Jun 24 2026 | Lawrence Shaw
The Triad of Exposure
Impact of organizations undermining themselves in the eyes of AI.
TL;DR
Organizations carry digital estates they no longer fully manage, and AI reads that estate in full. The Triad of Exposure sets out the three risks that follow: misrepresentation and misinformation, lost future visibility and competitiveness, and a cyber problem. Each surfaces in insurance, where exposure becomes financially visible through liability, a risk that positions traditional cyber risk as minor compared with exposure an organization may inadvertently be self-perpetuating.
The risk is not what AI will do. It is what AI is already reading.
Most boards are dealing with the AI position they can see, and the risks attached to it. The bigger one is invisible: AI is already answering questions about your company using pages you forgot you published. Digital teams have been screaming about this for years, unheard. Now AI has made it a boardroom problem.
World Economic Forum, Global Risks Report 2026 digest: misinformation / disinformation ranked second over two years, with adverse outcomes of AI rising sharply over ten years. Control of what you know, with oversight of what you own important.
Post-COVID publishing growth, distributed content updates, department self-build projects, and material left online after its purpose has passed have created a digital estate organizations have lost sight of, or worse, content the digital team was never aware of.
The Triad of Exposure names three distinct risks that follow from that position: misrepresentation and misinformation, future visibility and competitiveness, and the cyber problem. None requires AI to behave unusually. Each follows directly from the gap between what the organization manages and what remains visible.
Misrepresented, outranked, or quietly exposed: you cannot fix what you have never mapped. This article and our report set out how this exposure forms, why it sits outside what risk and governance currently measure, and the first practical move to bring it under control.
Listen: AI turns digital sprawl into active risk
A briefing on what AI reads across an organization's online estate, and the three exposures it creates. Voice intro length: 4 min 47 sec.
Three exposures
Exposure 01
Misrepresentation and misinformation
AI reads outdated material and presents it with confidence. The concern is not theoretical: it is the leading AI threat in the 2026 Gallagher benchmarking, cited by 57% of respondents.
Exposure 02
Future visibility and competitiveness
85% of brand mentions in AI search come from third-party content. With owned material unclear, the wider picture is harder to influence, and harder to correct once it circulates.
Exposure 03
The cyber problem
Old domains, forgotten subdomains, one-off campaigns, and joint partner pages stay online without maintenance. The estate AI reads is the same estate attackers probe for vulnerabilities.
“An organization’s AI readiness is measured by what AI reads across the footprint it has built online over years, much of it forgotten, not by what it believes it presents today.”
First exposure: misrepresentation and misinformation
AI errors, misinformation and hallucinations are the leading perceived AI threat in Gallagher’s 2026 AI Adoption and Risk Benchmarking, cited by 57% of respondents. That concern takes on a more specific shape when the mechanism is considered: AI reads the material that is available. If that material is outdated, contradictory, or superseded, AI will often present it as if it were current.
This is not a failure of AI capability. It is a consequence of the estate an organization has accumulated. The more material there is that no longer accurately represents the organization, the greater the surface area for inaccurate AI output.
Gallagher’s 2026 AI Adoption and Risk Benchmarking surveyed organizations on their primary AI concerns. Misrepresentation through AI errors and hallucinations came out as the leading perceived threat.
Source: Gallagher. 2026 AI Adoption and Risk Benchmarking. The 57% figure is as cited.
Second exposure: future visibility and competitiveness
McKinsey reports that brand-owned sites account for 5 to 10% of the sources AI search references in many categories. AirOps reports that 85% of brand mentions in AI search come from third-party content. The organization’s own estate is no longer the whole picture, but unclear owned material makes the wider picture harder to influence.
Adobe reported that traffic from AI sources to US retail sites grew 393% year on year in Q1 2026. AI is not only a research layer. It is becoming part of how demand is directed, which makes accurate representation and inclusion progressively more valuable. The commercial case for governance was already forming; that figure accelerates it.
The compounding factor is time. AI capability is moving from answering to acting. As agentic AI becomes more embedded in research, procurement, and recommendation flows, the estate that is unclear today becomes harder to manage once it has already been read, summarized, and used elsewhere. Correcting a record after it has circulated costs more than managing it before it does.
Third exposure: the cyber problem
Unknown, unmanaged assets are an open door. Old domains, forgotten subdomains, and legacy applications that remain online are almost always unmaintained, and unmaintained software is unpatched software. The surface area that AI can read from the outside is the same surface area a motivated attacker can probe.
In June 2026, a US export control directive suspended access to Anthropic’s Fable 5 and Mythos 5 models over their cybersecurity capability. The capability that drew that regulatory response is the capability now reading the estate an organization has lost sight of. The cyber dimension is not a future concern. It is present in the same unmanaged estate that creates the first two exposures.
Digital teams have warned about this for years: clearer ownership, fewer platforms, stronger control, a single manageable digital estate. Post-COVID publishing growth made that harder to achieve, with more short-life content, more distributed updates, and more material left online after its purpose has passed. The backlog grew faster than the governance.
Insurance impact: exposure, mitigation and evidence
Insurance is not separate from the Triad of Exposure. It is one of the places where exposure becomes financially visible. Misrepresentation, misinformation and cyber exposure can each lead to questions about loss, liability, policy wording, exclusions, limits, controls, and the evidence an organization can produce to show mitigation.
Gallagher’s 2026 AI Adoption and Risk Benchmarking reports that AI errors, misinformation and hallucinations are the leading threat from AI adoption, cited by 57% of respondents. The same report says one in five 1 in 5 insurance industry respondents had a client experience loss or claims from AI-related risks in the past year, with just over half fully covered. Gallagher also notes that AI-related exposures are driving exclusions, endorsements, bolt-on covers, and bespoke AI policies.
| Exposure | Insurance relevance | Evidence leadership should be able to show |
|---|---|---|
| Misrepresentation | AI may present the organization in a way leadership would not approve, creating customer, adviser, regulatory, or reputational questions. | A mapped public estate, current authoritative content, removed or corrected outdated material, and a record of decisions. |
| Misinformation | AI may use old or conflicting material to produce inaccurate answers that create loss, complaints, or dispute over what the organization represented. | Evidence that high-risk content has been identified, prioritized, corrected, consolidated, or withdrawn. |
| Cyber exposure | Unknown assets may sit outside normal security control, which can affect risk quality and underwriting confidence. | A view of externally visible assets, ownership, retirement decisions, and reduction of unmanaged surfaces. |
Insurance is built on risk transfer after mitigation, not as a replacement for it. RUSI describes cyber insurance as a mechanism for transferring residual risk after other risk management practices have been applied. OECD analysis notes that insurers increasingly use data, analytical tools, and engagement platforms to support risk assessment and policyholder risk reduction. Evidence of action therefore matters.
Marsh frames generative AI as a risk and insurance challenge because it can amplify misinformation, technological error and hallucinations at scale. Its guidance says AI can create and distribute misinformation faster than humans, while chatbot hallucinations can provide incorrect customer information about products and services. Marsh links this to operational, legal, regulatory and insurance exposure.
Alliant frames AI misinformation as a real-world liability issue, not a theoretical technology concern. Its AI in Insurance commentary cites fake ChatGPT legal cases reaching court, then states that AI information cannot be fully trusted without human vetting. Its governance guidance links responsible AI use to accountability, transparency, security, compliance and reputational protection.
Organizations that can demonstrate they are identifying, assessing, and reducing exposure are better placed in underwriting and renewal discussions than organizations relying on assertion. No outcome is automatic. The value lies in having evidence of mitigation, which gives executives a stronger basis to discuss risk quality, coverage terms, limits, and exclusions.
The scale that matters: 41%
P&C/Sitemorse risk profiling, covering more than 100 million websites across the period 2017 to 2023, indicates that 41% of an organization’s digital footprint is unknown to its own digital teams. That is not a web management statistic. It is a measure of the exposure AI can read from the outside that the organization itself cannot see.
Of the total digital footprint, 41% is unknown to digital teams.
- 41% unknown to digital teams
- 59% within the managed estate
Source: P&C / Sitemorse risk profiling, 2017 to 2023, covering more than 100 million websites.
That 41% is the part of the estate where misrepresentation sits unchecked, where old content shapes AI outputs that no one inside the organization has authorized, and where the cyber exposure is most acute. It is also, practically, where a governance program begins: not with a major eight-month consultative exercise, but with mapping what is actually there.

Report: The Triad of Exposure
An external report examining what AI reads across the estate an organization has built online, the three exposures it creates, and the financial cost of leaving the unknown estate in place.
Content is for informational purposes only and does not constitute legal advice.
Why this belongs at executive level
Misrepresentation can affect trust. Misinformation creates regulatory issues. Weak visibility affects future demand. Maintaining material that no longer supports the organization can keep cost in the system while increasing the work needed to correct it, and that cost compounds the longer it is left.
The three exposures do not sit in a single department. Misrepresentation touches communications and legal. Visibility affects commercial teams. The cyber dimension involves IT, risk, and the board. A governance response that sits below executive level will not reach across all three. The scope of the problem matches the scope of who needs to own the answer.
This is also a timing issue. The AI decision should not be framed as what to build next. It should start with what exposure the organization is already carrying. The estate that is unclear today is being read now, by AI systems that will carry what they find into outputs, recommendations, and decisions. The ground does not pause while the program is planned.
Extracts WEF / Global Impacts of AI
The World Economic Forum identifies false or misleading information as a material risk, with AI increasing both the volume of content and the difficulty of distinguishing accurate information from inaccurate material. Also that misinformation can result from AI-hallucinated content (commonly caused from foundation issues such as broken links to key references) or human error, making the issue relevant beyond deliberate campaigns.
For organizations, this creates a governance exposure wherever information is published, reused or trusted without current oversight. Out-of-date pages, unmanaged content, weak ownership and poor review controls can allow inaccurate information to persist, then be repeated by users, search engines, AI systems and external advisers.
WEF’s cybersecurity reporting adds a connected exposure: expanding supply chains reduce visibility, increase attack surfaces and make third-party vulnerabilities harder to control. That matters because compromised digital assets, software dependencies or supplier systems can become trusted routes for hostile or inaccurate content. The practical lesson is clear: organizations need current visibility over their digital estate.
Immediate steps, not 8 months of planning
The first step is not a major program. AAAnow offers a Discovery and Mapping answer. Two days of client resource to start; the work continues remotely. Within 90 days, leadership can see what exists, where exposure sits, and what should be kept, corrected, or removed.
AAAnow’s relevance is that it starts where the exposure starts: outside-in, with the estate AI can already read. The value is evidence of what is visible, what is unknown, and where the organization is carrying unnecessary risk, mapped against 25 years of digital assessment and 3.7 trillion data points.
The AI readiness decision begins with what is already there, not what is planned next.
Sources
- McKinsey & Company. New front door to the internet: Winning in the age of AI search. https://www.mckinsey.com/capabilities/growth-marketing-and-sales/our-insights/new-front-door-to-the-internet-winning-in-the-age-of-ai-search
- AirOps. The Influence of Offsite Signals in AI Search. https://www.airops.com/report/the-influence-of-offsite-signals-in-ai-search
- arXiv. UDA: A Benchmark Suite for Retrieval Augmented Generation in Real-world Document Analysis. https://arxiv.org/abs/2406.15187
- arXiv. Revolutionizing Retrieval-Augmented Generation with Enhanced PDF Structure Recognition. https://arxiv.org/abs/2401.12599
- arXiv. Capturing Logical Structure of Visually Structured Documents with Multimodal Transition Parser. https://arxiv.org/abs/2105.00150
- arXiv. Understanding the Logical and Semantic Structure of Large Documents. https://arxiv.org/abs/1709.00770
- arXiv. Structured Linked Data as a Memory Layer for Agent-Orchestrated Retrieval. https://arxiv.org/abs/2603.10700
- Section508.gov. Create accessible PDFs. https://www.section508.gov/create/pdfs/
- Government Digital Service. Why GOV.UK content should be published in HTML and not PDF. https://gds.blog.gov.uk/2018/07/16/why-gov-uk-content-should-be-published-in-html-and-not-pdf/
- CACI. Website sprawl: the cost of CMS fragmentation. https://www.caci.co.uk/blog/website-sprawl-cost-cms-fragmentation/
- Gallagher. The 2026 AI Adoption and Risk Benchmarking survey. https://www.ajg.com/news-and-insights/features/ai-adoption-and-risk-benchmarking-2026/
- OECD. Leveraging technology in insurance to enhance risk assessment and policyholder risk reduction. https://www.oecd.org/finance/leveraging-technology-in-insurance-to-enhance-risk-assessment-and-policyholder-risk-reduction.htm
- RUSI. Cyber Insurance and the Cyber Security Challenge. https://static.rusi.org/247-op-cyber-insurance-fwv.pdf
- Marsh. Debunking Generative AI myth #3: GenAI insurance issues. Generative AI can amplify misinformation and hallucinations. https://www.marsh.com/en/services/cyber-risk/insights/gen-ai-three-myths-ai-insurance.html
- Marsh. Two years after ChatGPT: The evolving world of generative AI, risk, and insurance. Chatbot hallucinations can provide incorrect customer information. https://www.marsh.com/en/services/cyber-risk/insights/generative-ai-evolving-considerations.html
- Alliant. AI in Insurance - Revolutionizing the Industry. Unchecked AI information can create real-world liability. https://engage.alliant.com/trendsandviewsQ323/article5-503T1-214633.html
- Alliant. Establishing a Governance Framework for AI Risk Management. AI governance must address accountability, transparency, security, compliance and reputational damage. https://alliant.com/news-resources/article-establishing-a-governance-framework-for-ai-risk-management/
- World Economic Forum. Global Risks 2025, a world of growing divisions. Supports the points that false or misleading content is rising, AI makes it harder to distinguish true information, and misinformation can result from AI-hallucinated content or human error. https://www.weforum.org/publications/global-risks-report-2025/global-risks-2025-a-world-of-growing-divisions-c943fe3ba0/
- World Economic Forum. 5 risk factors from supply chain interdependencies. Supports the points on limited supply-chain visibility, growing attack surfaces, system interdependencies, third-party vulnerabilities, and weaker control over supplier security maturity. https://www.weforum.org/stories/2025/01/5-risk-factors-supply-chain-interdependencies-cybersecurity/
- World Economic Forum. Global Cybersecurity Outlook 2025, understanding complexity in cyberspace. Supports the points on third-party software vulnerabilities, lack of ecosystem visibility, uncertainty across dependencies, AI-related vulnerabilities and the need to understand organization-specific cyber risks. https://www.weforum.org/publications/global-cybersecurity-outlook-2025/in-full/1-understanding-complexity-in-cyberspace-587e8c5eba/
- Gartner. Rise in business technologists: 41% of employees in 2022, predicted to reach 75% by 2027. https://www.gartner.com/en/newsroom/press-releases/2022-03-13-gartner-survey-finds-rise-in-business-technologists-is-driving-funding-for-tech-purchases-outside-of-it
- P&C. Sitemorse risk profiling, 2017 to 2023, covering more than 100 million websites. https://www.aaanow.ai/
- Anthropic. Statement on the US government directive to suspend access to Fable 5 and Mythos 5, 12 June 2026. https://www.anthropic.com/news/fable-mythos-access
- Fortune. Anthropic disables Fable and Mythos AI models following US government export ban, 13 June 2026. https://fortune.com/2026/06/13/anth
