AI Readiness · public entity risk pools

AI misinformation and cyber exposure.

A dedicated briefing for public entity risk pool executive and risk leadership.

Artificial intelligence is advancing two material exposures for public entity pools: cyber threats operating at greater speed and scale, and misinformation created or amplified through organisational information. This page is a short introduction to both, and to the briefing that explains what can be measured, controlled, and considered at pool level.

Presently briefings are by invitation only
FormatBriefing, then discussion
Duration20 minutes + questions
Held onMicrosoft Teams
MaterialsLimited distribution

The evidence

Misinformation is already the leading concern.

The concern is no longer limited to how organisations use artificial intelligence internally. AI systems are already interpreting, summarising and repeating what organisations and their members publish.

Businesses cite AI errors, misinformation and hallucinations as the leading AI threat.

Gallagher, 2026. AI Adoption and Risk Benchmarking.
Gallagher survey link

Of misinformation or misrepresentation, the organisation's own online position is the root cause.

AAAnow Research, Dec. 2023 to Jan. 2026; P&C (human misinformation) 2014 to 2023.

Of the typical web estate is unknown to the organisation, including sites from the COVID rush online that remain.

P&C / Sitemorse risk profiling, 2017 to 2023, covering more than 119 million websites.

Two advancing exposures

One is escalating fast. The other is already happening.

Exposure one

Rapidly escalating cyber exposure

Artificial intelligence is increasing the speed, accessibility, scale, and repeatability of cyber activity. Threats can be researched, adapted, and deployed more quickly, increasing the pressure on existing risk-control, governance, and incident-response arrangements.

This does not mean every cyber threat is created by artificial intelligence. It means artificial intelligence is changing how quickly threats can develop and how widely they can be applied.

The pace is no longer theoretical. On 21 July 2026, OpenAI disclosed that during an internal capability test, its models independently found and chained a zero-day vulnerability to breach a partner's production infrastructure, moving from identifying a weakness to exploiting it, without a person directing the attack. OpenAI's account of the incident (opens in a new window).

Exposure two

AI misinformation and misrepresentation

AI systems depend on the information they can access and interpret. When organisational information is inconsistent, outdated, incomplete, or difficult to understand, AI-generated answers may repeat an incorrect position or create a misleading interpretation.

The issue is often attributed solely to artificial intelligence. The underlying information, and the organisation's control over that information, must also be considered.

The root cause is rarely external, as the evidence above shows: it sits within the organisation's own online position, which is exactly where it can be measured and governed.

Why this matters at pool level

Beyond one member, one team.

These exposures may begin within individual member organisations, but their implications can extend beyond a single website, department, or technology team. For public entity pools, the wider considerations may include:

Shared and pooled exposure across member organisations.

Risk-control priorities and member guidance.

Governance and oversight requirements.

Claims and incident-response considerations.

The consistency of support provided across the membership.

The level of visibility available to pool leadership.

The briefing will examine the issue at pool level without assuming that every member faces the same exposure, or that every exposure will result in a claim.

Why this briefing matters

What can now be measured, and controlled.

Much of the current discussion remains focused on general AI adoption, visibility, or internal policy. What is less widely understood is that AI misinformation can be measured systematically, and significant causes can be identified and controlled. The briefing will give pool executive and risk leadership a clearer understanding of:

Why cyber exposure is advancing through artificial intelligence.

Why misinformation has become the leading perceived AI concern.

How member-controlled information can contribute to exposure.

How AI misinformation can be measured and evidenced.

Which elements can be controlled through stronger information management.

Where pool leadership may require greater visibility across members.

Which questions should now be considered within risk-control planning.

The session is educational and evidence-led. It is not a product demonstration, a completed pool assessment, a legal opinion, or a general AI-readiness presentation.

The next step

The first audit for the pool.

Following the briefing: an AI misinformation risk assessment establishing where members stand on AI readiness and their likely exposure to misinformation, giving leadership a measured, member-by-member baseline from which risk-control priorities can be set.

Why you need to do this

AI systems already read and interpret each member's online position, and answer on their behalf, accurately or not. Until that exposure is measured, the pool carries a misinformation and misrepresentation risk it cannot quantify, price, or govern.

Why now

AI-generated answers are fast becoming the first way the public, press, and markets read your members. Every month without a baseline is another month of decisions made on an unknown position, while the exposure compounds quietly.

Why us

The assessment grades each member against the AI Readiness maturity model, benchmarking the foundations first. The result is independent, repeatable, and comparable across the membership: evidence pool leadership can act on, not opinion.

What it gives leadership

More than a one-off audit.

The assessment becomes an ongoing monitoring tool for the pool and, for carriers and insurers, evidence that reasonable steps are being taken; the situation monitored, the exposure actively mitigated.

01

Understand the risk

The first stage of any risk-control programme. The assessment establishes each member's AI readiness and likely exposure; ongoing monitoring keeps that picture current.

02

Make members aware

Findings are shared so each member knows where it stands, and what is driving its exposure.

03

Mitigate the exposure

Appropriate risk-control programmes are put in place, with progress measured against the baseline.

Questions

Questions the briefing will address.

Short answers to the concerns that usually come up before this session, without disclosing the full briefing content.

What is this briefing about?

The briefing addresses two connected but distinct exposures affecting public entity pools: rapidly escalating AI-enabled cyber exposure, and AI misinformation or misrepresentation.

Why is this relevant to a public entity risk pool?

Member exposures may create wider considerations involving shared risk control, governance, claims handling, incident response, and the support provided across the pool's membership.

Why does this issue require attention now?

Artificial intelligence is increasing the speed, scale, accessibility, and repeatability of cyber threats and misinformation, making both exposures harder to understand and control.

What does Gallagher's 57% finding demonstrate?

It demonstrates that AI errors, misinformation and hallucinations are already the market's leading perceived AI concern, rather than an isolated or theoretical technology issue. Gallagher, 2026. AI Adoption and Risk Benchmarking. Gallagher survey link

How can an organisation's own information contribute to misinformation?

AI systems rely on published information, which can be misread or repeated when that information is outdated, conflicting, incomplete, unclear, or poorly governed.

Can AI misinformation genuinely be measured?

Yes. AI misinformation exposure can be assessed systematically and evidenced, rather than relying solely on general visibility measures, individual examples, or subjective opinion.

Can the exposure be controlled?

Significant causes can be identified and addressed through stronger information control, governance, measurement, and ongoing risk management, although every element of risk cannot be eliminated.

Is this the same as a general AI Readiness briefing?

No. This session is scoped specifically to the two exposures that matter most for public entity pools. For the fuller picture, outside-in discovery, governance and visibility, the main briefing covers the full discipline.

Has the pool or its membership already been assessed?

No. The briefing does not imply that the pool or its members have already been reviewed, measured, scored, or assessed.

Why is AAAnow qualified to deliver this briefing?

AAAnow is part of the group behind Sitemorse and AAAtraq: 25 years of outside-in digital assessment, including some of the earliest AI risk profiling for accessibility compliance. More on our experience is on the About page.