Cyber-attacks, especially ransomware, have ranked as the number one risk for the fifth year running for firms of all sizes, according to the latest Allianz Risk Barometer.
Following last year’s series of high-profile incidents hitting the likes of Marks and Spencers and JLR, the insurance giant revealed that fears of cyber-attack have spiked, with 42% of firms now rating this as their top risk, a higher margin than ever before.
The study found that cyber risk has become the top corporate fear across every region, which Allianz said is reflective of businesses’ growing technological dependence at a time when digital security is stretched to breaking point.
However, according to the study, which surveyed more than 3,300 risk management professionals around the world, AI-related risks will soon overtake cyber-attacks to become the biggest threat companies face.
This year, AI climbed to the second biggest perceived risk in all regions, its highest-ever position and a leap from the number 10 spot in 2025’s index, making it the biggest jump in this year’s ranking.
Emerging risks linked to AI moved into the top three highest risks for firms of every size, with companies across the board becoming more aware, and more worried, about their exposure to technology’s operational, legal, and reputational implications.
While almost half of firms agreed AI is bringing more benefits to their industry than risks, a fifth say the opposite, a number that will likely grow as AI becomes more deeply embedded in core business operations.
Respondents said they expect AI risks to intensify in the near future, especially when it comes to liability concerns surrounding the use of generative and agentic AI systems, with 90% saying that moderate to high investment is needed to meet AI-driven threats.
“Companies increasingly see AI not only as a powerful strategic opportunity but also as a complex source of operational, legal, and reputational risk,” said Ludovic Subran, chief economist at Allianz.
“New liability exposures are emerging around automated decision-making, biased or discriminatory models, intellectual-property misuse, and uncertainty over who is responsible when AI-generated outputs cause harm.”
Recommended reading
- What Key Cyber Risks Are Supply Chains Facing?
- Economic Turmoil Tops AI As Leading Emerging Risk of Q3 2025
- CEOs Bracing For An Explosion of Cyber-Fraud in 2026, Finds WEF
Meanwhile, firms also reported growing unease surrounding the overreliance on a small number of third-party suppliers, particularly in areas like cloud services, SaaS, AI, and data processing.
Just three firms, Microsoft, AWS, and Google, control around 60% of the global cloud market, meaning an outage or cyber-attack hitting one of these giants would have an oversized impact on business continuity.
As a result, Allianz found that fears of business interruption and supply chain disruption remain a priority, rounding out the top three risks in this year’s ranking, an issue made worse by unprecedented pressure on operations from a combination of geopolitical, digital and climate change-related risks.





