Most AI risk conversations focus on the technology. The bigger risk sits in how it is deployed: what gets delegated, what gets tested, and who is accountable when it is wrong. Five risks worth taking seriously, and what using AI properly actually looks like this quarter.
Every few weeks brings another story of an AI system getting something badly wrong: a support bot inventing a refund policy, a hiring tool quietly filtering out the wrong candidates, a forecast built on numbers nobody thought to check. The instinct is to blame the technology. That is rarely where the fault lies. In almost every case we have looked at, the model did exactly what it was built to do. The risk sat in how the business chose to deploy it.
In practice, this is where our AI work comes in, and AI delivery is not magic. It is disciplined execution covers useful related ground on why leadership discipline, not the tool itself, decides whether an AI project is safe to ship.
The five risks worth taking seriously
Most AI risk is not exotic. It is a small number of familiar failure modes, repeated at speed.
- 1Treating a plausible answer as a correct one. A model that sounds confident is not the same as a model that is right, and plausible answers are the ones that survive a quick look.
- 2Letting the system make decisions nobody agreed it could make. Scope creeps quietly from drafting an answer to deciding one, long after anyone signed off on that change.
- 3Skipping the test that would have caught it. “It looks fine” is not a standard, and without one, faults surface with customers instead of in testing.
- 4No named owner once it is live. A system without an owner drifts, and nobody notices until something breaks in public.
- 5Feeding it data nobody trusts. A confident answer built on a report the business already knows is wrong is still wrong, just delivered faster.
None of these are model problems. They are the same operational risks that show up whenever a business hands a task to someone new, and they are managed the same way: with clear scope, a defined standard, and a named owner.
AI does not remove the need for judgement. It moves the judgement earlier, into the design of the system, and raises the cost of skipping it.
Using AI properly is mostly restraint
The businesses getting real value from AI are not the ones moving fastest. They are the ones being deliberate about where it is used and where it is not.
- Start with a use case that can tolerate being wrong occasionally, not one where a mistake reaches a customer or a regulator first.
- Decide in advance what “correct” looks like, and test against it before launch, not after.
- Put a human in the loop wherever the cost of a wrong answer is high, and be honest about when that human is actually reviewing versus rubber-stamping.
- Name an owner for the system before it goes live, not after the first complaint.
- Revisit it. A system that was safe at launch can drift as the data around it changes, so treat it like any other live system that needs monitoring, not a project that finishes at go-live.
Using AI properly is a leadership habit, not a policy document
A written AI policy helps, but it does not substitute for leaders actually asking these questions on every use case, every time. The organisations we see handling this well have made it a habit rather than a one-off exercise: a short, repeatable check run against every new AI use case before it ships, owned by someone senior enough to say no.
What we would do this quarter
Pick one AI system already live, or close to it, and check it against the five risks above with the person who owns it. If you cannot say, plainly, what happens when it is wrong and who is watching for that, that is the gap to close before you scale it further. Our Discovery Playbook sets out the questions we ask before building anything, and it is a reasonable place to start if you want a structured way to run that conversation.
AI is not risky by nature. It becomes risky the moment a business stops asking the questions it would ask of any other system making decisions on its behalf.
If any of this sounds familiar, talk to us about your data.
Related reading
- AI delivery is not magic. It is disciplined execution.
- Context is the bottleneck, not the model
- In the loop or on the loop: governing analytics that AI helped build
Shauna Duffy
Director of Professional Services
Part of the Hopton Analytics team, delivering governed analytics programmes for UK mid-market organisations.
