The New Reasonable Security: How AI has changed What’s “Reasonable” (On-Demand)

Original Course Date: September 4, 2026

Artificial intelligence (AI) changes cybersecurity and cybersecurity is changed by AI. Organizations use AI as a tool for threat detection and prevention. But, should AI have the ability to decide what is a security threat without a human in the loop … or does waiting for a human decisionmaker obviate AI’s value as a threat detection tool? Should legal decision-making about ‘what’s reasonable’ cybersecurity consider use of AI a must do – like penetration testing, encryption and data deletion schedules? Does the potential for use of an organization’s data without proper masking for model improvement present a new source of security risk? Who is or should be accountable when AI gets it wrong or when AI is the source of the security threat?  Join this webinar to learn more about “reasonable” cybersecurity in the AI era.

Principles

  • AI is transforming both cybersecurity practices and cybersecurity risk.
    • Artificial intelligence enhances threat detection, monitoring, and incident response, but it also introduces new vulnerabilities, attack vectors, and governance challenges that organizations must address as part of their cybersecurity programs.
  • The standard of “reasonable” cybersecurity is evolving in the AI era.
    • As AI becomes more widely adopted, organizations and legal practitioners must evaluate whether the use—or failure to use—AI-driven security tools may influence regulatory expectations, industry standards, and assessments of reasonable cybersecurity practices.
  • Effective AI governance requires balancing automation with human oversight and accountability.
    • Organizations should establish governance frameworks that define when human review is appropriate, allocate responsibility for AI-assisted decisions, and address accountability when AI systems produce inaccurate, biased, or harmful outcomes.
  • Managing AI-related cybersecurity risk requires proactive legal and contractual safeguards.
    • Organizations should implement policies, vendor due diligence, contractual protections, and technical controls to address risks associated with AI systems, including third-party AI services, data security, model training practices, and incident response responsibilities.

Syllabus

  1. Understanding and navigating the intersection of U.S. AI and cybersecurity laws and related legal requirements
  2. How AI use may influence the standard of “what’s reasonable”
  3. Steps to protect an organization when AI makes mistakes or is the source of cybersecurity risk, including contractual clauses to mitigate third-party risk