Most mid-sized businesses don't have a dedicated AI risk team, and they don't need one to use AI responsibly. What they need is a clear picture of the main risks, a handful of practical controls and a sense of when to bring in legal or compliance help. This article covers the basics. It's general information, not legal advice; for decisions specific to your business, involve qualified counsel.
The main risks, in plain terms
Accuracy
AI language models can produce fluent, confident answers that are wrong. This is often called hallucination. The risk grows when AI output reaches customers, affects decisions or goes into official records without review. It's the most common AI risk and the easiest to manage with good process design.
Data privacy and confidentiality
Entering customer information, employee records, health data or confidential client material into an AI tool may breach privacy laws, contracts or professional duties if the tool's data handling isn't appropriate. Employees using personal AI accounts for work is a common source of this risk.
Security
AI systems introduce new security issues alongside the familiar ones. Prompt injection, where malicious instructions hidden in an email, document or web page trick an AI into doing something it shouldn't, is a leading example. AI tools that can take actions, such as sending messages or updating records, deserve extra care. The OWASP Top 10 for LLM Applications is a good free overview of these risks.1
Bias and fairness
AI systems can reflect biases in the data they were trained on. This matters most when AI influences decisions about people, such as hiring, lending, housing, insurance or access to services, where anti-discrimination laws apply regardless of whether a person or a system made the decision.
Regulatory and legal risk
Existing laws apply to AI use even when they don't mention AI. Consumer protection, privacy, anti-discrimination, telemarketing and industry-specific rules all still apply. Some states have also passed AI-specific laws, and requirements and effective dates are changing, so check the current position with counsel if you use AI in decisions about people.
Vendor risk
When you rely on an AI vendor, their data practices, security and reliability become your risk. Vendors may also depend on other AI providers, adding layers you can't see directly.
Claims risk
If you market your own products or services as AI-powered, your claims need to be truthful and supportable. Consumer protection law applies to claims about AI just as it does to any other advertising claim.
Practical controls that cover most of it
A small number of controls address the majority of these risks for a typical mid-sized business:
- A written AI use policy covering approved tools, data rules and human review. See how to write one.
- An inventory of AI use. Keep a simple list of which AI tools and automations are in use, what data they touch and who owns each one.
- Human review where it matters. Require a person to check AI output before it reaches customers, changes important records or affects decisions about people.
- Business-grade accounts and reviewed terms for any AI service that handles company data.
- Least-privilege access. Give AI tools and automations access only to the data and actions they need.
- Logging. Keep records of what automated systems did, so issues can be investigated.
- Testing before launch with real examples, including edge cases and attempts to misuse the system.
- A way to report and fix problems, including a blame-free process for reporting mistakes.
Match controls to risk level
Not every AI use needs the same scrutiny. A useful approach is to sort uses into tiers:
| Tier | Examples | Typical controls |
|---|---|---|
| Low | Drafting internal notes, brainstorming, summarizing public information | Approved tools, basic policy |
| Medium | Customer-facing drafts, document extraction, internal assistants on company data | Human review, data rules, logging, vendor review |
| High | Anything affecting decisions about people's credit, employment, housing, health or legal rights; automated outreach at scale | Legal review, testing for bias, strict oversight, documentation, regular audits |
For high-tier uses, involve counsel before launch. Some of these uses may be better avoided entirely until you have the expertise to manage them.
Industry rules still apply
If you operate in a regulated industry, the rules you already follow extend to AI. A few examples:
- Healthcare: Under HIPAA, a vendor that handles protected health information on your behalf is generally a business associate and needs a business associate agreement. HHS guidance explicitly gives a third-party AI chatbot on a patient portal as an example.2
- Financial services: Many non-bank financial institutions, including mortgage brokers and lenders, are covered by the FTC Safeguards Rule, which requires an information security program.3 AI vendors touching customer financial data belong in that program. See also our article on AI for mortgage teams.
- Legal: The American Bar Association's Formal Opinion 512 (July 2024) explains how lawyers' existing duties, including competence, confidentiality, communication and reasonable fees, apply to generative AI.4
- Telemarketing: The FCC ruled in February 2024 that AI-generated voices in calls count as "artificial" under the Telephone Consumer Protection Act, so consent rules for artificial or prerecorded voice calls apply.5
Use a free framework to organize your thinking
You don't need to invent your own approach. The NIST AI Risk Management Framework is a free, voluntary framework designed for organizations of any size.6 It organizes AI risk management into four functions: govern, map, measure and manage. NIST also publishes a Generative AI Profile that applies the framework to generative AI specifically.7 Neither needs to be adopted wholesale; many businesses use them as a checklist to make sure they haven't missed anything important.
Where to start this month
- List the AI tools your team uses today, including personal accounts used for work.
- Write or update a short AI use policy.
- Identify any AI use that touches decisions about people or regulated data, and review those first.
- Check the data terms of your main AI tools, and move work onto business accounts where needed.
- Decide who in your business owns AI risk, even if it's part of an existing role.
If you'd like help with any of this, it's built into our AI readiness assessment and fractional AI lead services. Book a free call to talk it through.
Sources
- OWASP Top 10 for Large Language Model Applications
- HHS: Business Associates guidance
- FTC: Safeguards Rule
- American Bar Association: Formal Opinion 512 on generative AI tools (July 29, 2024)
- FCC: AI-generated voices in robocalls ruled artificial under the TCPA (February 8, 2024)
- NIST AI Risk Management Framework
- NIST AI RMF: Generative Artificial Intelligence Profile