From AI Agents to Cyber Risk: Four Technology Questions Public Pension Boards Should Ask
Artificial intelligence is moving quickly from an experimental tool to an everyday part of the workplace. At the same time, the technology is giving cybercriminals new ways to target organizations, employees and the people they serve.
Public retirement systems are not technology companies, but they depend on technology to maintain member records, calculate and pay benefits, protect personal and financial information, prepare board materials and work with outside service providers. That makes technology oversight a governance issue, not simply an information technology assignment.
The McKinsey Technology Trends Outlook 2025, written by Lareina Yee, Michael Chui, Roger Roberts and Sven Smit, examines 13 developing technologies. The authors measure factors including innovation, public interest, equity investment, organizational adoption and demand for workers with related skills.
The report was written for business leaders and reflects technology activity largely from 2024. It is not a pension administration guide or an investment recommendation. Still, its findings offer public pension trustees and administrators a useful starting point for discussing artificial intelligence, cybersecurity, vendor oversight and operational risk.
Here are four questions public retirement system boards may want to consider.
1. What pension system information may staff or vendors provide to artificial intelligence tools?
The report rates organizational adoption of artificial intelligence at 4 on a five-point scale, meaning adoption was expanding across organizations. It also cites separate McKinsey research indicating that 78% of surveyed organizations were using artificial intelligence in at least one business function. At the same time, only 1% of leaders considered their organizations fully mature in deploying the technology (page 18).
That gap matters. Using an artificial intelligence tool does not necessarily mean that an organization has policies governing its use.
Pension system employees could use artificial intelligence to help summarize lengthy documents, organize research, prepare first drafts of member communications or identify questions within a board packet. Those uses could save time, but they also raise questions about what happens to the information entered into the tool.
A system policy should make clear whether employees and contractors may enter member information, benefit records, legal advice, personnel information, nonpublic investment materials or other confidential records into an artificial intelligence platform. The policy should also address whether a provider may retain that information or use it to train its models.
The goal does not have to be a blanket prohibition. It should be a clear set of boundaries that staff, trustees and service providers can understand and follow.
2. Which artificial intelligence-assisted decisions require documented human review?
One of the report's fastest-growing trends is agentic artificial intelligence. Unlike a chatbot that answers a question, an artificial intelligence agent may plan and complete a series of steps, communicate with other systems and adjust its actions as it receives new information.
The technology could eventually perform more complicated administrative work, but McKinsey rates its current adoption at only 2 out of 5. Most organizations were still testing small prototypes rather than using agents broadly (pages 11-17). The report also discusses concerns involving erroneous decisions, unintended actions, data quality, cyberattacks and the continuing need for human oversight.
As the report puts it, "trust is increasingly the gatekeeper to adoption" (page 4).
A retirement system should identify which activities always require review and approval by a qualified person. Those could include benefit eligibility and calculations, financial transactions, legal or regulatory interpretations, investment recommendations and communications that could affect a member's rights.
Human review should also be meaningful. An employee should be able to confirm the sources used, question the result and document who approved the final action. If no one can explain how an important conclusion was reached, the technology should not be making that decision for the system.
3. How are recordkeepers, custodians, consultants and other providers protecting system data?
McKinsey reports that digital trust and cybersecurity technologies attracted $77.8 billion in equity investment during 2024. Job postings in the field increased by 7% from 2023 to 2024 (page 56). The report rates cybersecurity adoption at 4 out of 5, but it emphasizes that even well-developed security programs must continue to evolve.
That observation is especially relevant to public retirement systems because so much of their work depends on outside organizations. A system may have strong internal controls and still face exposure through a recordkeeper, custodian, payroll connection, consultant, investment manager, software company or subcontractor.
The report warns that reliance on third-party software can concentrate risks across multiple business processes. It also points to the need for greater transparency about the components used in software and the vulnerabilities they may contain.
Boards and administrators can ask providers which system data they access, where it is stored, whether subcontractors can access it, and whether it is used in artificial intelligence applications. Contracts can also address encryption, access controls, data retention limits, breach notification, incident response responsibilities, and the return or destruction of system information upon the relationship's end.
Cybersecurity language should not be treated as standard contract wording that never changes. It should be reviewed as technology, threats and the provider's services change.
4. Are cybersecurity plans keeping pace with artificial intelligence-enabled fraud and future encryption threats?
Artificial intelligence can help organizations detect unusual activity and respond to attacks more quickly. It can also help criminals create more convincing emails, documents, voices and identities.
The McKinsey report points to CrowdStrike data showing that voice-phishing attacks increased 442% during the six months from the first half of 2024 to the second half (page 59). Voice phishing uses a telephone call or recorded message to trick someone into releasing sensitive or financial information. Artificial intelligence-generated voices can make those attempts more believable.
Retirement systems should consider whether their procedures rely too heavily on a familiar voice, telephone number, email address or urgent request. Verification procedures for bank changes, benefit payments, wire instructions, passwords and access privileges should account for the possibility that a message may look or sound authentic without being genuine.
The report also discusses the longer-term threat that quantum computing could pose to encryption. McKinsey rates quantum technology at only 1 out of 5, meaning it remains largely unproven in a business setting. The timeline is uncertain, but the report cautions that advances could eventually threaten commonly used cryptographic protections (pages 63-68).
Public pension systems do not need to purchase quantum computers. They can, however, ask technology providers whether they know which encryption methods protect system data and whether they have a plan for moving to newer standards when necessary.
Roger Roberts, one of the report's authors, summarizes the larger issue well: "Trust is no longer a soft issue; it's a business-critical asset" (page 57).
Governance must keep pace
The value of the McKinsey Technology Trends Outlook 2025 for public pension leaders lies not in predicting which product a system should buy or which technology investment will perform best. Its value is in helping boards recognize where technology is changing responsibilities, risk and accountability.
Trustees do not have to become artificial intelligence developers or cybersecurity engineers. They do need to ask understandable questions, establish clear responsibilities, and ensure the system's policies and vendor agreements keep pace with evolving tools and threats.
Technology will continue to change quickly. The fiduciary principles guiding public retirement systems remain familiar: act prudently, protect system assets, oversee delegated responsibilities and keep the interests of members and beneficiaries at the center of every decision.
Source: Lareina Yee, Michael Chui, Roger Roberts and Sven Smit, McKinsey Technology Trends Outlook 2025, McKinsey Global Institute, July 2025. Page references correspond to the report's numbered pages.
Disclosure: The banner graphic accompanying this article is an artificial intelligence-generated illustration created using ChatGPT, a tool developed by OpenAI.
About the Author: Allen Jones is director of communications and event marketing for the Texas Association of Public Employee Retirement Systems (TEXPERS), where he leads editorial strategy, member communications, conference marketing and digital engagement initiatives serving Texas public employee retirement systems. He began his journalism career in 1998 and has worked in journalism and communications for more than 25 years. He has completed Vanderbilt University's Prompt Engineering for ChatGPT course and Writing.io's AI Course & Certification for Non-Profits and AI Course & Certification for Government programs.


