The risks of artificial intelligence in business and how to control them

The real risks of using artificial intelligence in a company, with documented cases from Colombia and elsewhere, what regulation says, and how to control them.

Julian Martínez Arenas·Last updated: September 23, 2026

Key Takeaways

  • The most common AI risk in a company isn't a sophisticated attack, it's an error nobody reviewed. Nearly one-third of McKinsey's respondents reported consequences from inaccurate AI output (The State of AI, November 2025).
  • 51% of respondents from organizations using AI say their organization has already experienced at least one negative consequence (McKinsey, 2025).
  • The company is liable for what its AI says. In 2024 a Canadian tribunal ordered Air Canada to compensate a passenger for wrong information its chatbot gave, and rejected the argument that the chatbot was responsible for itself.
  • Colombia already has case law: the Constitutional Court set criteria for judges' use of AI in ruling T-323 of 2024, and the Supreme Court fined a lawyer for submitting nonexistent citations generated with AI.
  • Risks are controlled with human review proportional to the cost of an error, not with bans. Where an error is costly, a person reviews. Where it isn't, AI works alone.

Almost every conversation about the risks of artificial intelligence ends up at one of two extremes: either AI will destroy jobs and companies, or nothing will happen and you should adopt it now. Neither helps the manager of a mid-sized company.

The real risks of AI in a company are more concrete and easier to control than they seem. This guide sorts them by what actually happens to companies, with documented cases, and explains which control works for each one. It's part of our guide to artificial intelligence for businesses.

What are the risks of AI in a company?

The risks of AI in a company fall into six groups: errors that look true, legal liability for what AI says, information leaks, breaches of personal data rules, new attacks against AI systems, and costs or vendor dependency. They don't weigh the same for every company.

Risk What it looks like in practice Main control
Errors that look true A report with an invented figure reaches a customer Human review before anything leaves the company
Liability for what AI says The chatbot promises a discount that doesn't exist Limit what it can claim and review its answers
Information leaks Someone uploads the customer database to a personal account Use policy and an approved corporate tool
Personal data and regulation A system is trained on or fed data without authorization Impact assessment and data subjects' authorization
Attacks against AI An email with hidden instructions manipulates an agent Minimum permissions and human approval for sensitive actions
Costs and dependency The usage bill triples or the vendor changes terms Measure consumption and avoid locking into one vendor

McKinsey's The State of AI 2025 survey shows which comes first: 51% of respondents from organizations using AI say they've experienced at least one negative consequence, and nearly one-third of all respondents report consequences from inaccuracy.

What happens when AI is confidently wrong?

When AI is wrong, it's wrong in the same confident tone as when it's right, and that's the risk. Language models generate the most probable text, not the true one. Colombia's Constitutional Court summed it up in ruling T-323 of 2024: the most probable next word isn't always the most correct or factually true one.

The best-known case is Mata v. Avianca. In 2023, in a lawsuit against the airline in New York, the plaintiff's lawyers submitted court opinions that didn't exist, with citations invented by ChatGPT, and kept standing by them when the court asked. The judge fined them USD 5,000 and left a line useful to any company: there's nothing inherently improper about using a reliable AI tool, the problem is not verifying what it produces.

Colombia has its own version. The Civil Chamber of the Supreme Court of Justice, in order AC739-2026, fined a lawyer 15 monthly minimum wages for filing an appeal with ten nonexistent case citations generated with AI, and described verifying sources as a duty that can't be delegated.

In a company, the equivalent is a proposal with an invented market figure, a contract summary with a clause that doesn't exist, or a financial report with a miscalculation. The control is the same in every case: a named person reviews what leaves the company.

Is a company liable for what its AI says?

Yes. What a chatbot, an agent, or an AI-generated document says on the company's behalf commits the company. In Moffatt v. Air Canada, a British Columbia tribunal ruled in 2024 on a claim by a passenger whose bereavement fare policy had been misexplained by the airline's chatbot. Air Canada argued the chatbot was a separate legal entity responsible for its own actions. The tribunal called that a "remarkable submission" and concluded the company is responsible for all the information on its website, whether it comes from a static page or a chatbot.

The compensation was small, about CAD 800, but the precedent isn't. If your company puts an AI assistant in front of customers, what that assistant promises is the company's promise.

The practical control is to limit what the system can claim, connect it only to official, up-to-date information, and review a sample of its answers every week. When a topic has financial or legal consequences, like prices, warranties, or refunds, it's best for the system to hand off to a person.

How does company information leak through AI?

Information leaks mainly through shadow AI: employees using personal tools with company information because nobody gave them an alternative. IBM's Cost of a Data Breach Report 2026 found that security incidents involving shadow AI rose from 20% to 43% in one year, in a sample of 602 organizations that suffered a breach.

This risk isn't controlled by banning, but with a clear policy and an approved tool. We explain it step by step in AI acceptable use policy: how to control shadow AI.

What does regulation say about AI risks?

In Colombia there's no specific AI law as of September 2026, but personal data protection already applies. SIC External Circular 002 of 2024 requires, among other things, a privacy impact assessment before designing a high-risk AI system, and notes that data available on the internet isn't public just because it's there.

The SIC has already shown it acts. In October 2025 it ordered the immediate and permanent shutdown of World (Worldcoin)'s data processing in Colombia and the deletion of the iris codes it had collected, after concluding that consent to process sensitive data was conditioned on financial incentives. It isn't a generative AI case, but it shows how the authority looks at technology that uses personal data.

If your company sells to Europe, the EU AI Act also applies, since it covers providers from other countries when their system's output is used in the Union. Most of its general rules apply from August 2, 2026, and with the amendment adopted in 2026, obligations for high-risk systems, like those that evaluate staff or credit, were postponed to December 2027. This section is general guidance, not legal advice.

What new risks do AI agents bring?

Agents bring a risk an assistant doesn't have: they can act. If an agent reads emails and can send replies, an email with hidden instructions can try to make it do something nobody authorized. That attack is called prompt injection, and it's the first risk on the 2025 OWASP Top 10 for LLM Applications. The same list includes "excessive agency," which is giving a system more permissions than it needs.

The control is to give the agent the minimum permissions for its task and require human approval for anything that changes information or leaves the company. We cover it in what an AI agent is and what it's for.

How do you control AI risks without slowing adoption?

You control risks by matching human review to the cost of an error. It makes no sense to review every internal summary AI prepares, and it does make sense to review every figure that goes into a proposal to a customer. This matrix helps decide:

Cheap error Costly error
Internal use AI works alone. Example: summarizing minutes for the team Sample review. Example: analysis feeding a purchasing decision
Leaves the company Quick review before sending. Example: answering a frequently asked question Full review by an owner. Example: proposal, contract, or reply to an authority

To organize the deeper work there are reference frameworks like the NIST AI Risk Management Framework, intended for voluntary use, which organizes management into four functions: govern, map, measure, and manage. A mid-sized company doesn't need to implement all of it, but its logic helps: know which AI systems are used, where each one can fail, how you'll notice, and who is accountable.

Real case: how we control the risk of error in our research agent

At Suricata Labs we use our own AI agent that researches companies. We give it a company's name or website, and in 5 to 10 minutes it delivers a report on its sector, products, and competitors, work that used to take a junior consultant about 10 hours.

That agent's risk is the first row of the risk table, an error that looks true: it can confuse one company with another of the same name, assign the wrong competitor, or present outdated data as current. That's why the report doesn't leave the company or drive a decision on its own. It's the team's first input, and a consultant reads it, checks what matters, and digs deeper where needed before using it.

The control doesn't take away the agent's value. Reviewing a report takes a fraction of the time it took to write it, and verification stays with someone who knows the context. It's the same principle the Supreme Court required of the lawyer: the tool can do the work, but verification can't be delegated.

In the AI training programs we run, like the one for 117 advisors in El Salvador, each advisor worked on a real company, and learning to review what AI produces was part of the work, not a separate module.

Frequently asked questions about AI risks in business

What is the biggest AI risk for a mid-sized company?

The biggest risk for a mid-sized company is an AI error reaching a customer or a decision without anyone reviewing it. It's the most frequent according to McKinsey and the easiest to control: define what a person must review before it leaves the company.

Is a company responsible for its chatbot's or AI's mistakes?

Yes, in general the company is liable for what its AI tells customers and third parties. Moffatt v. Air Canada from 2024 is the most cited precedent: the tribunal rejected the idea that the chatbot was a separate entity and held the airline responsible for the information it gave. This answer is general guidance, not legal advice.

Which law regulates artificial intelligence in Colombia?

As of September 2026, Colombia has no specific AI law. Law 1581 of 2012 on personal data protection applies, along with SIC External Circular 002 of 2024, which applies it to AI systems. CONPES 4144 of 2025 sets the national AI policy but doesn't bind companies, and a new bill is making its way through Congress.

What is an AI hallucination?

A hallucination is an AI answer that sounds true but is false, like an invented figure, citation, or fact. It happens because language models generate the most probable text, not verified text. It's controlled by asking for sources, connecting AI to the company's official information, and reviewing anything that will be used to decide or sent to third parties.

Where do I start managing AI risks in my company?

Start by finding out which AI tools your team uses today and with what information, because most risks come from uses nobody knows about. Then define a short use policy and the points where a person must review before anything leaves the company. That covers most of the risk without slowing adoption.

The biggest risk is not knowing how AI is being used

A company that knows which AI tools its team uses, with what information, and who reviews what goes out has already controlled most of the risks. The cases that end up in courts and fines almost always have one thing in common: nobody verified what the AI produced before using it.

If you want to review how AI is being used in your company and where controls make sense, at Suricata Labs we do it with your team, along with the use policy and the first processes where it's worth applying.

Explore our AI services | Schedule a conversation

Read also: AI acceptable use policy: how to control shadow AI

Last updated: September 23, 2026

About the author

Julian Martínez Arenas

Julian Martínez Arenas

CEO of Suricata Labs | Business Growth Consultant & AI Strategy

CEO of Suricata Labs, consultant in business growth strategies and Artificial Intelligence implementation to empower businesses.