top of page

Who carries the AI risk?

May 6
2 min read

Updated: Aug 15

For my third post on AI governance and ethics, I want to move the conversation slightly higher up the chain. Not to the organisations deploying AI directly, but to those investing in them, insuring them or representing them legally.


I’m increasingly hearing that PE firms, insurers and legal practices are starting to consider the downstream risks associated with uncontrolled or unethical AI adoption within their portfolio companies or client base. While concern hasn’t yet reached the point of direct action, that may quickly change as businesses become increasingly impacted by unexpected AI related events.


As a certified CISO, I’m very familiar with the reality that cyber risk often sits somewhere within the supply chain. You may have your own house in order, but it only takes one critical supplier to suffer a cyber attack for your business to be directly impacted. Third party risk management (TPRM) providers exist to help organisations assess supplier security posture and identify areas of exposure.


Putting my AI Ethicist and Auditor hat on, I believe a similar situation is now emerging in the world of AI. TPRM solutions don’t yet meaningfully extend into AI governance, ethics and control, which is where specialists in this space – like me - can help organisations better understand and manage the associated risks.


As I mentioned in an earlier post, I propose that AI risk should be owned by the business leadership. It can directly impact brand reputation, regulatory exposure, contractual liability, litigation risk, insurability and corporate valuation.


A few examples:

  • AI generated customer communications create misleading or discriminatory outcomes, damaging brand reputation.

  • Sensitive or personal data is exposed through uncontrolled use of consumer AI tools.

  • AI generated content or recommendations breach contractual or professional obligations.


The AI conversation is still dominated by productivity, efficiency and innovation. And rightly so, because the opportunities are enormous. But I’m not convinced enough attention is yet being paid to governance, accountability, auditability and ethical deployment, particularly in environments where trust, regulation, reputation and due diligence matter.


I think we’re moving towards a point where organisations will increasingly need to demonstrate not just that they’re using AI, but that they’re using it responsibly. Some important questions include:

  • Can they clearly explain how AI is being used?

  • Can they evidence appropriate control?

  • Can they explain decisions influenced by AI?

  • Can they demonstrate effective governance?

  • Can they demonstrate that risks are understood and being actively managed?


I suspect those questions will become far more common and, in the rapidly evolving world of AI, perhaps within months rather than years. The time to act is now.  Happy to engage.


 
 
 

Recent Posts

See All
AI is changing the economics of cyber extortion

Much of the discussion around AI and cyber-crime has focused on how it enables attackers write malware, create more convincing phishing campaigns, or identify and exploit software vulnerabilities. My

 
 
 
The advantage might just be shifting

For quite some time, much of the discussion around AI and cybersecurity has focused on the risks. What happens when attackers use AI to find vulnerabilities faster? My previous post on Claude Mythos f

 
 
 
The rules just changed

Over the weekend, I listened to an interesting cyber security podcast (Steve Gibson’s ‘Security Now!’), discussing Anthropic’s new AI model “Mythos” and its ability to identify previously unknown soft

 
 
 

Comments


bottom of page