3 emerging risks that won't show up on your risk register (yet)

4 min read
Aug 12, 2026

On the surface, cyber vulnerability, workforce evolution and geopolitical fragmentation look like separate risk conversations. And yet, they are not isolated.

These are interconnected narratives, quietly redefining where organisational exposure sits vs. where the risk register says it sits. The primary danger is not always the headline we expect, but the second-order effect underneath it.

To navigate this landscape, risk leaders must tune into the “weak signals”: subtle shifts moving the needle right now that have not yet shown up on traditional risk registers. In a recent talk, Beyond AI: 3 emerging risks reshaping global business now, Risk Leadership Network's Head of AI and emerging risk strategy, Sterling Thompson, highlighted three interconnected trends affecting global business right now. We've summarised the highlights from that talk here in this article.

Meetings icon
Beyond AI: 3 emerging risks reshaping global business in 2026
In this 30 minute talk we discuss in detail three emerging risk trends that our members are responding to.
Watch now

1. Soft targeting of critical infrastructure

When boards discuss critical infrastructure attacks, they often picture a bad actor breaking into a physical facility, like a power plant. That idea, however, is becoming obsolete, as hard targets are increasingly well-defended.

Instead, the attack surface has migrated to the unglamorous but interconnected dependencies between organisations, such as building management systems, outsourced help desks, and shared identity providers. This is soft targeting, now bolstered by AI:


When operational technology and IT converge, cyber events not only produce simple data loss, but physical, environmental and safety consequences as well. This demands a shift from asset-based to dependency-based risk mapping. It's not about what you own, but what you (and the whole sector) share. Stop defending the plant, and start defending the seams bad actors can slip through.


Horizon scanning 1-91-1-1
Get regular emerging risk trends from Risk Leadership Network's Horizon Scanner 2.0 quarterly update
The trends in this article were highlighted as part of the four-step process that we've developed to help our members to accelerate their emerging risk framework. It includes an AI-assisted horizon scanning system that provides quarterly intelligence from over 500 timely and relevant sources.
Find out more

2. The workforce-resilience relationship

As organisations hurry to automate routine tasks, achieve efficiencies and combat a shortage of skills, there is a risk. You only discover what a role actually contains, beyond its most visible, measurable task, once you remove it. By then, the knowledge, relationships, and organisational resilience it props up are already gone.

This dynamic could precipitate a silent degradation of operational resilience across industries:

 

download button
Request a free emerging risk diagnostic today
Discover how mature your emerging risk framework is compared to peers, and identify some quick wins during the call. We can also show you Horizon Scanner 2.0 in more detail.
Request now

Before you automate a role, consider mapping the unmeasured value the role provides. Make that a line item in the cost-benefit analysis before you remove it. Also, treat the capture of tacit knowledge as a control. Succession planning usually means succession of people. It should mean succession of knowledge.


3. Weaponised interdependence

The mental model of trade risk is often confined to tariffs, but this may be the wrong instrument to fully assess the current risk environment in global trade.


The focus should be on access. Export controls, entity lists, and data localisation are turning global connections between economies into points of leverage. This is a phenomenon known as weaponised interdependence. And the reach of these restrictions extends beyond domestic borders:

 

These factors raise the importance of not just forecasting scenarios, but stress-testing them. The goal of this activity isn't to predict everything that will happen, but to discover your fragilities while it's cheap.


As part of this, make sure to audit your chokepoint exposure at the nth tier, including embedded foreign technology that could pull you into someone else's export regime.


What's next?

Looking across the 3 emerging risks outlined above, there is a common lesson. The headline is not the hazard. Rather, the hazard is the hidden dependency behind the headline.

The work of the modern risk function is to make those hidden dependencies visible, before an incident, retirement or export control makes them visible for you.

If you're looking at improving your emerging risk programme, book a free emerging risk diagnostic. We'll give you an informal assessment of your emerging risk framework compared to peers. And you'll also be able to explore how our members are using Horizon Scanner 2.0 to drive action from emerging risk intelligence.


 

Get new posts by email