The Biggest AI Risk May Be Neither Using It nor Banning It

22 September 2026

Artificial intelligence is creating a new type of corporate accountability problem. Employees can expose their organisations by sending confidential information into unapproved AI systems, relying on fabricated answers or allowing autonomous software to act beyond its authority. But companies can create another risk by responding with policies so restrictive that employees simply move their AI use outside approved systems. That tension was at the centre of a presentation at Ai4 2026 in Las Vegas by Rob T. Lee of the SANS Institute, who used a series of high-profile failures to illustrate how quickly routine AI use can turn into a professional, legal or corporate problem. Behind the deliberately provocative theme of ways AI can get someone fired was a broader governance question: how can businesses permit employees to gain the productivity benefits of AI without losing control over information, accountability and automated actions?

The first problem is confidential information. Employees increasingly use generative AI to analyse documents, debug software, summarise material and answer questions, sometimes through personal accounts or services that have not been approved by their employer. Verizon’s 2026 research points to a sharp increase in unauthorised AI use on corporate devices, with source code among the information being submitted to external generative AI services. The issue is no longer simply whether employees understand an AI policy. Companies need to know whether the technology employees are actually using is visible to the organisation at all. A written prohibition does not necessarily stop AI use, particularly when an employee believes a public tool is more useful than the corporate alternative. The organisation can then end up with the worst of both worlds: AI is being used, but outside the security, contractual and monitoring environment management established for it.

The second risk is professional responsibility for AI-generated information. A striking example emerged in Nebraska, where lawyer Greg Lake submitted an appellate brief containing extensive problems with its legal references. Of 63 citations challenged by opposing counsel, 57 contained some form of defect, including references that could not be substantiated. Lake later acknowledged that AI had been involved and that he had failed to verify the resulting work adequately, and the Nebraska Supreme Court subsequently suspended him while disciplinary proceedings continued. The significance of the case extends well beyond the legal profession. AI may help employees conduct research and prepare drafts, but professional responsibility does not transfer to the model. A journalist remains responsible for an article, an analyst for an investment memorandum, an engineer for technical work and a consultant for recommendations delivered to a client. The fact that a machine generated a mistake does not remove the accountability attached to the person or organisation placing its name on the finished product.

This is becoming increasingly visible in courts, consulting and professional services. Judges in several jurisdictions have encountered invented cases, inaccurate quotations and other AI-generated material, while a Deloitte report produced for the Australian government was later corrected after problems were identified in its references and content. These examples illustrate why the commercial value of professional services cannot simply be the production of documents more quickly. As clients gain access to many of the same AI tools, the value of lawyers, consultants, analysts and advisers increasingly lies in verification, expertise, judgement and accountability. AI can accelerate research, but reliable professional work still requires authoritative sourcing and independent checking.

A third issue appears as AI shifts from producing information to taking action. The risks of a chatbot drafting an incorrect paragraph are materially different from those of an agent capable of altering software, interacting with databases or executing transactions. Public incidents involving autonomous coding tools have shown that instructions written into a prompt are not equivalent to technical access controls. Telling an AI agent not to enter a production environment offers much less protection than ensuring that the agent does not possess permission to make the change in the first place. That principle is fundamental to governance of agentic AI. Organisations need to separate what a system is asked to do from what it is technically authorised to do. Access rights, segregated environments, approval gates and human control over consequential actions therefore become more important as AI systems gain greater autonomy.

The Air Canada chatbot dispute provides a simpler illustration of the same accountability principle. A customer relied on incorrect information from the airline’s website chatbot concerning the retrospective availability of a bereavement fare. Air Canada argued that it should not be responsible for the chatbot’s inaccurate information, but a British Columbia tribunal rejected that position and held the airline liable for the representation made through its own website. The lesson was not that the chatbot had become an employee or independent legal actor. It was that a company remained responsible for a system it chose to place in front of customers. That principle is likely to become more significant as companies deploy AI agents capable not merely of answering questions but of negotiating, recommending products, approving requests or communicating commitments to customers and suppliers.

Regulation adds another layer. The EU AI Act entered an important new stage on 2 August 2026, when a range of provisions, including certain transparency requirements, became applicable. Some high-risk obligations now follow later implementation dates, but organisations operating in Europe cannot interpret that as a general postponement of AI compliance. Different requirements apply at different stages, and penalties for some infringements can be substantial. This makes accurate governance information particularly important because the rules surrounding AI are changing quickly. Companies operating internationally also face overlapping privacy, cybersecurity, sectoral and AI-specific obligations, making AI governance increasingly difficult to manage as a standalone policy exercise.

Lee also referred to the US Securities and Exchange Commission’s action against SolarWinds and its chief information security officer after the company’s major cybersecurity incident. Although that case was not an AI matter and the SEC action was ultimately dismissed with prejudice in November 2025, it remains relevant as an example of regulators being willing to investigate and name individual executives where they believe corporate disclosures or oversight were inadequate. For senior managers responsible for AI, the broader point is that documented decision-making matters. If an organisation establishes AI policies but does not provide employees with suitable tools, training, monitoring or realistic alternatives, responsibility for failure cannot always be reduced to an individual worker breaking the rules. Effective governance needs to show how policies are implemented and whether management created conditions in which compliance was practical.

This leads to perhaps the most difficult problem: organisations can be damaged by adopting too much AI, but they can also be damaged by adopting too little. Companies have already discovered that automation strategies can go too far when service quality or customer experience deteriorates. At the same time, organisations that prohibit useful technology while competitors automate successfully may face higher operating costs and slower decision-making. The challenge is therefore not to decide whether a company is for or against AI. It is to determine where AI creates sufficient value to justify deployment, what level of autonomy is appropriate and which controls should surround each use case.

This is why shadow AI is particularly important. Employees using their own AI applications are often doing so because they see immediate productivity value that formal corporate programmes have not yet delivered. Treating every instance simply as misconduct risks overlooking what that behaviour reveals about the organisation’s technology strategy. A better response may be to bring useful AI activity into an authorised environment by providing enterprise-grade tools, setting clear rules around what information may be uploaded, limiting access according to risk and creating channels through which employees can request additional capabilities. The objective should be to make approved AI easier and safer to use than unapproved AI.

For commercial real estate and investment businesses, these questions are already highly relevant. Employees can upload leases, investment memoranda, tenant information, financial models, development documents and transaction material into generative AI systems. Much of that information may be commercially sensitive, personally identifiable or subject to confidentiality restrictions. The risk increases as AI moves beyond document analysis into operational workflows. An investment agent might screen acquisitions, a leasing system could prepare tenant communications, a building-management agent could change equipment settings, while an automated finance system might interact with invoices or payment processes. Each step from recommendation towards execution increases the importance of access controls and clearly assigned accountability.

Companies therefore need to know not only which AI systems employees are using but what those systems can actually do. A model allowed to summarise a lease creates one type of exposure. An agent capable of changing contractual data, sending an external communication or initiating a transaction creates another. Governance needs to reflect those differences rather than imposing one generic rule across all AI use. The strongest lesson from the SANS presentation is consequently that AI governance cannot succeed through policies alone. Employees need tools and processes that allow them to work effectively within the boundaries management has established.

Responsible AI adoption is therefore a balance between control and accessibility. Businesses need to create enough friction to prevent dangerous behaviour without creating so much friction that employees bypass the system entirely. They also need to distinguish between using AI as an assistant and granting it authority to act. The emerging corporate risk is not simply that employees will use AI badly. It is that organisations will fail to design an environment in which employees can use it well.

Companies that achieve that balance may gain the productivity benefits of AI while maintaining accountability and protecting sensitive information. Those that do not could find themselves exposed from both directions: employees taking uncontrolled risks on one side and competitors moving faster on the other. The challenge is therefore not merely to prevent AI from causing mistakes, but to build governance that enables useful adoption without losing control.

Source: CIJ.World Research & Analysis Team

front page info
LATEST NEWS