Skip to content
in your cart View Cart
Cart Join Login
Events Blog
Contact
National Conference on Public Employee Retirement Systems Logo
  • Learn
    • Event Registration
    • Continuing Education
    • NCPERS University
      • Trustee Essentials Training
      • Fiduciary in Focus Workshop
      • Advanced Fiduciary Institute
    • NCPERS Conferences
      • Annual Conference & Exhibition
      • Fall Conference
      • Public Safety Conference
    • NCPERS Summits
      • Chief Officers Summit
      • Communications & Member Services Summit
      • Public Pension HR Summit
    • NCPERS Forums
      • Legislative Forum & Policy Day
      • Public Pension Funding Forum
    • NCPERS Webinars
  • Engage
    • In-Person Events
      • For Pension Plan Staff
      • For Pension Trustees
    • Pension Fund Roundtables
    • Advocacy
    • Get Involved
      • Exhibit Hall
      • Speaker Opportunities
      • Thought Leadership
      • Sponsorship
    • Careers & RFPs
  • Access Insights
    • Public Pension Data
      • Public Pension Compensation Survey
      • Public Retirement Systems Study
    • Research Reports
    • Publications & News
    • Toolkits & Resources
    • Pension Facts
  • Membership
    • Why Join?
    • Pension Fund Membership
    • Industry Stakeholder Membership
    • Service Provider Membership
      • Meet the CorPERS Members
    • Access Your Benefits
      • Discounted Services for Pension Funds
  • About NCPERS
    • Introducing NCPERS 2.0
    • Awards & Recognition
    • FAQ
    • Media Inquiries
    • Staff & Leadership
    • Contact NCPERS​
  • Contact
  • Join Login

AI Is Coming for Your Pension Plan’s Weakest Link

Date postedJuly 27, 2026
in PERSist, Technology,

By: Srikumar Bala, Educational Employees’ Supplementary Retirement System of Fairfax County (ERFC)

While artificial intelligence is rapidly becoming a critical piece of infrastructure for pension funds, the shift towards AI tools is exposing a new class of cybersecurity and fiduciary risks that trustees can no longer treat as a side issue.

Digital warning symbol representing artificial intelligence cybersecurity risks

Artificial intelligence is already embedded in pension operations. Chatbots handle member inquiries, AI models support actuarial forecasts and fraud detection, and security “copilots” assist internal teams. For many pension plans, AI is no longer experimental technology, it is becoming critical infrastructure.

That matters because AI changes the cybersecurity landscape in two ways at once: it expands the attack surface while also making attackers more capable. For trustees and plan sponsors, this creates direct implications for fiduciary duty, regulatory compliance, and member trust. Treating AI as a side issue risks discovering, during a breach or operational failure, that a mission-critical process was never properly governed.

In a pension context, AI errors can quickly become fiduciary failures. A chatbot hallucination in retail customer service may be inconvenient; a hallucinated eligibility decision or miscalculated retirement benefit is something else entirely. If an AI system incorrectly flags a beneficiary as ineligible, misroutes a payment, or understates liabilities, the pension plan — not the software vendor — remains accountable to members.

Regulators are already signaling that cybersecurity is part of prudent oversight. The U.S. Department of Labor’s Employee Benefits Security Administration (EBSA) has issued cybersecurity best practices covering governance, encryption, MFA, audits, and vendor oversight. Public-company sponsors and investment advisers also face SEC disclosure expectations, while GDPR and CCPA/CPRA impose privacy and breach-notification obligations. AI raises the bar further by introducing new operational and governance risks.

AI is also transforming social engineering into an industrial-scale threat. Pension funds are attractive targets because they combine large financial flows with highly sensitive personal data and complex vendor ecosystems. Attackers can now use AI to generate convincing spear-phishing emails, clone executive voices, and create synthetic video for fraud attempts. Recent incidents in the financial sector have already involved cloned voices authorizing wire transfers and synthetic identities bypassing authentication controls.

The pension-sector scenarios are easy to imagine: a benefits manager receives a convincing “urgent” call from a cloned executive requesting an off-cycle payment; a member-services representative hears a familiar voice requesting banking changes; or a trustee’s compromised personal email becomes the entry point for business email compromise.

The technical defenses are well understood but inconsistently implemented. Pension plans should prioritize phishing-resistant MFA such as FIDO2 keys or passkeys, strong email protection including DMARC, and mandatory out-of-band verification for changes to banking or beneficiary information. Just as important is training staff to recognize AI-enabled fraud attempts, including deep-fake audio and video. The biggest weakness is often not technology, but organizational priority.

Vendor risk is another growing concern. Pension plans depend heavily on record-keepers, custodians, actuarial firms, payroll providers, and SaaS platforms — many of which are rapidly embedding AI into their products. Plans often have limited visibility into how those AI systems process or retain sensitive data. A compromised AI plugin could quietly exfiltrate plan census data, while AI summarization tools may expose confidential board discussions if prompts are logged or reused for model training.

In the AI era, prudent vendor oversight must become AI-literate oversight. Trustees should expect clear answers from vendors about what AI models are being used, where data is processed, whether plan data is used for training, which subcontractors are involved, and what controls exist on termination. Contractual protections such as “no training on plan data,” rapid breach notification, and audit rights should become baseline expectations.

Trustees do not need to become AI engineers, but they do need sharper governance practices. Every plan should maintain a current inventory of AI use cases and include AI-specific risks directly in the cybersecurity risk register. Risks such as prompt injection, deepfake fraud, shadow AI usage by employees, and insecure vendor integrations should have clear owners and mitigation plans.

Most importantly, plans should test their preparedness. AI-era incident simulations — deepfake wire-fraud attempts, ransomware at a record-keeper, mass PII leakage through AI tools, or AI-driven benefit errors — should be practiced with legal, privacy, communications, and vendors involved.

The standard of prudence is changing. Pension plans that can demonstrate active AI governance, evolving controls, and tested response capabilities will be far better positioned when AI-enabled incidents inevitably hit the sector. The weakest link in an AI-enabled environment will ultimately be chosen by attackers. Trustees must decide now how strong they want that link to be.

Srikumar Bala is a senior technology and operations executive with deep experience leading enterprise transformation, digital modernization, cybersecurity, data strategy, and product innovation across public sector, financial services, and global consulting environments. He brings a track record of aligning technology investment with business strategy, improving operational performance, and building resilient organizations that can scale through change. In his career, he has advanced multi-year technology roadmap, strengthened enterprise governance and cyber resilience, and driven measurable efficiency, cost, and service improvements through cloud, automation, and modern delivery practices.

Pension Industry Careers: Job Listings, Hiring, and Retirement AnnouncementsDate postedJuly 23, 2026

Categories

  • Actuarial
  • Asset Management
  • Careers & RFPs
  • Events & Education
  • Governance
  • Legal
  • Member Services
  • News from NCPERS
  • PERSist
  • Policy
  • Press Releases
  • Public Pension Profiles
  • Research
  • Technology

Most Recent Posts

  • Pension Industry Careers: Job Listings, Hiring, and Retirement Announcements Date postedJuly 23, 2026Posted
  • Balancing Short-Term Risks and Long-Term Plans: Inside the 2026 Public Pension Funding Forum Date postedJuly 16, 2026Posted
  • Staying the Course in Uncertain Times: NCPERS Public Pension Funding Forum Date postedJuly 9, 2026Posted
  • The Hidden Risk in Portfolios: Why Today’s Market Concentration Deserves a Closer Look Date postedJuly 7, 2026Posted
  • Women in Pension Leadership: TMRS Executive Director on Building a Culture of Excellence Date postedJuly 2, 2026Posted

Stay in the know: Get NCPERS updates sent to your inbox

Sign Up Now

1201 New York Avenue Northwest Suite 850
Washington, District of Columbia 20005
United States

—

202.601.2445

View Event Calendar
Get Involved (Sponsor, Exhibit, Speak)
Continuing Education
Pension Fund Roundtables
Advocacy
Research Reports

—

About NCPERS

FAQ

Contact Us

Membership Information

Pension News

Media Inquiries

Novi AMS
Association Management Software

Copyright © 2026 - National Conference on Public Employee Retirement Systems. Legal

×

Membership & Account Access

Need To Create An Account?

If you are already a member, please set up and log in to your member account by clicking "Create an Account" below. This option is also for current individual members and staff of company members who need to login, but do not have a user account set up.

Once logged in, you can:

  • Update Your Profile
  • Register for Events
  • View & Pay Invoices

Create an Account

Applying for Membership?

We invite and encourage you to join! By working together, we can achieve our mission to maintain and enhance our industry as a whole.

Becoming a member offers access to a network of professionals, fostering valuable connections and collaboration opportunities. Additionally, it often provides resources, such as training programs or industry insights, enhancing members' professional development.

 

View Membership Information