In 2018 I predicted that the SEC would require public companies to disclose cyber risk in their 10-K filings. The rule arrived in 2023 — five years late by my reckoning, but structurally identical to what I had argued for.
That is a useful data point about pattern recognition in regulated technology. The pattern was right. The timing was wrong. Both of those facts matter for what I’m about to do, which is make three predictions about AI governance in the next 24 months.
The Promise
Pattern recognition is one of the most valuable forms of analysis in fast-moving regulated industries, and it’s also one of the most dangerous. It works for two reasons.
First, regulated technology transitions tend to repeat their structure even when the technology is different. The arc looks the same: a new technology arrives, deployment outpaces governance, incidents accumulate, regulators catch up, frameworks emerge, certifications follow, and the early-mover organizations consolidate the operational knowledge that becomes the next decade’s table stakes. Cyber went through this. Data privacy went through this. AI is in the middle of it now.
Second, the structural patterns are usually visible before the timing patterns. You can often see what is going to happen before you can see when. The 2018 prediction about SEC cyber disclosure was an example. The breach economy was producing the conditions for the rule years before the rule arrived. The trick is to bet on the structure and stay agnostic about the calendar.
The Risk
The risk is that pattern recognition fails when it gets confident. The 2018 prediction got the rule right and the calendar wrong by half a decade. Which means a 2018 organization that built its cyber disclosure program based on my timing call would have spent five years carrying capability ahead of demand.
The deeper risk is that AI is not just cyber on a faster clock. It is structurally different in three ways that most pattern-matching analyses underweight.
First, the deployment pattern is different. Cyber risk concentrated in the security perimeter. AI risk lives in every workflow. The governance challenge is broader, less centralized, and harder to map.
Second, the actor model is different. Cyber regulation could focus on the operator. AI regulation has to account for providers, deployers, distributors, importers, authorized representatives, and the foundation model layer that sits underneath all of them. The accountability architecture is more complex.
Third, the harm model is different. Cyber harms are usually data, money, or business disruption. AI harms include all of those plus discrimination, defamation, hallucinated medical advice, autonomous-system failures, and harms to people who never interacted with the system. The harm taxonomy doesn’t fit neatly into existing regulatory categories.
So the predictions in the longer canonical piece — Caremark-style AI litigation, foundation model concentration risk, AI governance certifications gaining traction — are made with confidence in the structural shape but caution about the calendar.
The Verdict
The Promise & Risk needle leans Promise here, but with a discipline. Pattern recognition tells you what’s going to happen. It doesn’t tell you when. The work is to start the operational preparation early enough that the timing variance doesn’t matter.
Organizations that built cyber programs in 2018 — five years before the SEC rule — were ready when it arrived. Organizations that started in 2023 were not. The five-year gap was the difference between two very different filing cycles.
For AI, my prediction window is tighter — 18 to 24 months — because the regulatory infrastructure is moving faster. But the discipline is the same. Start now.
For the longer analysis → I wrote a deeper piece on what the 2018 prediction got right, what it got wrong, and three specific predictions for AI governance in the next 24 months.
Read I Predicted This Cybersecurity Reckoning in 2018. Here's What I'm Predicting for AI. →