The days of information security and data privacy budgets expanding year-over-year have started to slow significantly. This, coinciding with the increased velocity of data privacy legislation and expansion of the use of artificial intelligence (AI), presents significant concerns for information security and data privacy groups. The average information security/data privacy budget is close to 10 percent of the overall IT budget, but what we are seeing is spending at the 2020 limits and not growing as you would expect. According to a study conducted by the Ponemon Institute, it was found that ‘83 percent of directors describe themselves as at least ‘moderately’ engaged with overseeing the risk of cyber attacks.’ This is very significant and does not align with the data on slowing security budgets. What is the disconnect? We can see several trends and potential reasons, but the feeling seems to get the most out of what you have and avoid the new ‘shiny’ toys. So, if 83 percent of the BoD cares about cybersecurity, and the SEC requires specific cybersecurity representation on the BoD, how do information security/data privacy groups manage this along with preparing for the explosion of data sets resulting from AI data models?