Artificial intelligence is reshaping cyber risk faster than traditional governance models can adapt. Threat actors are already exploiting AI at scale, while regulation struggles to keep pace. For boards, the question is no longer what AI might mean, but how to govern cyber and operational risk in an environment where AI is already embedded in everyday systems and adversarial tools. Here are five steps for boards to take.