In the following guest post, Chris Mosley and John Orr discuss the findings from the 2026 North America edition of the Global Directors’ and Officers’ Survey, developed by Willis, a WTW business, in collaboration with Reed Smith LLP. As the survey results show, cyber risk remains the leading concern for directors and officers in North America, while artificial intelligence has emerged as one of the fastest-rising areas of board-level focus. The survey also highlights growing concerns surrounding governance, regulatory compliance, supply chain disruption, and litigation risk. Chris Mosley is a partner in the Denver office of Reed Smith who focuses his practice on insurance recovery exclusively on behalf of policyholders, and John Orr is the D&O Liability Product Leader for Willis, North America, based in San Francisco. Our thanks to Chris and John for allowing us to publish their article on our site.


The 2026 edition of the Global Directors’ and Officers’ Survey, developed in collaboration between Willis, a WTW business, and Reed Smith LLP, maintains the survey’s ongoing international focus, with responses from directors, officers and risk managers in more than 40 countries. The survey asks respondents to assess the importance of specified risks for directors and officers, whether financial, reputational or both. This discussion focuses on responses from North America, including the United States and Canada. The North America region accounted for 13% of global responses, comprising 127 respondents from the United States and 3 from Canada.

This year’s North America results reflect a risk landscape shaped by a familiar combination of cyber exposure, core governance issues and the rapidly increasing prominence of artificial intelligence. Responses from both the U.S. and Canada suggest that directors and officers remain highly attuned to risks capable of causing near-term disruption, while at the same time assigning greater weight to emerging, technology-driven threats that may alter risk profiles over time.

Cyber risks retain the top spot

Cyber risk again ranked as the most significant concern for North America respondents, consistent with results from recent years. Among specific exposures, cyber attack risk (including cyber extortion) was cited as very or extremely important by 83% of respondents, making it the highest ranked risk overall. Data loss followed closely, with 81% of respondents identifying it as a critical concern. These results represent notable increases from the prior year’s survey, where data loss led at 77% and cyber attack followed at 76%; the two risks have effectively swapped positions, with cyber attack moving from number two to number one, reflecting the escalating sophistication and frequency of cyberattacks facing organizations today.

This heightened concern among North American respondents aligns with broader global trends. The World Economic Forum’s Global Cybersecurity Outlook 2026 report highlighted the growing sophistication of cybercriminals, fueled in part by rapid advances in generative AI, while IBM’s Cost of a Data Breach Report 2025 estimated that the global average cost of a data breach reached approximately $4.44 million. AI-powered social engineering, deepfake fraud and ransomware attacks have fundamentally altered the corporate threat landscape, making it increasingly difficult for organizations to distinguish genuine communications from malicious ones. Taken together, these findings underscore that cyber-related exposures continue to sit at the top of board and executive risk agendas across the region, reflecting both their frequency and potential severity.

Beyond cyber, health and safety remained a top tier concern. Eighty percent of North America respondents rated health and safety as very or extremely important, making it the third highest ranked risk overall. This represents a significant increase from its number four ranking at 71% in 2025 and contrasts with global results where health and safety remained the number one overall risk at 76%. Despite sustained focus in prior years, the category has not receded in importance, reflecting its wide ranging implications for employee well being, operational continuity and organizational reputation. Within this risk area, respondents most frequently pointed to mental health, financial well being, burnout, work demands and working hours as key workforce related challenges.

North America Top 7 Risks

The Trump Administration: Deregulation continues

Governance and compliance risks also featured prominently. Systems and controls were rated as very or extremely important by 72% of respondents, highlighting the ongoing emphasis on internal oversight, control environments and effective risk management processes. Regulatory breach followed closely at 68%, reflecting continued concern around compliance obligations and enforcement exposure. This increase from 62% in 2025 may appear counterintuitive given the deregulatory environment under the Trump Administration, but it likely reflects the complexity and uncertainty that the evolving regulatory landscape creates for companies seeking to maintain compliance.

The United States Securities and Exchange Commission (SEC) under the Trump Administration has continued to scale back the aggressive enforcement approach that characterized the Biden-era SEC under Chair Gary Gensler, moving to roll back rulemakings including effectively shelving the SEC’s climate-related disclosure rules and abandoning proposed rules related to human capital management disclosure and corporate board diversity.

Of particular note, the executive order issued in February 2025 announcing a “pause” on enforcement of the Foreign Corrupt Practices Act remains in effect, with the Attorney General having issued revised enforcement guidelines favoring a more restrained approach. Companies would be well-advised to maintain robust compliance programs regardless of the current enforcement posture, given that the Foreign Corrupt Practices Act’s (FCPA) five-year statute of limitations means violations committed during this period could be prosecuted by a future administration.

At the same time, state attorneys general have stepped up enforcement activity to fill perceived gaps left by reduced federal oversight, creating a complex compliance environment in which companies must navigate both a more permissive federal regulatory regime and potentially more aggressive state-level enforcement. While cyber risks clearly dominate the rankings, these results suggest that foundational governance disciplines retain a critical place in director and officer oversight in North America.

AI risk: A dramatic rise

One of the more notable shifts in the 2026 survey is the elevated importance assigned to artificial intelligence. AI and machine learning were rated as very or extremely important by 72% of North America respondents, placing AI firmly within the region’s top five risks. This represents a 30-percentage-point surge from just 42% in 2025 — the largest single-year increase for any risk in this year’s North America results — reflecting the rapidly growing recognition among directors and officers that artificial intelligence presents both transformational opportunity and significant liability exposure.

The concern is well-founded: according to Cornerstone Research’s Securities Class Action Filings, 2025 Year in Review, 16 AI-related securities class actions were filed in 2025, a slight increase from the 15 such cases filed in 2024, which itself represented more than double the seven cases filed in 2023. These lawsuits increasingly target so-called “AI washing,” where companies allegedly overstate AI capabilities to enhance their business prospects and inflate share prices.

Among respondents identifying AI as a material concern, the most frequently cited issues included AI generated errors and misinformation (51%), AI enabled fraud and social engineering (40%), strategic failure to adopt AI (37%), weak governance and uncontrolled AI use (32%) and poor data quality and bias (26%). The regulatory landscape for AI remains fragmented in the United States.

Under the Trump Administration, it appears unlikely that comprehensive federal AI regulation will be adopted anytime soon, with the Administration continuing to favor a light-touch approach aimed at promoting AI technological advancement. In December 2025, the President issued an executive order establishing a national policy framework for artificial intelligence, further signaling the federal government’s preference for facilitating innovation over prescriptive regulation. However, state-level activity continues apace: during 2024 and 2025, virtually every state introduced AI-related bills and a growing number of states have enacted broad AI legislation. The result is an increasingly complex patchwork of state regulations that may create significant compliance challenges for companies operating across multiple jurisdictions, particularly those with inadequate AI governance frameworks. These responses suggest that boards are increasingly grappling with both the operational risks associated with AI deployment and the longer term competitive risks associated with delayed or ineffective adoption.

Supply chain risk enters the picture

Rounding out the top risk group, supply chain issues were identified as very or extremely important by 66% of respondents. This risk was not among the top seven in last year’s North America results and its emergence reflects the growing recognition that supply chain disruptions pose direct risks to directors and officers — not only operationally but also from a liability and governance perspective.

The current environment has placed unprecedented pressure on corporate supply chains. According to a Thomson Reuters report, 72% of trade professionals identified U.S. tariff volatility as the most impactful regulatory change in 2026, a dramatic increase from 41% the previous year. The Trump Administration’s tariff policies — including sweeping tariffs on goods from China, Mexico, Canada and other trading partners — have created sustained uncertainty that affects sourcing, manufacturing and distribution strategies across industries.

One industry report found that 86% of companies reported experiencing a supply chain loss in the past year, with rising material costs, geopolitical instability and tariff and trade disputes cited as the top three drivers of disruption. PwC’s 2025 Annual Corporate Directors Survey found that virtually all industrial products directors expressed concern about geopolitical instability, with trade policy and tariffs identified as the top external barrier to growth. Nearly two-thirds of directors reported that their boards discussed supply chain management at every meeting, yet nearly half said their boards needed to spend more time on the issue.

For directors and officers, the D&O implications of supply chain disruption are multifaceted: failures to adequately disclose supply chain risks, inadequate board oversight of supply chain resilience and the cascading financial impacts of disruption can all give rise to securities claims and derivative litigation.

Litigation risks remain elevated

Civil litigation and third party claims were also identified as meaningful areas of exposure, though they ranked just outside the top tier for North America. According to Cornerstone Research’s Securities Class Action Filings, 2025 Year in Review, plaintiffs filed 207 new securities class actions in 2025, a decline from 226 filings in 2024. However, the overall size of filings increased substantially: Disclosure Dollar Loss surged to a record $694 billion in 2025, up sharply from $429 billion in 2024, while Maximum Dollar Loss rose to $2,862 billion, its third-highest level on record. The median securities class action settlement amount reached $17.3 million, a nearly three-decade high.

Derivative actions continue to be a significant concern for directors and officers and their insurers, with large cash settlements in derivative cases remaining a particular worry, especially as companies may not be able to indemnify for such settlements. It is also worth noting that the decrease in SEC enforcement activity could give rise to a more aggressive plaintiffs’ bar, eager to pursue claims that the SEC may be less inclined to bring under the current administration. These findings indicate that litigation risk remains an important concern relative to cyber, governance and operational risks.

ESG risks: A shifting landscape

Environmental, social and governance (ESG) risks continue to appear among many of the surveyed subjects that ranked in North America, though the relative weight of these concerns is evolving. Health and safety (80%) and systems and controls (72%) represent the social and governance categories that ranked highest, while regulatory breach (68%) also reflects governance concerns.

Notably absent from this year’s top seven is diversity, equity and inclusion, which ranked number seven in 2025 at 54%. This shift likely reflects the continued impact of anti-DEI political pressures in the United States, including the Trump Administration’s executive orders targeting “illegal DEI” and the Department of Justice’s (DOJ) directives to investigate companies maintaining certain DEI policies. The evolving legal and political environment around DEI presents a complex challenge for companies: while federal pressure has intensified against certain DEI practices, many shareholders, employees and customers continue to support diversity initiatives, creating potential liability exposure regardless of the approach a company takes.

Risks in the environmental categories continue to be viewed as less important by North America respondents than those in other global regions. Under the current Administration, the SEC’s climate-related disclosure rules have been effectively abandoned; however, companies should not assume that environmental disclosure obligations have disappeared entirely. California’s climate disclosure laws remain in effect (pending court challenges) and a number of other states — including Illinois, Minnesota, New York and Washington — are considering similar legislation. Moreover, companies doing business in the European Union remain subject to the EU’s sustainability disclosure requirements.

D&O insurance: Board preparedness under scrutiny

The survey also provides insight into directors’ and officers’ insurance priorities and board preparedness. Among North America respondents, claims related considerations – particularly claims control and settlement – were cited as key areas of focus, alongside dispute resolution with insurers, choice of defense counsel and coverage for cyber related claims. This emphasis suggests a strong awareness of how D&O policies perform once a claim arises, rather than an exclusive focus on limits or headline coverage terms.

Globally, respondents expressed strongest confidence in their fellow board directors’ ability to oversee financial performance monitoring and reporting (84%) and purpose and strategy development (80%), while confidence was notably lower for AI (54%), broader sustainability (51%) and climate risk and transition (48%). The low confidence in AI oversight is particularly notable given that AI has surged into the top five risk concerns in North America, suggesting a meaningful gap between perceived risk and board-level readiness to manage that risk.

The survey further found that 33% of respondents globally considered operational resilience to be within the top five issues requiring more time or having greatest materiality to their business, with increased risk exposure (including third-party and supply chain risk) cited as the most concerning aspect of operational resilience at 39%.

Looking ahead

Taken together, the 2026 North America results point to a mature risk environment. Long standing exposures such as cyber risk, governance and health and safety retain a central place in board oversight, while emerging risks – most notably artificial intelligence – are quickly becoming embedded in mainstream board level discussions rather than treated as peripheral or speculative concerns. As the risk environment grows more complex, boards will need to ensure they have the skills, information and governance structures to exercise effective oversight — particularly in areas such as AI and operational resilience, where the survey data suggests that board preparedness may not yet match the magnitude of the risk.

*This article first appeared on the Willis website at https://www.wtwco.com/en-us/insights/2026/07/global-directors-and-officers-survey-report-2026-north-america

In Episode 7 of the D&O Diary Podcast Series, we sat down with Stephen Sills, Founder and CEO of Bowhead Specialty, to discuss the evolution of the D&O insurance marketplace and the lessons Stephen has learned throughout a career spent building, leading, and growing successful insurance organizations.

Few industry leaders have as broad a perspective on the D&O marketplace as Stephen. Drawing on decades of experience across multiple market cycles, he shared his views on how the industry has evolved, the challenges facing underwriters today, and the trends that are likely to shape the market’s future. Our conversation explored the many changes that have transformed the D&O landscape, from shifts in underwriting philosophy and market conditions to the growing role of technology and data-driven decision-making.

Stephen also offered valuable insights into the factors driving today’s market, including the increasing complexity of risk assessment, emerging risks such as artificial intelligence and AI-related litigation, and the ways underwriters are adapting to a rapidly changing environment. In addition, he reflected on the importance of leadership, organizational culture, and talent development in building high-performing and enduring insurance businesses.

For insurance professionals, underwriters, brokers, and industry leaders alike, Stephen’s observations provide a compelling look at where the D&O marketplace has been, where it stands today, and where it may be headed next.

We would like to thank Stephen for joining us and for sharing his experiences and perspectives. We hope you enjoy this latest episode of the D&O Diary Podcast Series.

🎧 Listen now on:

Apple Podcasts: https://podcasts.apple.com/us/podcast/the-d-o-diary-podcast/id1896880954?i=1000789802728

Spotify: https://open.spotify.com/episode/5PjlanMhi3yWXOaLEauyPr?si=IplZQPbqQLKdvBebC-MnWw

📺 Watch on YouTube: https://youtu.be/XVfIzLBwueM

If you enjoy the podcast, please consider following the series and sharing it with colleagues. We also welcome your suggestions for future topics.

Follow us on LinkedIn here to be notified when new D&O Diary posts are published.

Artificial intelligence has generated considerable discussion about operational, regulatory, and compliance risks that may translate into D&O underwriting exposure. An August 27, 2026, ruling allowing a securities class action against CVS to proceed highlights a growing source of securities litigation risk arising when AI-enabled business processes materially contribute to financial performance. The Southern District of New York granted in part and denied in part CVS’s motion to dismiss, permitting claims to proceed based on allegations that the company failed to disclose material information regarding the role AI-assisted prior authorization processes allegedly played in generating cost savings and supporting profitability.

Continue Reading The CVS Case and the Emerging D&O Risks of AI-Driven Performance

One of the recurring issues in D&O coverage litigation is whether an individual director or officer was acting in an insured capacity when the conduct that gave rise to a claim occurred. Because directors and officers often serve in multiple roles, as executives, shareholders, investors, lenders, or guarantors, the capacity question can be complex, but the answer can be coverage dispositive.

Continue Reading Eighth Circuit: D&O Policy Does Not Cover Executives’ Personal Loan Guarantees

In a recent decision, the 11th Circuit reversed a lower court’s blockbuster ruling holding that the qui tam provisions of the False Claims Act violate the U.S. Constitution’s Appointments Clause. The appellate court left other key constitutional questions unanswered and remanded the case to the district court for further proceedings, leaving the door open for further judicial consideration of the constitutionality of the qui tam provisions. The Eleventh Circuit’s September 1, 2026, opinion can be found here.

Continue Reading False Claims Act’s Qui Tam Provisions Survive Constitutional Challenge

Over the last several months, the boards of a number of tech companies have been hit with “follow on” shareholder derivative lawsuits, after the companies were first sued in underlying intellectual property suits. The derivative lawsuits allege that the companies’ boards knowingly allowed their companies to use copyrighted materials to train their AI models, resulting in the underlying IP liability litigation, as well as potential IP-related liability. In the following guest post, Nathaniel French and Mason Dressler take a detailed look at the latest of these lawsuits, filed against Apple’s board. Nate is a partner and Mason is an associate at the Kennedys law firm. Our thanks to Nate and Mason for allowing us to publish their article on this site.

Continue Reading Guest Post: Apple Intelligence: Ongoing Risks Associated with AI Development

On August 21, 2026, when the Tioga-Franklin Saving Bank of Philadelphia was closed by banking regulators, it became the fifth U.S. bank to fail this year. The five failures so far in 2026 comes after only two banks closed in 2024 and in 2025, respectively. News of the most recent closure left me wondering if perhaps there was something to worry about with the recent apparent uptick in bank failures. Turns out, I am not the only one wondering about this. On August 26, 2026, Law.com ran an article considering what might be causing the recent increase in the number of bank failures. While the Law.com article concludes that the banks closed this year mostly failed due to operating problems specific to the failed institutions involved, there is still enough there to take a closer look at what is going on.

Continue Reading Should We Worry About the Uptick in Bank Failures?

The D&O Diary has been closely following the growing number of lawsuits, investigations, and governance concerns emerging from the private credit sector. Private credit generally refers to loans made by non-bank lenders, which may include private funds or asset managers, to corporate borrowers. As private credit managers have become increasingly integrated with life insurers and affiliated businesses, questions surrounding related-party transactions and disclosure practices have attracted heightened scrutiny. The investigations involving Mark Walter and several entities within his business empire provide a particularly noteworthy example of how these concerns can evolve into significant regulatory and potential D&O liability events.

While public attention has focused on Walter’s ownership interests in major sports franchises, the underlying investigations reportedly involve questions surrounding affiliated private credit investments, related-party transactions, and disclosure practices involving insurer assets. The circumstances remain ongoing, and no wrongdoing has been alleged. Because the investigations and related proceedings remain ongoing and the relevant facts remain under development, the term “Walter matter” is used throughout this article as a neutral description of the situation.

As discussed below, the Walter matter offers an instructive case study of how questions involving affiliated transactions can develop into significant regulatory scrutiny and potential D&O liability exposures.

Continue Reading Private Credit, Affiliated Transactions, and D&O Risk

Every year after Labor Day, The D&O Diary takes a step back to survey the most important current trends and developments in the world of Directors’ and Officers’ liability and insurance. This year’s review is set out below. As the following discussion shows, this is a particularly interesting time in the world of D&O.

Continue Reading What to Watch in the World of D&O
Stephen Hourigan

In the following guest post, Stephen Hourigan argues that a key driver of D&O claim severity is not necessarily board ignorance or misconduct, but the delay between when warning signs are known somewhere within the organization and when they are effectively communicated to the board. Steve suggests that there are questions underwriters can ask to determine the effectiveness of information communication to corporate boards. Steve is the Founder and CEO of Heardsafe, LLC. Our thanks to Steve for allowing us to publish his article as a guest post on our site.

Continue Reading Guest Post: Governance Signal Decay as a D&O Severity Problem