All briefings
AI Governance

AI risk in business terms: what the board needs to understand

By Marcin Pajdzik ·

Many of the risks AI brings are familiar. Inaccurate advice, leaked information, supplier failure and unfair treatment already fall within established risk management. AI changes how they arise. An error can repeat across thousands of interactions before anyone notices, a wrong answer can read as convincingly as a correct one, and it can be difficult to explain how a particular result was produced. For a board, the useful questions are how each risk would reach the business and what would show that it is under control.

Three questions for examining AI risk

Leadership can examine AI risk through three practical questions, covering what AI produces, what it can access or change, and what it depends on.

What AI produces. AI can give a confident answer that is wrong, or produce results that treat some groups of people less favourably than others. Where those results reach customers or inform decisions about people, the organisation answers for them. Air Canada learned this in February 2024, when a Canadian tribunal held it liable for incorrect advice about bereavement fares that its website chatbot had given a customer. Leadership should know where AI output reaches customers or affects decisions about people, and how its accuracy and fairness are checked before and after launch.

What AI can access or change. AI works with the information it is given and the systems it can reach. Staff may enter confidential material into public AI services, and generated content may draw on material the organisation has no right to use. Where AI is connected to other systems, it may be able to change records, send communications or initiate transactions, and the same access allows it to cause damage. SaaStr, a business community, discovered this in July 2025 when Replit's AI coding agent deleted its live database despite an instruction to make no changes. Carefully worded instructions can also manipulate AI into revealing information or acting outside its intended limits. Leadership should know which information AI services can access, what they are permitted to change or initiate, which services staff may use, and how misuse would be detected.

What AI depends on. A business that uses a supplier's AI service depends on it staying available, affordable and supported. The supplier can also change or withdraw a model the business relies on. When a faulty internal change disrupted OpenAI's services for about four hours in December 2024, businesses that had built those services into their own products may have been unable to provide the affected features for much of that time unless they had an alternative in place. Leadership should know which business processes depend on AI services, how they would continue during an outage, and whether the organisation has the skills to run and change what it depends on.

How the consequences land

AI failures can interrupt services, create financial loss, expose confidential information or harm customers and employees. Legal action, regulatory consequences and loss of trust can follow.

Where a business process depends on an AI service, an outage or a faulty change can stop that process, and the organisation needs a way to continue, whether by reverting to a manual procedure, switching to an alternative service or accepting a defined delay. Data protection, consumer protection and equality law already apply to AI use, sector rules add their own duties, and AI-specific regulation adds further obligations in some jurisdictions. Organisational decisions shape all of these consequences, including where AI is used, how much authority it is given and how quickly problems are escalated.

Setting the organisation's appetite

The board approves the organisation's appetite for AI risk and the boundaries within which management may authorise its use. Legal requirements remain mandatory.

Each proposed use should be assessed on what it actually does, the data it uses and the consequences of an error. The assessment considers the effect on customers and employees, whether a decision is regulated, the sensitivity of the information, how easily a mistake can be reversed, the scale of use, how much the AI can do without a person's involvement, how likely harm is, and how effective the controls are. The result sets the controls a use needs, which may include human review, limits on what the AI can access or change, or a decision not to proceed.

For example, management might allow internal drafting with approved data, require review before contractual commitments are communicated, and prohibit autonomous changes to payment instructions.

What the board should see

The board should receive a consolidated view of significant AI risks and incidents, the uses with the highest potential consequences, and decisions that require its attention, such as a proposed use outside the agreed appetite. Reporting should show whether controls keep material risks within agreed limits, where testing or incidents reveal weaknesses, and who owns corrective action. Where the organisation accepts a material risk, the record should show who accepted it, on what evidence and when it will be reviewed. Management maintains the detailed register of AI use and the controls applied to each.

Questions for the board

  • Where does AI output reach customers or influence decisions about people, and how is it checked?
  • What can our AI services access or change, and which services are staff permitted to use?
  • How would we know if an AI service had been manipulated or was producing harmful results?
  • Which business processes depend on AI suppliers, and how would they continue during an outage?
  • Have we agreed the boundaries within which management may authorise AI use?
  • Do our controls keep material AI risks within agreed limits, and what shows it?
  • Who is accountable for AI risk, and how does it reach the board?

Scaling AI safely describes the operating model that brings these risks under common governance. An AI Readiness and Governance Review establishes where AI is already in use across your organisation, which of these risks apply and what to address first. AI Factory Design and Transformation designs the operating model that keeps them within the agreed appetite as AI use grows.

References

  • British Columbia Civil Resolution Tribunal, Moffatt v. Air Canada, 2024 BCCRT 149, 14 February 2024.
  • The Register, Vibe coding service Replit deleted user's production database, faked data, told fibs galore, 21 July 2025.
  • OpenAI, API, ChatGPT and Sora facing issues, incident report, December 2024.
  • National Institute of Standards and Technology, Artificial Intelligence Risk Management Framework (AI RMF 1.0), January 2023.
  • National Institute of Standards and Technology, AI 600-1, Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile, July 2024.
  • ISO/IEC 23894:2023, Information technology, Artificial intelligence, Guidance on risk management.
  • ISO/IEC 42001:2023, Information technology, Artificial intelligence, Management system.
Start the conversation

Facing this in your organisation?

Talk to us

We use analytics cookies to understand how this site is used. See our Privacy Notice for details. You can change your choice at any time.