ºìÌÒÊÓÆµ

Skip to content

Cognitive security: The project risk no one is registering

Added to your CPD log

View or edit this activity in your CPD log.

Go to My CPD
Only ºìÌÒÊÓÆµ members have access to CPD features Become a member Already added to CPD log

View or edit this activity in your CPD log.

Go to My CPD
Added to your Saved Content Go to my Saved Content
AI in project management

Most project risk registers include cyber threats, financial pressures and operational constraints. Very few include the risks to the quality of thinking and decision-making inside the governance process itself. That gap is increasingly costly.

Projects don’t usually fail because someone ran the wrong process, they fail because somebody made a poor judgement under pressure, discounted inconvenient evidence or deferred to confident voices when they should have challenged them. In the AI era, the tools designed to help are often making this worse.

We are adopting AI fast and understanding it slowly 

AI use in project management has nearly doubled in two years. ºìÌÒÊÓÆµâ€™s own research found that 70% of project professionals now say their organisation uses AI, up from just 36% in 2023. The investment picture matches the ambition. 

Yet the State of found that only half of projects are deemed successful. The primary barrier to effective AI adoption has shifted from resistance to change to lack of understanding. Most project professionals are using AI tools they have not been trained on, in governance environments that have not been updated to account for them. That combination creates specific and measurable risk.

Cognitive security has emerged as an interdisciplinary field at the intersection of security studies, psychology, information warfare, artificial intelligence and resilience research. At its core, it is concerned with protecting human judgement, decision-making and trust from manipulation, distortion and degradation through disinformation, influence operations, cognitive bias and AI-enabled harms. 

While the concept has primarily been explored in national security and defence settings, its relevance extends directly to project governance. Gardner S (2026) argues that cognitive security should be considered a fifth pillar of AI governance, alongside safety, legality, ethics and explainability, because the ultimate target of many AI-enabled risks is not the technology itself but the human decision-maker using it. 

Applied to project management, cognitive security means protecting the quality of human judgement from distortion, overconfidence, misinformation and over-reliance on flawed information. Projects are fundamentally decision-making environments. Every day, project professionals make judgements about risk, delivery confidence, stakeholder dynamics and resource allocation. Those judgements are made under conditions of pressure, uncertainty and information overload. ºìÌÒÊÓÆµ research on behavioural decision-making suggests that project decisions are shaped by three interrelated influences: cognitive limitations and bias, political dynamics, and the social processes through which teams construct meaning and reach consensus.

The biases that rarely make the risk register 

Bent Flyvbjerg’s analysis of over go over budget, over schedule or both. This is not bad luck. It is the consistent, replicated consequence of optimism bias: the tendency to underestimate risk and overestimate capability. The UK Government’s Green Book mandates adjustments for this bias in public project appraisal specifically because it is so pervasive. 

Confirmation bias causes project teams to weight evidence that supports existing assumptions and discount evidence that challenges them. Authority bias gives senior voices disproportionate weight in risk discussions. Sunk cost thinking keeps failing projects alive past the point of rational decision. Groupthink suppresses challenge in cohesive teams. None of these routinely appear on risk registers. All of them routinely cause project failures. 

Why AI makes this more urgent 

AI does not create cognitive bias. It amplifies it. When project professionals rely on AI tools for forecasting, risk assessment and performance reporting, those outputs carry an authority that equivalent human judgements do not. Research consistently shows that people trust algorithmic outputs more than human expert judgements, even when the algorithm is demonstrably less accurate. The confident presentation of an AI-generated number discourages exactly the challenge that good governance requires. 

AI systems are trained on historical data and optimised against measurable metrics. They reflect the biases embedded in the data and the design choices made by the people who built them. An AI reporting delivery confidence at 87% is not exercising judgement. The human receiving that number bears full professional responsibility for deciding what to do with it. Governance frameworks have not yet caught up with that responsibility. 

Practice checklist 

  • Name the cognitive risks: Add optimism bias, groupthink and automation bias to your risk register alongside technical and financial risks. Give them owners and mitigations. 
  • Record AI influence: Document when and where AI tools influenced governance decisions, and what human validation was applied before acting on the output. 
  • Audit your information sources: Ask regularly where the data in your governance reports comes from, what it cannot show and what assumptions are embedded in how it was produced. 
  • Protect challenge: Create conditions where questioning AI outputs and confident forecasts is professionally safe. Governance is only as good as the challenge inside it. 
  • Make one question standard: At every major decision point: what is this information not showing us? 

 

You may also be interested in:

0Ìý³¦´Ç³¾³¾±ð²Ô³Ù²õ

Join the conversation!

Log in to post a comment, or create an account if you don't have one already.