Milan, May 25, 2026
When artificial intelligence stops being an experiment
For years, artificial intelligence has remained in a kind of comforting limbo: promising, spectacular, at times unsettling – but still far enough away not to require real decisions. Something that was happening in labs, in tech demos, in the innovation teams of big companies. Interesting to follow, not yet urgent to govern.
Today this distance no longer exists.
AI is entering the real processes of organizations-document production, customer service, cybersecurity, supply chain, data analytics, software development, operations, decision support-with a speed that has taken even those who were watching it closely by surprise. In many organizations it is already being used daily by employees, often without policy, without governance, and without management’s full awareness of it.
And this is perhaps the most interesting-and most insidious-aspect of the current moment: AI is not entering companies through large, centralized, board-approved projects. It is entering in a distributed, spontaneous way that is difficult to control. From the bottom up. One prompt at a time.
Like all major technological transitions, this one brings with it extraordinary opportunities and new risks. On the one hand, the promise is real: processing information faster, automating repetitive tasks, improving scenario analysis, supporting increasingly complex decision-making processes. On the other, it introduces dependencies we do not yet know how to fully measure – infrastructural, energy, cognitive, regulatory, geopolitical. For behind the apparent immateriality of AI are data centers, power grids, semiconductors, global supply chains, hyperscalers, and technology concentrations unprecedented in recent history.
Questions remain open that no one has yet satisfactorily resolved. Who is responsible for a decision suggested by an algorithm? How much can we trust systems that produce plausible but not always correct content-and that do not know when they are getting it wrong? How do we prevent tools used every day by our employees from introducing reputational, legal, or security risks that we have not yet mapped? How do we govern systems that evolve faster than our procedures and regulations?
This is exactly where the theme of artificial intelligence meets that of resilience.
In this issue we have chosen to address AI not as a “tech” phenomenon to be observed with curiosity, but as a new structural factor of risk, dependency, and organizational transformation. You’ll find an analysis of the physical infrastructures that make AI possible and their vulnerabilities, an in-depth look at how BCM and crisis management systems are already changing, an explanation of how these models really work-without mystification-and an overview of European regulation, governance, accountability, and impacts on cybersecurity and incident management, all the way to fire protection.
The question, probably, is no longer whether artificial intelligence will enter organizations permanently.
The question is how quickly we can truly understand its implications, limitations and dependencies-before it becomes an invisible but essential component of our daily operations. Before, that is, it is too late to govern it with the cool head that the situation demands.
Risk&Resilience Outlook
Artificial intelligence is not immaterial
Artificial intelligence is not immaterial
For years we have treated artificial intelligence as an almost ethereal technology: models, algorithms, automation, data. Something that lives in the cloud and takes up no space. A comfortable, but less and less sustainable illusion.
Behind the rapid expansion of generative AI, a new global physical infrastructure is materializing-so it should be said: energy, data centers, semiconductors, networks, cooling systems, water, highly concentrated supply chains. Anything but immaterial.
This is the central message of theWorld Economic Forumreport.“Building Resilient and Scalable AI Value Chains: A Nexus Strategy”, released in May 2026, and probably one of the most lucid analyses in recent months on the relationship between artificial intelligence and operational resilience.
The paper shows how AI is rapidly transforming into a truly cross-cutting critical infrastructure, with implications that go far beyond the technology sector: exponentially growing data center power requirements; global dependence on a handful of advanced semiconductor manufacturers; pressure on power grids and cooling systems; far from negligible water consumption; market concentration at a few hyperscalers and cloud providers; and geopolitical exposure of the chip supply chain.
In other words: the risk is not about “the algorithm.” It is about the entire value chain that makes AI possible.
For resilience practitioners, this introduces a nontrivial shift in perspective: artificial intelligence is no longer just an operational tool to be used, but a new critical dependency to be governed. Like electricity or connectivity – without which no business continuity plan holds – AI is entering the perimeter of infrastructure that we cannot afford to take for granted.
The report also highlights an often overlooked aspect: the resilience of the AI ecosystem will depend on the ability to simultaneously coordinate energy policies, industrial supply chains, environmental sustainability and technology governance. A vulnerability in just one of these elements could trigger systemic effects on a global scale.
This reading is consistent with other recent publications that deserve attention:
- theInternational AI Safety Report 2026,which invokes the theme of “societal resilience” and the need for multilevel approaches to AI risk management;
- theMcKinsey & Company “State of AI Trust 2026,” which captures the shift toward “agentic” systems, capable not only of generating content but of performing autonomous operational actions;
- the joint reportWorld Economic Forum / KPMGon AI in cybersecurity, which shows how artificial intelligence is simultaneously becoming a defense tool and a multiplier of the attack surface;
- the report of theGlobal Risk Instituteon AI risks in the financial sector, with a focus on governance, technology focus, and operational resilience.
All these publications converge on one point: AI is not just another technological evolution. It is a new global infrastructure layer – and it will need to be governed with a maturity in terms of resilience, business continuity and risk management that, at the moment, we are still struggling to achieve.
At the top of the Resilience Manager’s list.
The risk is arriving too late
What keeps the Resilience Manager awake: The risk is not AI. It is arriving too late.
For years, Business Continuity Management has been perceived as a highly “manual” discipline: interviews, documentation, reviews, qualitative analysis, evidence gathering, reports. A job made of paper-or at least PDFs.
Today, artificial intelligence is beginning to change this scenario. Not in theory. In practice.
A number of platforms are emerging in recent months that integrate AI capabilities into incident management, crisis management, operational resilience, business continuity and root cause analysis processes. Many use generative models and “agentic” systems capable of automatically correlating events and alerts from different systems, identifying possible root causes, reconstructing incident timelines, suggesting corrective actions, and autonomously generating post-mortems. Some more advanced platforms are already experimenting with semi-autonomous capabilities for technical investigation, evidence gathering, and workflow orchestration-always under human supervision, at least for now.
Of particular interest is the evolution of AI-supportedRoot Cause Analysissystems. Several vendors and research projects are working on platforms that can simultaneously analyze logs, metrics, configurations, change management, historical incidents, and relationships between infrastructure components. The goal is to dramatically reduce the time to identify causes and improve the quality of post-event analysis. Even in the banking industry-notoriously stingy with enthusiasm for novelty-some research shows how generative AI-based approaches can identify correlations and root causes of recurring incidents that traditional analytics, especially in complex legacy environments, tend to miss.
Dedicated features are also appearing in the BCM world for dynamic updating of call trees, real-time monitoring of operational status, automated vendor analysis, centralized crisis playbook management, and AI-assisted simulations.
There are still major limitations-hallucinations, misinterpretations, lack of organizational context, algorithmic opacity, governance problems, and dependence on external models. Now is not the time to blindly rely on any of these tools.
But the more important point is another.
The resilience manager of the future will probably not be replaced by artificial intelligence. It will, however, be joined-or surpassed-by professionals capable of using these tools to more quickly analyze complex information, build better scenarios, reduce time spent on repetitive tasks, and manage increasingly complex operational ecosystems.
The question, then, is no longer“Will AI enter resilience processes?”
It is,“Is the resilience function learning how to use it before it simply becomes the market operating standard?”
Professional development
Upcoming Continuitaly courses – DRI Italy – DRI France – NFPA
Upcoming professional training courses we deliver in Italy in collaboration withDRI InternationalandNFPA
NFPA 13 – Standards for sprinkler systems.
June 29-July 3, 2026 – Online – Italian
Official NFPA course dedicated to sprinkler system design.Learn more
Business Continuity Management – Certification Course
DRI France – July 7-8, 2026 – Online – French
Business Continuity Management intensive course with certification exam (BCP501).Learn more
Cyber Resilience – Certification Course
DRI Italy – July 14-16, 2026 – Online – Italian
Cyber Resilience intensive course with certification exam (CRP501).Learn more
Regulatory news to monitor
Artificial intelligence enters European – and Italian – regulation
Artificial intelligence enters European – and Italian – regulation
For years, artificial intelligence has been developing faster than the regulatory capacity of governments and regulators. Today this is changing, and with a speed that until recently seemed unlikely. With the enactment of theAI Act, Europe has become the first major economic area to introduce a comprehensive regulatory framework dedicated to artificial intelligence. The approach taken is risk-based: the more an AI system can impact people’s rights, safety or lives, the heavier the obligations, controls and responsibilities will be.
The four categories of risk
The AI Act distinguishes four main levels.
Unacceptable risk – prohibited systems.Some uses of AI are considered incompatible with European principles and therefore prohibited: social scoring on the Chinese model, subliminal behavioral manipulation, exploitation of vulnerabilities of fragile people, some forms of massive biometric recognition, emotion recognition systems on workers.
High-risk systems.Applications with significant impacts on security, employment, credit, healthcare, critical infrastructure, education, justice, border control, and essential services fall into this category. Structured risk management, data quality and traceability, technical documentation, human oversight, logging, cybersecurity, and explicit governance become mandatory for these systems.
Limited risk – transparency requirements.This is probably the category that will impact the most organizations. Those using certain AI systems will need to clearly inform users when they are interacting with a chatbot, reading artificially generated content or viewing deepfakes. This means introducing disclaimers, content labeling, internal policies, validation procedures, and controls on generative systems used by employees.
Minimal risk.Most less critical applications remain essentially free of additional specific obligations, while remaining subject to existing regulations-GDPR, cybersecurity, labor law, intellectual property, industry regulations.
The European calendar – with some complications
The AI Act did not go into effect all at once, but in progressive steps. The first step was in February 2025, when prohibitions on prohibited AI practices and general AI literacy obligations went into effect. In August 2025, obligations for general purpose models (GPAI) were triggered. The main enforcement date is set for August 2, 2026, with full enforcement for high-risk systems embedded in regulated products expected in 2027.
There is, however, one new element worth noting. In November 2025, the European Commission unveiled the so-called“Digital Omnibus,” a reform proposal that provides, among other things, a six-month extension-to February 2027-for compliance of AI systems that generate synthetic content already on the market before August 2026. Negotiations are still ongoing: at the moment the secondpolitical trialoguebetween Parliament, the Council and the Commission has not produced an agreement, and a further round has been set for May 13, 2026. If the Omnibus is not adopted in time, the original provisions of the AI Act will go into effect on August 2, 2026 as scheduled.
In summary: the calendar is evolving, and organizations would do well to actively monitor it in the coming weeks.
And in Italy? An unexpected step forward
On the Italian front, the most relevant news in recent months is a law-and it is not a minor detail. With the Law September 23, 2025, no. 132, Italy intervened in the field of AI regulation before any other European country, flanking-not replacing-the AI Act with a national regulatory framework based on the principles of anthropocentric, transparent and safe use of AI.
The law designatesAgIDandACNasNational AI Authorities: AgID presides over innovation, development and notification functions; ACN assumes the role of market surveillance and single point of contact with the European Union, along with the Bank of Italy, Consob and IVASS for their respective sectors. Penalties can be up to 35 million euros or 7 percent of annual worldwide turnover for the most serious violations.
On the operational front, AgID has initiated a structured path of guidelines for public administration: those for AI adoption in PA were adopted in 2025, while the development and procurement guidelines were put out for public consultation until last April. Together, the three documents form a comprehensive framework that touches on principles, architecture, standards, and contractual management of AI systems.
That said, the most important issue for private organizations is not yet formal compliance. It is that many entities are already using AI tools without having defined corporate policies, classification of permitted uses, data controls, clear responsibilities, validation criteria or oversight processes.
Technology, once again, is entering organizations faster than governance.
The new theme: AI governance as a discipline
And this is where regulation meets the territory of resilience.
In the coming years, organizations will have to learn howto simultaneously managecompliance, cybersecurity, data quality, transparency, human oversight, accountability, business continuity, and dependence on external AI providers. These are not separate challenges; they are faces of the same problem.
Artificial intelligence will not just be a technological or legal issue. It will become-and in part already is-a central theme of organizational governance and operational resilience.
The technical corner
How does an artificial intelligence “reason”? A brief guide for non-specialists
How does an artificial intelligence “reason”? A brief guide for non-specialists
In recent years, the term “artificial intelligence” has become ubiquitous. But behind chatbots, virtual assistants and generative systems there remains a fundamental question that many professionals continue to ask:How does it really work?
The short answer is that modern AI systems do not “think” in the human sense of the word. They do not understand the meaning of words; they do not possess consciousness, intentions or experience. What they do is something very different-and, in some respects, much more mechanical than we imagine.
From fixed rules to neural networks
For many years, computer systems have operated through explicit rules:if A happens, do B. If the value exceeds a threshold, generate an alert.Clean, transparent, predictable logic.
Modern artificial intelligence works in a radically different way: it uses artificial neural networks, mathematical structures loosely inspired-very loosely-by the workings of the human brain. A neural network consists of billions of interconnected nodes. The nodes are simply numerical values, like switches that turn on or off in response to an input: nothing mystical, individually. The “magic” is not in the nature of the individual elements, but in the quantity and structure of the connections between them. Each connection has a “weight,” that is, a numerical value that is changed during the learning phase. The system receives huge amounts of data, analyzes correlations and patterns, and gradually modifies its internal parameters to improve its ability to predict the most likely response.
AI does not “know”: it predicts
This is perhaps the most important point to understand.
A Large Language Model does not reason like a person. Its operating principle is closer to this:“Given this sequence of words, what is the word that is statistically most likely to come next?”
It seems almost trivial. But when this process is performed on billions of words, trillions of parameters, and endless archives of texts, the result can look surprisingly — and deceptively — intelligent. The model learns linguistic structures, conceptual relationships, recurring logical patterns, writing styles. But it continues to work, fundamentally, through statistical prediction.
He does not understand. He predicts. The difference is subtle in output, but huge in implications.
How learning happens
Training an AI model requires amounts of data difficult even to imagine: books, websites, articles, software code, technical documentation, images, audio recordings, videos. During this phase – calledtraining– the system continually compares its predictions with the correct result and modifies internal parameters to reduce error. It then repeats the process. Millions of times. Over billions of parameters.
The end result is a giant statistical correlation machine, trained to produce plausible outputs from textual inputs.
Why huge data centers are needed
And this is exactly why modern AI requires colossal infrastructure: power, specialized GPUs, cooling systems, ultra-high-speed networks, dedicated data centers. That’s not a minor detail-it’s the reason we talked about AI as a new global critical infrastructure in this issue. The “cloud” weighs, consumes and depends on physical supply chains that are far more fragile than the term suggests.
The problem of “hallucinations”
Because these systems work by statistical correlation and probabilistic prediction, they can also invent references, create nonexistent information, confuse contexts, and produce convincing but completely false answers. These phenomena are calledhallucinations.
These are not necessarily failures-they are often a natural consequence of the way these systems work. The model does not “know” when it is failing. It simply produces the statistically most likely output-which is sometimes correct, sometimes not, and in both cases has the same safe tone.
AI does not eliminate judgment – it makes it more necessary
Paradoxically, the more powerful AI becomes, the more the importance of human oversight increases. The model does not understand organizational context, does not distinguish between critical operational issues and marginal details, has no accountability, and does not assess ethical or reputational implications. It does not know when it is doing wrong.
That is why, at least at present, artificial intelligence works best as a cognitive accelerator, analysis tool, document assistant, correlation engine. Not as a substitute for professional judgment.
And perhaps that is the most useful lesson for those working in resilience: understanding AI is not just about learning how to use it. It means figuring out precisely where the machine ends and where the person must begin again.
Insight&Inspirations
Suggestions of the month
Suggestions of the month
In this column, we continue to point out content that we find useful not so much for acquiring new knowledge but for refining the way we read risk, uncertainty, and strategic decisions in complex contexts.
Reports & publications
World Economic ForumBuilding Resilient and Scalable AI Value Chains: A Nexus Strategy(2026)
Probably the most useful reading of the moment for those involved in operational resilience-and in-depth in this issue’s Outlook. The report addresses an issue that is still underestimated: the growth of AI depends on very real physical and geopolitical factors-data centers, semiconductors, energy, water, hyperscalers-and the concentration of these dependencies creates systemic vulnerabilities that no business continuity plan can yet ignore.
McKinsey & CompanyState of AI Trust 2026: Shifting to the Agentic Era
Useful for understanding where we are going: from generative systems that “produce content” to “agentic” models that perform operational actions autonomously. The central theme is the governance of systems that do not wait for instructions, but act. Very relevant to those involved in accountability and risk control.
International AI Safety Report 2026
One of the most comprehensive analyses of emerging AI risks: security, reliability, systemic risk, societal impacts, international governance. Particularly interesting is the concept ofsocietal resilienceapplied to artificial intelligence-a framework that resilience practitioners will immediately recognize as their own.
Global Risk InstituteFIFAI II – Financial Industry Forum on Artificial Intelligence
Designed for the finance and insurance industry, but relevant far beyond. The focus on AI governance, operational resilience, third-party risk, and technology concentration makes it valuable reading for anyone managing critical dependencies on external providers.
Books
Ethan Mollick –Co-Intelligence.
The most pragmatic and accessible book on the human-AI relationship in everyday work. Mollick succeeds in avoiding both uncritical enthusiasm and principled rejection-and explains how to integrate generative tools into professional processes in a practical and informed way. A good starting point for anyone who wants to start using these tools in earnest.
Mustafa Suleyman –The Coming Wave
The book that introduces the concept of the “containment problem”: what happens when extremely powerful technologies become rapidly accessible and difficult to control? Suleyman-one of the founders of DeepMind-writes from inside the system, which makes the book all the more interesting and, in some ways, disturbing.
Stuart Russell –Human Compatible
For those who want to understand the structural risks of advanced AI without stopping at the surface. Russell addresses the problem of alignment between human goals and autonomous systems with rigor and lucidity. A challenging read, but among the most important for those who really want to understand what is at stake.
Podcast
Hard Fork– One of the most followed podcasts on the AI and technology world. Good balance of current events, critical analysis and concrete impacts. Good for keeping up to date without drowning in technicalities.
The Cognitive Revolution– More technical, but extremely dense in content: evolution of models, AI agents, security, automation, future scenarios. For those who want to go deep.
Eye on AI– Frequent interviews with researchers, startups, hyperscalers, and industry professionals. Useful for quickly following trends and market developments without having to read everything.
In a field that transforms virtually every week, the most important advice remains one: stop reading artificial intelligence as a technological phenomenon and start reading it as a new structural factor of organizational, operational and geopolitical transformation.
Because that is exactly what it is.
Updates from National Fire Protection Association (NFPA)
News from the international Fire Safey community
Updates from NFPA –Fire protection also enters the age of artificial intelligence
Artificial intelligence is not only transforming the IT or cybersecurity worlds. The fire protection and life safety sectors are also beginning to adopt AI-based tools-and doing so on two fronts simultaneously, both of which are relevant to resilience professionals.
NFPA LiNK 3.0 and the regulatory assistant
The most significant news in recent months comes directly from theNFPANational Fire Protection Association, which in January 2026 announced the release of the new NFPA LiNK 3.0 platform, introducing features explicitly based on artificial intelligence.
At the heart of the innovation isCASI – Codes and Standards Intelligence: an AI assistant capable of natural language querying the entire NFPA corpus of standards, producing automated summaries of technical content, and supporting advanced contextual search. Flanking CASI are tools to accelerate standards consultation, collaborative features and integrated digital notebooks.
This is an interesting shift because it shows how even historically conservative and highly technical standards-oriented organizations are beginning to integrate AI tools into everyday professional processes. This is not an ideological leap: it is pragmatism. The amount of technical regulation to be managed is now such that AI assistance is not a luxury, but a reasonable response to a real problem.
In parallel, NFPA has published a specific policy on the use of artificial intelligence in the standards development process-explicitly recognizing that these tools will also increasingly enter technical and regulatory activities that traditionally have been the exclusive territory of human experts.
The second front: data center AI as a new fire protection problem
There is, however, a second way in which AI is affecting the industry-and perhaps it is even more relevant from the perspective of operational resilience.
The explosive growth of infrastructure dedicated to artificial intelligence is rapidly changing the risk profile of hyperscale environments. Increasing power densities, electrical loads, and cooling requirements create scenarios that traditional fire protection systems were not designed to address. The latest technical analyses highlight the need for much faster detection systems, advanced pre-action protections, greater integration between detection, suppression, and monitoring, new assessments of clean agent systems, and specific management for very high power density racks.
Looking forward, this could also have an increasing impact on the evolution of standards such as NFPA 75, NFPA 76 and NFPA 855.
In other words, artificial intelligence is not just creating new digital tools for fire protection professionals. It is already concretely changing the physical infrastructure that those professionals need to protect.
Updates from Disaster Recovery Institute International (DRI)
News from the global community of certified professionals in resilience
Updates from DRI –Call for presentations open for DRI2027
DRI International (Disaster Recovery Institute)has announced the official opening of the Call for Presentations for the upcoming DRI2027 International Conference, scheduled for February 21-24, 2027 at the Loews Arlington Hotel in Arlington, Virginia.
The DRI conferences have for years been one of the leading events in the international operational resilience community-a place where business continuity, crisis management, cyber resilience, operational resilience, risk management, disaster recovery, supply chain resilience, and emerging threat management meet in one high-level professional setting.
Professionals interested in proposing a session as a speaker have untilJuly 17, 2026to submit their abstracts.
This is also a particularly interesting opportunity for European and Italian professionals: at a time when topics such as AI, DORA, operational resilience, and critical dependency management are becoming increasingly relevant in the international debate, bringing a European-and Mediterranean-perspective to the stage of a global conference has a value that goes far beyond personal visibility.abstract dri conference 2027
Resilience Leadership Newsletter is published by Phoenitx srl, a Milan-based training and consulting firm specializing in operational resilience, business continuity and risk management.
PhoenITx srl
Via Pietro Calvi, 2
20129 Milan, Italy
www.continuitaly.it
info@continuitaly.it
This post is also available in:
Would you like to find out more about our training programmes?
Discover the official international certification courses offered by DRI Italy and DRI France on Business Continuity and Cyber Resilience, or the NFPA courses on fire protection systems and all the other Continuitaly courses.













