness? An unusable approved tool? Deadline pressure? Habit? Confusion? Overconfidence? A badly designed workflow? A manager who has implicitly rewarded output over compliance?
Those are different problems. They require different interventions.
This is where AI workforce risk management starts to become a useful discipline: examining what happens when AI governance meets real people, real work, real incentives and real organizational conditions.
This is what Human Risk Management was supposed to grow into
There is a larger strategic point here for Human Risk Management as a discipline. For years, the argument has been that organizations need to move beyond the narrow mechanics of awareness: annual training, phishing metrics, completion rates and the assumption that every human-related problem can be corrected with another piece of education. The ambition behind HRM was always broader than that. It was to understand where human-related risk comes from, why it persists, which populations and conditions matter most, what kinds of interventions are likely to work and whether those interventions actually improve security and organizational resilience.
AI is where that ambition starts to become very practical.
The human side of AI adoption cannot be managed through training alone because the problem is not simply whether employees know the rules. Organizations need to understand how people are using these systems, where confidence is too high or too low, which behaviors are emerging, how different groups are adapting, what cultural norms are forming, where workarounds are appearing and whether governance is translating into real practice. That draws on measurement, behavioral science, psychology, competency development, communications, change management, work design, leadership, controls and continuous feedback—the same capabilities mature HRM programs have been trying to build for years.
This is why AI matters so much to the evolution of HRM. It is not just another risk topic to add to the program. It is a business problem large enough, fast-moving enough and consequential enough to show what Human Risk Management can become when it operates as a genuine management capability rather than a more sophisticated version of security awareness.
This is not a criticism of today's Human Risk Management teams
There is a practical constraint sitting underneath all of this: many security awareness and human-risk teams are already operating at the edge of their capacity. Small teams are supporting large, often global populations while juggling mandatory learning, phishing programs, audits, communications, reporting, stakeholder requests, incident support and the steady flow of work that comes with being the part of security expected to “get the message out.” In that environment, asking the same team to take on AI workforce risk, AI governance support and a broader Human Risk Management remit can sound less like an opportunity and more like another layer of responsibility.
That is particularly true for organizations that have adopted the language of Human Risk Management faster than they have built the capability behind it. A change in title does not create new operating capacity, and a platform on its own does not suddenly provide the people, processes, data, expertise or management model needed to run HRM well. We have written elsewhere about why Human Risk Management needs to operate as a management model, not merely a SaaS category, and AI makes that distinction even more important.
So the challenge is not to tell already stretched practitioners that they need to become more strategic. It is to give the function enough leverage to actually operate at a more strategic level. Automation can remove administrative load, better data can sharpen decisions, managed services can extend delivery capacity, and stronger measurement and tooling can help teams focus their time where it creates the most value. The point is not efficiency for its own sake. HRM needs to scale because the scope, speed and consequence of the human-risk problem are all expanding, and AI is accelerating that shift considerably.
AI literacy is the floor, not the operating model
AI literacy is receiving a great deal of attention, and rightly so. Article 4 of the EU AI Act, for example, requires providers and deployers of AI systems to take measures that support appropriate levels of AI literacy among staff and others using AI on their behalf, taking account of factors such as knowledge, experience, education and the context in which the systems are being used.
The risk is that organizations interpret that requirement too narrowly and recreate a pattern cybersecurity already knows well: write the policy, build the course, assign it to everyone and treat completion as evidence that the workforce is ready.
AI literacy is a necessary foundation, but it is not the same thing as safe, effective AI-enabled work.
People can understand the rules and still behave in ways that introduce risk. Someone may know that an AI-generated answer needs to be checked, but become progressively less rigorous about verification as the system proves useful and familiar. An employee may understand the data-handling policy perfectly well and still use an unapproved tool because the sanctioned option makes the job slower or harder. A manager may support the principle of human oversight while setting deadlines and productivity expectations that leave very little room for meaningful review.
Those are not simply knowledge gaps. They are questions about how people actually operate within a system of incentives, pressures, habits, tools and social norms.
A mature program therefore needs to look beyond whether employees can repeat the guidance and ask harder questions about what is happening in practice:
- Are people becoming appropriately confident with AI, or merely more comfortable with it?
- Do they know where verification matters most, and are workflows designed to make that verification realistic?
- Are teams developing healthy norms around challenge, escalation and responsible experimentation?
- Do managers reinforce the behaviors governance expects, or unintentionally reward speed over care?
- Where are people creating workarounds because approved tools, controls or processes do not fit the work?
This is where the distinction between AI literacy and AI workforce risk becomes important. Literacy helps people understand the technology, its limitations and the rules around its use. Human Risk Management goes further by examining how confidence, trust, capability, incentives, workload, leadership, culture and the design of work affect what people actually do with that knowledge.
Cybersecurity has spent years learning that awareness does not automatically translate into behavior. There is little value in repeating the same mistake with AI.
Agentic AI raises the stakes again
Generative AI has already changed how people research, write, analyze and make decisions. Agentic AI extends that shift by allowing systems to plan, coordinate and take action across enterprise environments, which makes the human side of the control problem much more consequential. NIST's 2026 work on AI-agent security recognizes that agents introduce novel security challenges and that existing cybersecurity principles will need to be adapted accordingly. Its AI Agent Standards Initiative also includes work on secure human-agent and multi-agent interactions, while the OWASP Agent Control Standard focuses on making agents more inspectable, traceable and controllable at runtime.
That technical work is essential, but it only addresses part of the system organizations are actually trying to govern. An agent can be well constrained technically and still be used badly by the person delegating work to it. Conversely, a competent employee can be placed in a workflow where the agent's speed, complexity or level of autonomy makes meaningful supervision increasingly difficult.
Once AI begins taking action rather than simply producing an answer, organizations need a much clearer understanding of the relationship between the person and the system. Who decides what can be delegated? What does appropriate supervision look like? Where is verification required, and who is responsible for doing it? When should a person intervene, and do they still understand enough of the underlying work to recognize when something has gone wrong? As autonomy increases, those questions become part of the operating model rather than an edge case for the security team.
Our recent work on the human-risk layer of AI agent governance explores this distinction in more depth. Technical governance needs to define what an agent is permitted to do, but Human Risk Management has a complementary question to answer: how do people decide what to trust, what to hand over, what to check and when to take control back?
That is where cognition, competency, trust, behavior, work design and culture enter the picture. As agentic systems become more capable, those human factors will increasingly determine whether the organization is genuinely in control of the work or simply has technically governed agents operating inside poorly governed human-agent relationships.
What should a CISO expect from HRM in the AI era?
Not ownership of every AI problem. Not another empire. And definitely not an awareness team frantically trying to become the AI Governance Office between phishing simulations.
A modern Human Risk Management capability should be able to contribute something distinctive to the wider AI program:
- Measure AI workforce risk and readiness: understand differences in confidence, capability, behavior, sentiment, trust, adoption, unsafe practices and organizational conditions across populations.
- Translate governance into human reality: identify whether people understand, can perform and actually follow the behaviors that policy and controls assume.
- Build competency rather than deliver one-off training: develop AI judgment, secure use, verification, escalation and role-specific skills over time.
- Apply behavioral and psychological insight: examine over-reliance, automation bias, risk perception, confidence, norms, workarounds, resistance and other drivers of behavior rather than assuming knowledge causes action.
- Support cultural and organizational change: help leaders, managers, champions and teams establish norms around safe experimentation, questioning, escalation, accountability and responsible AI use.
- Prepare for human-agent work: understand how roles, decision rights, supervision and skills need to change as people increasingly delegate work to AI agents.
- Measure what happens next: connect interventions to adoption, behavior, incidents, security signals and organizational outcomes so the program can learn and adapt.
That is a much more useful contribution than “we own the AI awareness course.”
It also puts HRM exactly where CISOs increasingly need it: operating across security, risk, workforce behavior and organizational change rather than sitting downstream waiting for somebody to send over the approved communications.
HRM needs to get involved before the policy is finished
One of the easiest mistakes for security teams to make is to wait until AI governance has been largely designed and then ask what employees need to be told. By that point, many of the important human decisions have already been made: which tools are being introduced, how work is expected to change, where responsibility sits, what people are being asked to trust and which controls will shape everyday behavior.
Human Risk Management teams should be much closer to those conversations from the beginning. That means working alongside the people leading AI transformation, governance, security, legal, risk and business change so they can understand not only what the organization intends to do with AI, but how that intention is likely to play out in real work.
The useful questions are not just communication questions. They are questions such as:
- Where is AI adoption already happening faster than policy or governance?
- Which roles are being asked to make new judgments, supervise new systems or work in unfamiliar ways?
- Where are employees hesitating, improvising or creating workarounds?
- What new human control points are emerging, and do people have the capability to operate them?
- Are policies realistic in the context of workload, incentives, available tools and business pressure?
- What competencies will people need as AI becomes part of everyday work rather than a specialist technology?
This is where HRM can add something that other parts of the AI program may not naturally bring. Architecture teams will focus on systems and controls. Legal and compliance teams will focus on obligations and acceptable use. Transformation teams will focus on adoption, productivity and business value. Human Risk Management can connect those conversations to behavior, psychology, capability, communications, culture and the practical conditions that shape whether people can actually do what the organization expects of them.
Just as importantly, HRM should not enter the conversation only as the function that identifies what employees must not do. AI governance has to make safe adoption possible, not simply constrain it. If security can help the business understand where people need support, where confidence needs to grow, where judgment needs strengthening and how safe experimentation can happen within sensible guardrails, it becomes part of the enablement story rather than the team that arrives at the end with a prohibited-use list.
That is a much stronger role for Human Risk Management, and a much more valuable one for the CISO.
HRM has to scale its own way of working
If AI is changing how work gets done across the business, Human Risk Management has to apply some of that same thinking to itself. The function cannot meet a broader, faster-moving risk landscape by simply adding more manual work to an already overloaded team. No practitioner can personally analyze every population, create every intervention, build every communication, advise every stakeholder, track every new technology and still run the core program well.
Scaling HRM therefore has to mean more than doing the same work faster. It requires an operating model that gives the team more leverage: stronger data, better measurement, useful automation, more adaptable technology and increasingly AI-enabled ways of understanding risk, creating interventions and managing the program. It also means recognizing where specialist expertise and delivery capacity should sit around the internal team rather than expecting every capability to be built in-house.
That is increasingly how we think about Cybermaniacs' role. We are not trying to replace the practitioner, and we are not interested in handing over another platform and assuming the job is done. The aim is to strengthen the function around them: helping teams see more clearly, act more quickly, deliver more consistently and build capability as the demands on HRM continue to grow.
In practice, that means supporting different parts of the operating model. Our ASSURE Human Risk Baseline provides the diagnostic layer, helping organizations understand where human risk exists and what is driving it. CLX supports continual competency development and adaptive learning, while MANAGE helps organizations build and operate the broader HRM capability. CHANGE gives teams additional creative and content capacity when an intervention needs to reflect a particular workforce, culture, brand or risk problem.
AI now sits naturally inside that model because the same challenge is appearing in a new form: organizations need to understand how people are adapting to AI, where capability is lagging, what behaviors are emerging and how governance is translating into practice.
Our AI Enablement and Change Management program is designed to help organizations understand workforce readiness, adoption barriers, capability and human risk as AI becomes part of everyday work. Our Agentic AI Readiness program takes that further into human-agent roles, delegation, oversight, workflows and the governance questions that emerge as AI systems begin to take on more consequential work.
The value of bringing those capabilities together is not that an organization gets more content or another piece of software. It is that the internal team gets more reach. They can draw on specialist expertise when they need it, use technology to reduce operational drag, build interventions faster, improve the quality of their data and measurement, and develop the function without having to create every capability from scratch.
For us, that is what scaling Human Risk Management should look like: not replacing the people who know the organization best, but giving them enough support, tooling and specialist capacity to operate at the level the business now requires.
This is the moment HRM should be preparing for
AI will create new vulnerabilities, new attack paths and new technical control requirements, and security teams will rightly invest heavily in understanding them. But the equally important change is happening in the way people themselves are starting to work. Employees are already using AI to interpret information, shape decisions, draft outputs and accelerate tasks; as agentic systems become more common, they will also begin delegating more of that work to systems that can act on their behalf.
That changes the human-risk landscape in ways that are easy to underestimate. Judgment may be shared between a person and a system. Expertise may become less visible because part of the work has been outsourced to the model. Decisions may become harder to reconstruct when multiple prompts, tools and agents contribute to the outcome. Teams will develop their own conventions about what is acceptable to automate, what still needs checking and when a person should step back in. Some of those norms will be sensible. Others will emerge simply because they make the work faster.
The important question for HRM is no longer only whether people are making secure decisions. It is whether the organization understands how those decisions are being made when AI becomes part of the process.
That is why AI workforce risk should not sit at the edge of the Human Risk Management agenda. It is likely to become one of the areas where the discipline is most valuable, precisely because the problem cuts across knowledge, behavior, capability, trust, culture, incentives, work design and governance.
HRM does not need to own enterprise AI strategy, and it should not try to. Its value is in bringing the human layer into the room while those strategies are being designed and implemented: measuring what is happening, understanding why people are behaving as they are, helping build the right competencies, identifying where controls are colliding with real work and supporting the organization as new behaviors and norms take shape.
For CISOs, that should be a meaningful part of the next-generation HRM mandate. The goal is not simply to make employees safer users of AI. It is to help the business adopt powerful new ways of working without losing sight of judgment, accountability, resilience and the human conditions that make those controls work in practice.
Frequently Asked Questions
Is AI workforce risk part of Human Risk Management?
Yes. AI workforce risk includes the human and organizational risks created as AI changes how employees make decisions, exercise judgment, handle information, perform tasks, collaborate and share responsibility with technology. Managing those conditions fits naturally within a mature Human Risk Management capability, working alongside AI governance, security, risk, transformation and business teams.
What role should Human Risk Management play in AI governance?
HRM should not own the entire AI governance program. Its role should be to help operationalize the human side of governance: workforce capability, behavior, culture, human oversight, policy adherence, trust, accountability, adoption, workarounds and the effectiveness of human controls.
Is AI literacy training enough to manage AI workforce risk?
No. AI literacy is an important foundation, but knowledge alone does not determine behavior. Organizations also need to understand how confidence, incentives, workload, culture, social norms, tool design, management expectations and repeated AI use affect real decisions and actions.
How does agentic AI change human risk?
Agentic AI can move from generating information to planning and taking actions. That makes the relationship between the employee and the AI system more consequential. Organizations need to define appropriate delegation, supervision, verification, escalation, intervention, accountability and human competency as AI agents take on more work.
How can Human Risk Management teams take on AI without creating more workload?
The answer is not simply to add AI responsibilities to an already overloaded team. HRM programs need scalable technology, automation, measurement, reusable operating models, specialist support, managed services and AI-enabled ways of working that increase the team's capacity while allowing practitioners to concentrate on judgment, strategy and business partnership.