Listen to this article
Executive Summary
The 1991-2016 era of open trade routes and U.S. unipolarity was a historical anomaly, not the norm. Strategies still built on those assumptions now carry material operational risk rather than serving as a conservative default.
Core conclusions
- Great-power competition, transactional geopolitics, and jurisdiction-specific regulation have replaced the single integrated global market most infrastructure and vendor strategy was designed for.
- AI is a dual-edged force: it materially shortens breach detection and response cycles, but it also expands the attack surface through agentic non-human identities, shadow AI, and AI-enabled attacks.
- The fix is redundancy, not prediction: eliminating single points of failure across vendors, cloud regions, and jurisdictions, revisited on a quarterly rather than annual cadence.
The resilience case, in ten slides
Save it, share it, or send it to whoever still thinks 2016-era assumptions are a safe default.










Organizations operated between 1991 and 2016 under assumptions that were historically exceptional rather than typical. The assumption of open trade routes, durable multilateral institutions, and cost-optimized supply chains reflected a unique geopolitical moment. Cloud infrastructure and vendor relationships were designed for efficiency rather than resilience because geopolitical considerations seemed unnecessary.
That backdrop has fundamentally shifted. U.S. unipolarity was itself an anomaly, not a stable equilibrium. International relations have reverted to the historical pattern of great-power competition. Evidence is now structural: semiconductor export controls, fragmented regulatory landscapes for data and AI, attacks on undersea cable infrastructure, and rising cybersecurity costs.
For leaders managing infrastructure, data platforms, and digital ecosystems (particularly across Asia and the Middle East), strategies built on 1990s assumptions now represent material operational risk rather than conservative defaults.
The Return of Great Power Politics
Competition among major powers constitutes a structural feature of international relations. Multipolar or bipolar competition dominated most of the twentieth century; U.S. dominance after 1991 was a brief deviation enabled by the absence of peer competitors. That condition no longer exists.
Technology has become the primary competition arena, evidenced by export restrictions on advanced semiconductors and efforts to build sovereign or allied technology stacks. Organizations that built procurement and infrastructure strategies around a single integrated global market now operate on outdated premises.
Transactional Geopolitics
The United States increasingly defines interests through narrow transactional terms, applying tariffs, export restrictions, and bilateral trade renegotiation as routine policy instruments rather than exceptional measures. China and the European Union have responded with regulatory and industrial countermeasures.
For organizations, this means cross-border data transfer, AI deployment, and critical infrastructure procurement compliance should be treated as contingent and jurisdiction-specific rather than fixed. Regulatory frameworks governing cross-border data transfer, AI deployment, and critical infrastructure procurement are being rewritten on a rolling basis simultaneously across multiple jurisdictions, meaning current compliance may not persist within twelve months.
The Cybersecurity Cycle
Offense consistently outpaces defense. The global average data breach cost in 2025 was $4.44 million, with the United States averaging over $10 million per incident; healthcare breaches averaged $7.42 million for the fourteenth consecutive year.
Just over half of breaches involved malicious activity, while human error and IT failure together accounted for roughly half of all incidents. This confirms that organizational process and training failures remain equally significant vulnerabilities as external attack.
A distinct risk category emerged in July 2024 when a single flawed software update from a major endpoint-security vendor caused approximately 8.5 million Windows systems to fail simultaneously, disrupting airlines, hospitals, banks, and government services worldwide with direct losses estimated in billions.
The lesson extends beyond cybersecurity defense to vendor concentration risk. Since both attack and failure modes are largely unpredictable in timing and origin, organizations should architect assuming breaches and outages are inevitable, with detection speed and recovery capability (not prevention alone) as primary performance metrics.
The Limits of Absolute Sovereignty
Pursuing absolute sovereignty over technology and data remains unachievable, yet regulatory trends across Asia and the Middle East move firmly in that direction. The UAE’s Personal Data Protection Law, Saudi Arabia’s Cloud Cybersecurity Controls and AI governance frameworks, India’s Digital Personal Data Protection Act, and expanding ASEAN data-localization regimes impose jurisdiction-specific requirements on data residency and access.
Over sixty countries now enforce some form of data-localization requirement. Simultaneously, physical infrastructure underpinning global connectivity remains concentrated at vulnerable chokepoints. The September 2025 severance of multiple undersea cables in the Bab el-Mandeb Strait disrupted internet connectivity across the Middle East and South Asia. Comparable incidents in the Baltic Sea and around Taiwan have been attributed, with varying confidence levels, to deliberate state-linked activity.
Sovereignty over data and infrastructure should be treated as a matter of degree and jurisdiction, not an absolute condition. The more productive objective is systematically eliminating single points of failure: whether a single vendor, cloud region, regulatory jurisdiction, or physical cable route.
Sovereignty over data and infrastructure should be treated as a matter of degree and jurisdiction, not an absolute condition.
The AI Paradox: Accelerant and Attack Surface
Artificial intelligence simultaneously represents the most significant lever for managing described volatility and a material new risk source. Defensively, organizations using AI and automation extensively in security operations reduced breach lifecycles by an average of 80 days and saved close to $1.9 million per incident in 2025, with agentic AI systems increasingly handling Tier-1 detection, triage, and remediation tasks at scale and speed unattainable by human analysts.
Offensively, the same capability expands the threat surface. Roughly one in six breaches in 2025 already involved attacker use of AI, principally for phishing and deepfake impersonation.
A faster-growing risk category emerges from agentic AI deployed inside enterprises: autonomous agents granted standing access to enterprise systems, APIs, and operational technology introduce non-human identities that legacy identity and access management frameworks were not designed to govern. Specific failure modes include prompt injection, tool misuse, privilege escalation, and cascading multi-agent failures.
Shadow AI (tools adopted by employees without security or governance oversight) was already a factor in one in five breaches in 2025, adding an average of $670,000 to breach cost, with the substantial majority of affected organizations lacking proper access controls at the time.
For organizations deploying AI within digital twins, IoT-connected operational technology, and intelligent operations platforms, this dual character is a primary design constraint, since the same agentic capability enabling real-time critical infrastructure optimization also expands autonomous decision points an adversary or poorly governed internal deployment could exploit.
Action Items for Leadership
To build organizations capable of withstanding modern risk, leadership should prioritize:
Integrate risk into decision-making. Geopolitical and operational risk should not be treated as a compliance checkbox addressed after strategy is set. It must be embedded in core decision-making (capital allocation, vendor selection, data architecture, site location) even where risk cannot be precisely quantified. Scenario-based stress testing, rather than single-point forecasting, should underpin investment cases for cross-border infrastructure and digital platforms.
Cultivate organizational agility. Agility of thinking should extend throughout the entire hierarchy, not reside solely with senior leadership. Plans provide necessary operational baselines, but leadership should assume those plans will fail under stress and should design decision rights, escalation paths, and incident-response protocols accordingly, enabling teams at every level to adapt without waiting for centralized direction. Regular cross-functional war-gaming of plausible disruption scenarios (vendor failure, regulatory shift, infrastructure outage, geopolitical shock) builds this capability more reliably than static contingency documentation.
Diversify dependencies. Avoid over-reliance on a single vendor, cloud provider, or geographic region for critical systems. This applies to cybersecurity tooling and endpoint protection as much as to cloud infrastructure and data hosting, given demonstrated concentration risk in markets dominated by few providers. For smaller organizations particularly, deliberate diversification (multi-vendor architectures, multi-region data residency aligned to local regulatory requirements, and redundant connectivity routing) remains the principal lever for mitigating systemic risk, since these organizations typically lack scale to negotiate bespoke resilience guarantees from any single provider.
Adopt deep scepticism. This is scepticism, not cynicism: a discipline of testing assumptions rather than defaulting to rejection of available data. Decisions should not wait for world stabilization, since underlying dynamics indicate volatility is now the baseline condition rather than temporary deviation. Operating models and planning horizons should instead assume continuous, dynamic shifts in regulatory, commercial, and security equilibrium, revisited on a quarterly rather than annual cadence matching environmental pace.
Govern AI as critical infrastructure, not as a productivity tool. Treat every AI agent granted access to enterprise systems, APIs, or operational technology as a non-human identity requiring the same access governance, audit trail, and revocation capabilities as a privileged human user. This requires closing the shadow AI gap through formal approval processes and continuous monitoring rather than relying on policy documents alone, and explicitly extending AI governance to digital twin and IoT-connected environments, where autonomous agent actions translate directly into physical-world operational consequences. Given regulatory developments already in train (including full EU AI Act implementation from August 2026 and parallel AI governance frameworks emerging across Saudi Arabia, the UAE, and other jurisdictions), AI governance architecture should be built for jurisdiction-specific compliance from deployment outset rather than retrofitted after implementation.
Conclusion
The organisations that prove most resilient by 2030 will be those that, in 2026, chose to leave no assumption unquestioned, and rebuilt operating models around redundancy, jurisdictional awareness, and decision-making speed rather than around predictability of a world that no longer exists.
Organizations should plan to be caught off guard and build operating models that adapt to change as standard practice.
Free tool
AI Trust, Risk & Governance Dashboard
Operationalises AI-specific threat monitoring, bias signals, data lineage, and privacy compliance, across the regulatory frameworks this article identifies as non-negotiable.
Free tool
TRACE Agent Evaluation
Before granting an agentic AI system standing access, verify that escalation and override pathways exist and have actually been tested.
The Four-Question Governance Baseline provides the organisational governance structure for treating AI as the critical infrastructure it has become.
Was this useful?
