AI Is Coming for Your Pension Plan’s Weakest Link
By: Srikumar Bala, Educational Employees’ Supplementary Retirement System of Fairfax County (ERFC)
While artificial intelligence is rapidly becoming a critical piece of infrastructure for pension funds, the shift towards AI tools is exposing a new class of cybersecurity and fiduciary risks that trustees can no longer treat as a side issue.

Artificial intelligence is already embedded in pension operations. Chatbots handle member inquiries, AI models support actuarial forecasts and fraud detection, and security “copilots” assist internal teams. For many pension plans, AI is no longer experimental technology, it is becoming critical infrastructure.
That matters because AI changes the cybersecurity landscape in two ways at once: it expands the attack surface while also making attackers more capable. For trustees and plan sponsors, this creates direct implications for fiduciary duty, regulatory compliance, and member trust. Treating AI as a side issue risks discovering, during a breach or operational failure, that a mission-critical process was never properly governed.
In a pension context, AI errors can quickly become fiduciary failures. A chatbot hallucination in retail customer service may be inconvenient; a hallucinated eligibility decision or miscalculated retirement benefit is something else entirely. If an AI system incorrectly flags a beneficiary as ineligible, misroutes a payment, or understates liabilities, the pension plan — not the software vendor — remains accountable to members.
Regulators are already signaling that cybersecurity is part of prudent oversight. The U.S. Department of Labor’s Employee Benefits Security Administration (EBSA) has issued cybersecurity best practices covering governance, encryption, MFA, audits, and vendor oversight. Public-company sponsors and investment advisers also face SEC disclosure expectations, while GDPR and CCPA/CPRA impose privacy and breach-notification obligations. AI raises the bar further by introducing new operational and governance risks.
AI is also transforming social engineering into an industrial-scale threat. Pension funds are attractive targets because they combine large financial flows with highly sensitive personal data and complex vendor ecosystems. Attackers can now use AI to generate convincing spear-phishing emails, clone executive voices, and create synthetic video for fraud attempts. Recent incidents in the financial sector have already involved cloned voices authorizing wire transfers and synthetic identities bypassing authentication controls.
The pension-sector scenarios are easy to imagine: a benefits manager receives a convincing “urgent” call from a cloned executive requesting an off-cycle payment; a member-services representative hears a familiar voice requesting banking changes; or a trustee’s compromised personal email becomes the entry point for business email compromise.
The technical defenses are well understood but inconsistently implemented. Pension plans should prioritize phishing-resistant MFA such as FIDO2 keys or passkeys, strong email protection including DMARC, and mandatory out-of-band verification for changes to banking or beneficiary information. Just as important is training staff to recognize AI-enabled fraud attempts, including deep-fake audio and video. The biggest weakness is often not technology, but organizational priority.
Vendor risk is another growing concern. Pension plans depend heavily on record-keepers, custodians, actuarial firms, payroll providers, and SaaS platforms — many of which are rapidly embedding AI into their products. Plans often have limited visibility into how those AI systems process or retain sensitive data. A compromised AI plugin could quietly exfiltrate plan census data, while AI summarization tools may expose confidential board discussions if prompts are logged or reused for model training.
In the AI era, prudent vendor oversight must become AI-literate oversight. Trustees should expect clear answers from vendors about what AI models are being used, where data is processed, whether plan data is used for training, which subcontractors are involved, and what controls exist on termination. Contractual protections such as “no training on plan data,” rapid breach notification, and audit rights should become baseline expectations.
Trustees do not need to become AI engineers, but they do need sharper governance practices. Every plan should maintain a current inventory of AI use cases and include AI-specific risks directly in the cybersecurity risk register. Risks such as prompt injection, deepfake fraud, shadow AI usage by employees, and insecure vendor integrations should have clear owners and mitigation plans.
Most importantly, plans should test their preparedness. AI-era incident simulations — deepfake wire-fraud attempts, ransomware at a record-keeper, mass PII leakage through AI tools, or AI-driven benefit errors — should be practiced with legal, privacy, communications, and vendors involved.
The standard of prudence is changing. Pension plans that can demonstrate active AI governance, evolving controls, and tested response capabilities will be far better positioned when AI-enabled incidents inevitably hit the sector. The weakest link in an AI-enabled environment will ultimately be chosen by attackers. Trustees must decide now how strong they want that link to be.
Srikumar Bala is a senior technology and operations executive with deep experience leading enterprise transformation, digital modernization, cybersecurity, data strategy, and product innovation across public sector, financial services, and global consulting environments. He brings a track record of aligning technology investment with business strategy, improving operational performance, and building resilient organizations that can scale through change. In his career, he has advanced multi-year technology roadmap, strengthened enterprise governance and cyber resilience, and driven measurable efficiency, cost, and service improvements through cloud, automation, and modern delivery practices.