Cyber Security 2026 Conference
Risk Management in the AI Era: Attacks happen at machine speed, accountability at human speed.

Participation in the recent Cyber Security 2026 conference, organized by Poslovni dnevnik, once again confirmed that we are at a turning point where artificial intelligence (AI) is no longer merely a promising technology, but is becoming a cornerstone of both our business operations and our cyber defence.
Riko Luša, Head of Cyber Security at KONČAR – Digital, took part in the opening panel discussion, “Risk Management in the AI Era – Who Is Accountable?”, which examined the implications of the EU AI Act, data sovereignty, and operational risks. During the discussion, Luša described AI primarily as a powerful tool whose value depends entirely on how it is implemented. As cybersecurity professionals, we see firsthand the remarkable opportunities AI brings. It enables organizations to anticipate market demands, optimize resources, and personalize services in ways that were previously unimaginable. Across our products and services, AI acts as a highly capable partner – able to analyze thousands of pages of documentation in seconds or identify complex patterns within vast datasets. By doing so, it helps companies become faster, more competitive, and more innovative.
However, this same progress comes with a downside. Cyberattacks no longer have a human face – they have become automated, operating at machine speed. Today’s threat actors increasingly rely on autonomous, AI-driven systems that learn from failed attempts, adapt their tactics, bypass traditional security controls, and operate with minimal or no human intervention. With machines now responsible for an estimated 80 to 90 percent of cyberattacks, organizations face a significant challenge: how do you defend against systems that never sleep and are constantly evolving?

This is precisely why oversight and regulation play a critical role. Put simply, artificial intelligence is a highly capable yet not entirely reliable collaborator – one that can occasionally “hallucinate” or produce biased outcomes. For that reason, it is essential to build robust security controls into AI systems, continuously monitor their performance in real time, and ensure that every significant decision ultimately remains under human accountability. In this context, the EU AI Act should not be seen as an obstacle to innovation, but rather as a necessary framework that promotes human oversight, technical robustness, and clear accountability. At the same time, Croatia’s Cybersecurity Act reinforces the importance of threat intelligence sharing and demonstrable system resilience, helping organizations strengthen their ability to anticipate, withstand, and respond to evolving cyber threats.
Despite the challenges, the overall outlook remains positive. Technology provides us with powerful tools for progress, while regulation offers the framework needed to ensure that progress remains secure and responsible. By adopting cybersecurity best practices – such as continuous monitoring, supply chain security, regular assessments, and ongoing education for both management and employees – organizations can strengthen trust and safeguard business continuity.
Attacks may occur at machine speed, but with the right governance, expertise, and resilience, human judgment and accountability can remain one step ahead.