Skip to content

Briefing 3 of 8

AI Risk

What would an AI-related mistake actually cost your business, and would you find out before or after it happened?

A 15-Minute Executive Read

Prepared by 3rd Element Consulting, Mechanicsburg, Pennsylvania

Executive summary

"AI risk" is not one problem. It is several different categories of risk, each behaving differently, each requiring a different response from leadership. Treating all of it as one vague worry, or one line in a policy document, leaves real gaps that a determined regulator, a competitor's lawyer, or a bad month will eventually find.

This briefing breaks AI risk into the categories that actually matter for a business your size: what happens when regulated data or your own confidential information and intellectual property end up somewhere they shouldn't, what a confidently wrong answer costs when nobody catches it, what AI does to the skills and judgment of the people using it, what legal and contractual exposure looks like, and where AI quietly creates operational and security gaps that have nothing to do with the tool being bad and everything to do with how it's used.

None of this is a reason to avoid AI. It is the reason to make risk decisions on purpose, instead of discovering them after the fact.

Get this series delivered weekly instead.

Sign up for the Executive AI Briefing Series

What every executive should know

  1. 1. Sensitive information risk, by data type

    Briefing 2 introduced the idea that account type matters most once sensitive data is involved. Here is what that actually looks like broken out by data type, in plain numbers, because the consequences are not the same across the board.

    Health information: if a business mishandles patient health information, the government can fine it anywhere from about $145 to more than $73,000 for each separate violation. A breach involving thousands of patient records can be counted as thousands of separate violations, which is how a single incident turns into a fine in the millions. If someone did it on purpose, for personal gain or to cause harm, that becomes a criminal case, with fines up to $250,000 and up to 10 years in prison for the person responsible. This applies to any business that handles patient data, not just hospitals and clinics.

    Financial and payment data: if your business doesn't protect customer card information the way the card networks require, your bank or payment processor can charge you $5,000 to $100,000 every month until it's fixed, and the fee goes up the longer it takes. If an actual breach happens on top of that, you're typically charged an additional amount for every card number exposed, and in serious cases you can lose the ability to accept credit cards at all.

    Personally identifiable information (names, Social Security numbers, addresses, and similar personal data): every state requires you to notify people if their information was exposed, and most states can fine a business per person they failed to notify correctly. In California, for example, an affected person can personally sue for $100 to $750 each if their information wasn't properly protected. A breach affecting a few hundred customers can turn into tens of thousands of dollars in penalties on that basis alone, before legal fees, PR, or lost business are even counted.

    Attorney-client privileged or confidential legal material: the law only protects a client's confidential communications with their attorney as long as they stay confidential. Pasting that material into a public AI tool can break that protection permanently, meaning the information could later be used against the client in court. It also breaks the confidentiality promise most firms make in their client agreements, which can lead to a malpractice claim and the end of the client relationship.

    Government-controlled data on a federal contract: mishandling it can get your business banned from bidding on future government contracts, full stop. If it's treated as fraud against the government, the penalty is roughly $14,000 to $28,000 for every false claim or invoice involved, on top of paying back three times whatever the mistake cost the government. In the worst cases, it isn't just the company that pays. A specific person, the owner, the manager, whoever made the call, can be personally sued or criminally charged.

    Your own company's confidential information and intellectual property: trade secrets, pricing models, proprietary methods, product roadmaps, and strategic plans don't carry a dedicated law or a fine schedule the way health or financial data does, but they can be permanently exposed the moment they're pasted into a public AI tool, especially one whose terms allow the vendor to use submitted data to improve its models. There's no notification requirement for this one, and often no clear moment you'd even find out it happened.

    The pattern across every category is the same. The penalty is rarely about the AI tool itself. It's about what was already true regarding that data before AI ever entered the picture. AI just makes it dramatically easier for one employee, in one prompt, to move that data somewhere it was never allowed to go.

  2. 2. Accuracy and reliability risk

    Briefing 2 covered why AI can be confidently wrong: it has no internal signal for uncertainty, and a fabricated answer reads exactly like a correct one. The risk side of that is what happens when nobody catches it before it matters.

    • A confidently wrong figure in a client proposal or board deck, treated as fact because it was well written.
    • A summary that quietly drops a material condition, exception, or caveat, changing the meaning without changing the tone.
    • A calculation that looks right and is off, because AI is unreliable at precise math and rarely shows its work.
    • A decision made on AI output with no one checking it against a source the business actually trusts.
    • Each of these costs the same amount of leadership attention to prevent, a human review step, as it costs to clean up after the fact, usually far more, plus the damage to the relationship or reputation involved.
  3. 3. Workforce and capability risk

    This is the risk that builds quietly and shows up expensively, usually months after the decision that caused it. Briefing 2 raised the pattern of employees using AI to skip the work of learning something, not just the work of typing it. Left unmanaged, that pattern produces a workforce that looks productive on paper and cannot perform the underlying task without the tool. That gap is invisible until the tool is unavailable, the task gets harder than AI can handle, or someone has to explain a decision they didn't actually understand.

    Some employees go further than leaning on AI too much. They use it to actively misrepresent their own ability on work they're already responsible for, turning in a project, an analysis, or a report that is almost entirely AI-produced while presenting it as their own effort and expertise. This usually surfaces the same way: a manager asks one follow-up question the employee can't answer, because they didn't actually do or understand the work they turned in. That's not a skills gap anymore. It's a trust problem, and it's often harder to catch than a hiring mismatch, because the person is already on the team, already trusted, and already vouching for work they didn't really produce.

    The same risk shows up before someone is even hired. AI can make a resume, cover letter, or interview answer look considerably stronger than the candidate's actual ability, since the polish often comes from the tool rather than the person. That mismatch usually isn't visible in the hiring process. It surfaces months in, once the person has to perform without help, and by then the business has already spent a full hiring cycle, months of salary, and often a client relationship or two finding it out. For roles that require licensure, certification, or demonstrated technical competence, the exposure goes further than a bad hire. A skills gap that AI helped hide can turn into a compliance or liability problem the moment that person is relied on to do the thing they were hired to do and can't.

  4. 4. Legal and contractual risk

    • Confidentiality obligations: most client and vendor agreements already restrict how information can be shared. Pasting that information into a third-party AI tool is sharing it, whether or not anyone intended it that way.
    • Copyright and ownership: who owns content an AI tool generates, and whether that content infringes on someone else's copyrighted material, is still being tested in court. Treating AI output as automatically safe to publish or resell is a bet, not a fact.
    • Vendor terms of service: free and consumer-tier AI tools often include terms that let the vendor use submitted data to improve their models. Few employees read those terms before pasting in a document.
    • Disclosure and recordkeeping obligations: some industries require disclosing when AI was used in a decision, an analysis, or a client deliverable. Not knowing where AI touched a work product makes that disclosure impossible to make accurately.
  5. 5. Operational risk

    None of these require a security incident to cause damage. They cause damage simply by making the business more fragile and less able to explain how its own work actually gets done.

    • Shadow AI spreading faster than anyone tracks it, so leadership finds out about a tool after it's already embedded in a workflow, not before.
    • A single employee's personal AI account becoming a load-bearing part of a process, with no continuity plan if that person leaves.
    • Automations or AI-assisted workflows quietly making decisions outside the scope anyone originally approved.
    • Institutional knowledge thinning out as more of it lives inside someone's AI chat history instead of a shared, documented process.
  6. 6. Security risk

    This is the category most likely to already be on your IT team's radar. It rarely gets the leadership attention it deserves, because it looks like a technical problem instead of the business risk it actually is.

    • Malicious prompts and prompt injection, where AI tools connected to other systems can be manipulated into taking unintended actions.
    • Unreviewed AI browser extensions and apps with broad permissions to read email, documents, or calendars.
    • Compromised AI accounts, particularly personal accounts without multifactor authentication, becoming a new path into company data.
    • Vendor data retention: some AI tools retain submitted data indefinitely, which becomes exposure of its own if that vendor is ever breached.

Real business examples

Composite scenarios, illustrative, not specific to any one company.

The strategy deck that became someone else's training data

A specialty distributor's VP of sales used a free AI tool to help polish an internal memo covering next year's pricing model, target accounts, and margin targets, ahead of a leadership offsite. The free account's terms allowed the vendor to use submitted content to improve its models. No law was broken and nothing was stolen in any way a court would recognize. The company simply gave up exclusive control of its own pricing strategy, permanently, in exchange for a slightly better first draft.

The resume that looked stronger than the person

A growing company hired a mid-level analyst whose resume and interview answers were sharp and well articulated. Three months in, it became clear the polish had come almost entirely from AI-assisted prep, and the analyst could not perform the core analytical work the role required without leaning on AI to produce answers no one on the team could verify. The company had already spent a full hiring cycle and a quarter of salary before the gap surfaced.

The privileged document that wasn't anymore

An associate at a professional services firm pasted a client's confidential strategy memo into a public AI tool to get a faster summary ahead of a meeting. The firm's engagement agreement explicitly prohibited sharing client materials with third-party tools. The associate didn't think of a chatbot as a third party. The client's counsel did.

The one person holding the process together

At a 30-person distribution company, a single operations coordinator had built an entire reporting workflow around her personal AI account, prompts refined over months, shortcuts nobody else knew existed. When she left the company with two weeks' notice, the workflow left with her. It took the team six weeks to reconstruct something close to what she had built quietly, on her own account, the entire time.

Decision framework

Six questions that reveal where your real AI risk sits

  • If regulated data, or your own confidential information and IP, ended up in an AI tool tomorrow, would you find out from your own team, from a regulator, or from a competitor?
  • Is there a human review step between AI-generated analysis and any decision, proposal, or figure a client or board member will see?
  • Could any of your current employees perform their core job responsibilities without AI assistance, if the tool were unavailable for a week?
  • Has anyone reviewed what your AI vendors' terms of service actually say about how submitted data can be used or retained?
  • Does any single employee's personal AI account currently hold institutional knowledge your business would struggle to reconstruct without them?
  • Have your IT and security teams reviewed which AI tools, extensions, or integrations currently have access to company email, documents, or systems?

If you answered "no" or "not sure" to two or more of these questions, your business is carrying AI risk it hasn't measured yet.

Leadership discussion questions

  • Which category of AI risk, information, accuracy, workforce, legal, operational, or security, worries us the most right now, and why?
  • If something we'd typed into an AI tool ended up with a regulator, a competitor, or the press, what would it be, and how bad would that actually be?
  • Where might AI quietly become the floor under someone's performance rather than a boost to it?
  • Where does a single person's personal AI account currently carry more of our institutional knowledge than we're comfortable with?
  • Have we actually read the terms of service for the AI tools our teams use most, or are we assuming they're fine?
  • If we had to pick one AI risk to fix first, which one would save us from the worst outcome?

Action plan

This Week

  • Pick the one risk category from this briefing that keeps you up at night and ask your leadership team a direct question about it. Specificity beats a general audit right now.

This Month

  • Identify every process in your business that currently depends on one person's personal AI account, and start documenting it as a shared, business-owned process instead.
  • Have someone actually read the terms of service for the two or three AI tools your teams use most, and report back in plain language.

Next 90 Days

  • Continue with Briefing 4, AI Governance, to put guardrails around the risks identified here, and Briefing 6, Selecting AI Tools, to make sure any new tool you adopt is evaluated against this list before it's approved.

This is the third in an eight-part series designed to give your leadership team a shared, working understanding of AI, without turning your business into a training exercise.

Get this series delivered weekly instead.

Sign up for the Executive AI Briefing Series

Continue the series

Ready to talk through where your business stands? Schedule an IT Environment Review with 3rd Element Consulting.

Schedule an IT Environment Review

Next step

Get a clearer view of your IT environment.

Find out what is working, where the risks are, and what needs attention next.