AI Didn’t Create New Risks — It Exposed How Undisciplined Most Businesses Are

AI didn’t create new risks; it highlighted poor process and governance across the stack. Organisations that follow frameworks such as ISO 27001 or heed ICO guidance can close many of those gaps; one immediate action is to assign a single owner for each AI use case and measure it weekly.

Too often UK firms enable AI features faster than they formalise the controls around them. Access lists, template versions and approval gates that worked for older automation are left informal; when AI injects content or decisions into day-to-day work those informal habits quickly become repeatable mistakes.

The key takeaway is simple: treat AI as a visibility lens, not the origin of new threats. If processes and accountability were tight before, exposing them with AI would show strength; if they were loose, AI merely accelerates the consequences.

Action 1 — Lock ownership, rules and access

The first practical step is to stop treating AI as a feature and start treating it as a business process. That means naming a single accountable person for each AI use case — someone who owns access, approvals, and change records. This reduces ambiguity and makes audits straightforward.

Specifically, implement these three controls in the next 30 days:

  • Assign a named owner and a deputy for every AI-enabled workflow (billing, customer messaging, reporting).
  • Map who can read, edit and approve AI outputs; remove blanket edit rights and use role-based access.
  • Mandate version control for prompts, templates and integration code so you can roll back a change within one working day.

For data protection and accountability, follow existing guidance from the ICO on automated processing and decision-making; link your internal process owners to that guidance so compliance is not an afterthought. Where possible fold AI ownership into existing risk registers and the ISO 27001 control set you already use — it makes reporting to the board and insurers easier.

Action 2 — Assume AI outputs are drafts and measure them

Operationally, treat every AI-touched output as a draft until a named human approves it. In our experience, we run our own IT operations AI-augmented — from ticket triage to first-line diagnosis to knowledge-base authoring — but every AI-touched output goes through a human before it reaches the client. The gain is speed of first response, not the removal of the technician. That approach protects reputation and gives you measurable performance gains.

Set up a simple monitoring loop:

  1. Define acceptance criteria for each AI output (accuracy, tone, sensitive-field redaction).
  2. Sample output daily for the first month, then weekly once error rates stabilise.
  3. Log every human override and use that data to retrain prompts or tighten access.

Useful metrics to track include: time-to-first-response, percentage of outputs requiring edits, and number of human overrides per 100 requests. Start small — a single KPI owned by the process lead is better than a dashboard no one uses.

Practical guardrails you can adopt immediately:

  • Keep human-in-the-loop for any customer-facing message for at least 90 days after deployment.
  • Lock API keys and monitor their use rather than embedding them in shared documents.
  • Run a privacy review before introducing any AI that processes personal data; tie the decision to a named data controller.

These steps are not about blocking AI; they are about forcing an organisation to be disciplined. Once rules exist, you can safely increase automation and realise the promised efficiency gains without amplifying risk.

Related reading

FAQ

How quickly should I apply human review to AI outputs in customer service?

Apply human review immediately and keep it mandatory for at least the first 90 days after rollout; measure edits per 100 responses and aim to reduce that number before removing the human check.

What governance documents do I need to show to an insurer or auditor?

Insurers typically want to see named owners for AI use cases, an access-control map, change logs for prompts/templates, and an incident response route — one consolidated folder with these documents is sufficient.

Can I rely on vendor controls alone to manage AI risk?

No. Vendor controls help, but you remain responsible for outputs and data handling; ensure vendor SLAs include breach notification timelines and allow you to audit prompt use.

How long should a pilot run before wider rollout?

Run a pilot for at least two weeks and through a minimum of 100 real instances, or until your chosen error metric stabilises for five consecutive working days.