AI is moving rapidly from something businesses experimented with to something people are using as part of their everyday work.
Employees are using AI to draft documents, summarise information, analyse data, create content, conduct research and automate tasks.
In France, more than 35,000 companies have engaged with the Osez l’IA programme, with further support planned through 1,000 Diagnostics Data IA.
The opportunity is significant.
So are the risks.
And one of the biggest risks for businesses may not be AI itself.
It may be assuming that having an AI policy means the risk is managed.
It doesn’t.
A policy is only one part of a control framework. Effective AI governance requires businesses to understand how AI is actually being used, what information is being processed, who is responsible and whether the controls they have introduced are working in practice.
AI adoption creates new business risks
When a business introduces a new technology, it introduces new dependencies and new ways for things to go wrong.
AI is no different.
Some of the risks are relatively obvious.
There are questions around confidentiality, personal data, intellectual property, accuracy, bias and inappropriate use.
There are also less obvious operational questions.
What happens when employees become dependent on an AI tool?
What happens if an important service becomes unavailable?
What happens when AI-generated information is accepted without appropriate checking?
What happens when different teams adopt different tools without anyone having a complete picture of what is being used?
And what happens when the technology changes faster than the business’s policies and controls?
These aren’t purely technology questions.
They are business risk questions.
Start by understanding how AI is actually being used
Before deciding what controls you need, you need to understand what is happening.
This sounds obvious, but it can be surprisingly difficult.
AI adoption doesn’t necessarily happen through a formal technology project.
An employee discovers a useful tool.
Someone recommends it to a colleague.
A team starts using it.
Another team adopts something else.
Before long, AI has become part of the way work gets done without anyone having deliberately designed an AI operating model.
This is sometimes called shadow AI.
The first step therefore isn’t necessarily to ban it.
It is to understand it.
Ask:
- What AI tools are currently being used?
- Which teams are using them?
- What are they being used for?
- What information is being entered?
- Are any client, employee or commercially sensitive data involved?
- Which tools have been formally approved?
- Who approved them?
- Are there business processes that now depend on AI?
- What happens if those tools are unavailable?
You may find that your business already has considerably more AI exposure than you realised.
An AI policy is useful, but it isn’t enough
An AI policy can provide important boundaries.
It might explain:
- which tools are approved
- what information can be entered
- what information must not be entered
- how AI-generated content should be checked
- when human review is required
- who is responsible for different decisions
- how incidents should be reported
All of these are useful.
But the existence of the policy doesn’t demonstrate that the risk is controlled.
That requires evidence.
Consider a simple rule:
Employees must only use approved AI tools.
How do you know that happens?
If your answer is “because the policy says so”, you have identified a policy, not demonstrated a control.
A stronger control environment might include an approved tools list, appropriate technical restrictions, employee training, monitoring, clear reporting routes and periodic reviews.
The exact controls will depend on the business and the risk involved.
The important point is that they need to be connected to the actual risk.
Ask whether your controls work
This is a fundamental risk management principle and one that applies well beyond AI.
A control that has never been tested is an assumption.
For example, a business might have a process requiring employees to report an AI-related data incident immediately.
But have employees been shown how to report one?
Do they know who to contact?
Would the responsible person know what to do when the report arrives?
Could the business identify what information had been disclosed?
Could it assess the potential impact?
Could it respond quickly enough?
These are assurance questions.
They move the conversation from:
“Do we have a process?”
to:
“Would the process work when we actually needed it?”
That distinction is central to effective risk management.
AI governance needs clear ownership
AI frequently crosses organisational boundaries.
IT may manage systems.
Legal may advise on data protection and contractual issues.
HR may be responsible for training.
Individual teams may choose tools.
Senior leaders may be making decisions about productivity, investment and business strategy.
Without clear ownership, gaps can appear between all of these responsibilities.
Someone needs to have a clear view of the overall picture.
That doesn’t mean one person needs to become responsible for every aspect of AI.
It means the business should be able to answer straightforward questions such as:
- Who approves AI tools?
- Who sets the rules?
- Who monitors compliance?
- Who provides training?
- Who investigates incidents?
- Who decides whether a particular use of AI is acceptable?
- Who reports significant AI risks to senior leadership?
If nobody knows, the governance framework has a gap.
Don’t forget resilience
AI governance is often discussed in terms of data protection, ethics and compliance.
Those are important.
But there is another question:
What happens if the AI service you rely on isn’t available?
This is where AI governance starts to overlap with operational resilience.
Many businesses increasingly depend on cloud-based technology.
Behind those services sit data centres and infrastructure that depend on electricity, cooling, telecommunications and other critical services.
A disruption somewhere in that chain can eventually become a business problem.
For a business that relies on cloud systems to communicate with customers, manage records, process transactions or deliver services, the question isn’t simply whether the technology provider has a continuity plan.
You also need to understand your own dependency.
What stops if the service is unavailable?
How long could you operate?
What could you do manually?
What information would you still have access to?
Which customers would be affected?
Who makes the decision to activate contingency arrangements?
These are operational resilience questions.
Use risk management principles rather than creating another silo
One of the mistakes businesses can make is treating every emerging technology as requiring an entirely new management discipline.
AI certainly creates new risks.
But many of the questions are familiar.
The TRAPS approach in Strategic Risk starts with five stages:
Targets
What are you trying to achieve and what are you protecting?
Risks
What could prevent those objectives being achieved?
Analyse
What controls do you have and how effective are they?
Prioritise
Which gaps need attention first?
Systemise
How do you embed what you’ve learned into the way the business operates?
That approach works for AI risk because it starts with the business rather than the technology.
The question isn’t simply “What could AI do wrong?”
It’s:
“What does our business depend on, how is AI changing those dependencies, and what do we need to do about it?”
A practical AI risk review
If you’re not sure where to start, you could carry out a simple review using six questions.
1. What AI are we using?
Create an inventory of the tools and services currently being used.
Don’t rely solely on what has been formally approved.
Ask teams what they actually use.
2. What are we using it for?
Some uses may be low risk.
Others could involve confidential information, client data, financial decisions or important business processes.
The purpose matters.
3. What information goes into it?
Identify the types of data being processed and consider whether there are restrictions around confidentiality, personal data or intellectual property.
4. What could go wrong?
Consider inaccurate outputs, inappropriate disclosure, security incidents, dependency, reputational damage, regulatory issues and business interruption.
5. What controls do we have?
Look at policies, training, approved tools, technical controls, human review, monitoring and incident response.
Then ask whether those controls actually work.
6. What would happen if something went wrong?
Make sure there is a clear route for reporting, investigating and responding to incidents.
And test the arrangements.
The goal isn’t to stop people using AI
For many businesses, the answer to AI risk isn’t to prevent employees using AI.
The technology can offer real benefits.
The challenge is to introduce enough structure that the business can use it without losing sight of the risks.
That means understanding what is happening.
Setting sensible boundaries.
Giving people the information and training they need.
Making ownership clear.
Testing important controls.
And revisiting the risks as the technology and the business change.
That is risk management.
It doesn’t require a giant AI governance department.
It requires the same thing good risk management has always required: knowing what matters, understanding what could affect it and having enough evidence to know whether your response is working.
AI may be changing quickly.
The underlying risk questions haven’t changed nearly as much.
Want to explore a practical approach to risk?
My book, Strategic Risk: The TRAPS Framework for Better Business Decisions, looks at how businesses can understand their critical objectives, identify risks, assess controls, prioritise action and build resilience into the way they operate.
Recent Comments