AI Risks: What Your Company Should Watch Out For

The question has been circulating for months in headlines, podcasts and hallway conversations: can artificial intelligence wipe us all out? MIT Technology Review devoted a live event with its subscribers to answering it, and its AI reporters —Will Douglas Heaven and Grace Huckins— later published the best audience questions along with their answers ("Could AI really kill us all? Your questions, answered", MIT Technology Review). It’s an interesting read, but if you run a private company you probably have a more down-to-earth question: amid all the existential debate, which AI risks actually affect my business next week? Let’s get to that.

The apocalyptic debate and the debate that concerns you

In the MIT Technology Review article the two journalists don’t entirely agree. Huckins admits that predictions from the most pessimistic camps about model capabilities have proved "uncomfortably accurate" in recent years, although she doesn’t take the worst-case scenario for granted. Heaven is more blunt: outside of science fiction, he says, there are no circumstances in which AI kills us all, and he warns of something important —catastrophism serves to cover up the real, present-day problems of the technology and of the companies building it.

That last sentence is the one that interests us. Because while human extinction is being debated, in a distribution, retail or construction SME much more mundane and much more expensive things are happening: an automated agent that executes an action nobody reviewed, a report generated with data nobody validated, a wrongly allocated invoice, an impeccable phishing email written with generative AI.

Both journalists do agree on one sensible point: you don’t have to believe in the apocalypse to recognise that this technology has already caused concrete harm. That is exactly the ground on which senior management can —and should— act.

The AI risks you really do see in a company

These are, in our experience supporting digitalisation projects, the AI risks a real company runs into when it moves from enthusiasm to implementation.

1. Agents with a lot of autonomy and little supervision

An AI agent doesn’t just answer questions: it executes multi-step tasks using tools. That’s where its value lies and that’s where the problem lies. As Heaven summarises, the balance between autonomy and control still isn’t resolved even in the big labs: much of an agent’s power lies in not having to micromanage it, but that requires trusting that it won’t go off the rails. Translated to your company: before letting an agent modify orders, issue credit notes or write to customers, define what it can do on its own, what requires human validation and what gets logged.

2. Hallucinations about messy data

A model can generate incorrect information that looks true. And if it’s fed data scattered across Excel, emails and three systems that don’t talk to each other, the result isn’t intelligence: it’s noise that’s well written. That’s why we insist so much on the boring part: without organised and governed data, AI doesn’t deliver.

3. Expanded cybersecurity

The article mentions cyberattacks carried out with the help of AI as a risk that is already present, not futuristic. For a medium-sized company this translates into more credible impersonations, better-written CEO fraud and automation on the attacker’s side. The response isn’t exotic: risk assessment, response plans and team training.

4. Opacity and dependency

Heaven and Huckins point out that the techniques for monitoring model behaviour are still fragile and that the manufacturers themselves self-regulate with an obvious conflict of interest. For you that means one very practical thing: demand traceability, know where your data is processed and be able to change providers without getting locked in.

"Alignment": the technical word behind the fear

One of the audience questions was about alignment: getting models to behave the way we want and not the way we don’t. Heaven explains it well: language models are not programmed like traditional software, where you can code fixed rules. The desired behaviour is induced during training, with rewards or with a kind of written "constitution". And even so the results are inconsistent: a model may act one way in one situation and a different way in a situation that seems almost identical to us.

The conclusion for your company: don’t delegate judgement to a system that isn’t predictable. Delegate well-defined tasks, with controlled context and with review. It’s the same logic you’d use to approve a purchasing workflow or a joint signature; nothing a good CFO wouldn’t understand right away.

Five practical decisions before your next AI project

  1. Start with a measurable use case. AI to reduce the time of a specific process, not "AI for the sake of having AI". If you don’t know which indicator should move, it isn’t a project yet.
  2. Organise the data before the model. Identifying which information is relevant and what quality it’s in is 80% of the work.
  3. Write a usage policy. Who can use which tool, with what data, and what is forbidden to upload. One page is enough to start with.
  4. Define human supervision. Which decisions need sign-off and who gives it.
  5. Log and review. If you can’t audit what the system did, you can’t improve it or defend it before a customer or an auditor.

How we approach it at Tisa

At Tisa we have been implementing management technology in private companies since 1987, and our approach to AI is the same as always: business first, tool second. Our AI advisory service works precisely on the fronts where AI risks are concentrated for an SME: identifying the relevant data sets, creating data governance protocols aligned with regulations, evaluating tools according to your real investment capacity, developing and executing a use case tailored to your business and training the team to use it with good judgement.

And since we are a Microsoft Partner and certified developers in Business Central and Power Platform, that work usually lands on a foundation you already know: your ERP, your reports and your processes, not a parallel platform nobody uses three months later.

Is AI going to kill us?

Probably not. But the fact that the answer is reassuring doesn’t mean there’s nothing to do: it means the effort should go into the AI risks that already exist —control, data, security and supervision— rather than into a movie script. The companies that organise their data today and test well-defined use cases will be the ones that in two years’ time can truly automate, with confidence and without nasty surprises.

Would you like a no-obligation assessment of where to start? Let’s talk: (+34) 971 305 885 · info@grupotisa.com · grupotisa.com. We’ll help you choose the first use case and get it up and running with guarantees.


Source of the debate discussed: "Could AI really kill us all? Your questions, answered", MIT Technology Review (Will Douglas Heaven and Grace Huckins).

Hablemos de tu proyecto

En TISA Internacional ayudamos a empresas como la tuya a sacar partido de la tecnologia. Cuentanos que necesitas.