← All insights
· Filippo Pietrantonio

AI Strategy

AI Risk for Non-Technical Leaders: A Plain-English Guide

Most AI risk isn't the model going rogue — it's ungoverned access, unverified output, and nobody named as the owner. The four risks that actually matter at mid-market, and the five controls that cover them.

AI Risk for Non-Technical Leaders: A Plain-English Guide

The short answer

AI risk for most mid-market companies comes down to four things you can actually control: who can feed company data into which tools, whether a human verifies output before it reaches a customer, who owns each system by name, and what it costs. IBM's 2026 breach report found 92% of organizations hit by an AI-related breach had no access controls on their AI models (IBM, 2026). That's a permissions problem, not a technology problem.

Documented AI incidents jumped 55% in a single year — 362 in 2025, up from 233 in 2024, according to Stanford HAI's 2026 AI Index (Stanford HAI, 2026). Over the same period, 88% of organizations reported regularly using AI in at least one business function, while only 35% of boards reported integrated AI oversight.

If you're a COO or founder who just approved an AI rollout and can't tell whether you've taken on real exposure or just new software, that gap is the whole problem. You don't need to understand transformer architecture to manage it.

This is the plain-English version: what can actually go wrong, which risks matter at your size, and what a proportionate response looks like.

What are the real AI risks for a mid-market company?

Four categories cover almost everything that has actually gone wrong in production. Ranked by how often they bite mid-market companies, not by how dramatic they sound.

Data leakage through ungoverned tools. Someone pastes a customer list, a contract, or source code into a consumer chatbot. IBM found shadow AI incidents more than doubled in one research cycle, from 20% to 43% of breached organizations, and 68% of breached organizations had no policy governing AI use at all (IBM, 2026). This is the single most common exposure and the cheapest to fix. We cover the mechanics in how to roll out AI without leaking company data.

Wrong output reaching a customer. An AI system states something confidently and incorrectly, and the company is bound by it. Stanford's data shows concern about inaccuracy rose from 60% to 74% of respondents year over year — the sharpest increase of any risk category (Stanford HAI, 2026).

Agents acting beyond their scope. McKinsey's 2026 AI trust research found 80% of organizations have already encountered risky agent behavior, including unauthorized data exposure and improper system access, while only 21% have a mature governance model for agents (McKinsey, 2026).

Cost running away quietly. Token spend and unused seats compound without anyone noticing, because no one owns the line item. This is a governance failure that looks like a finance problem — more in how to control AI costs.

Notice what's not on this list: the model becoming dangerously capable. That's a real research concern and almost never your operational one.

Who is liable when an AI system gets it wrong?

You are. Courts have consistently declined to treat an AI system as a separate actor. In Moffatt v. Air Canada, a British Columbia tribunal found the airline liable for negligent misrepresentation after its chatbot described a bereavement refund policy that didn't exist. Air Canada argued the chatbot was responsible for its own statements; the tribunal rejected that outright and held the company accountable for everything on its website (American Bar Association, 2024).

The dollar amount was trivial — roughly $650. The precedent is not. Anything your AI tells a customer is a statement by your company.

The practical implication: liability tracks the output, not the vendor. "The model hallucinated" is not a defense, and your vendor's terms of service will not move that risk off your balance sheet. Any AI output that reaches a customer, a regulator, or a contract needs a human verification gate.

Which AI risks actually matter at your size?

Most published AI risk frameworks were written for banks and hospitals. A 200-person services company applying a Fortune 500 framework spends six months producing documents and ships nothing.

Here's a proportionate read:

  • Data leakage via shadow AI — High — Already happening. 43% of breached orgs saw it (IBM, 2026)
  • Unverified customer-facing output — High — Direct legal and reputational exposure
  • Uncontrolled agent permissions — High if agents deployed — 80% of orgs have already seen risky behavior (McKinsey, 2026)
  • Runaway cost — Medium-high — Quiet, cumulative, rarely owned
  • EU AI Act high-risk obligations — Medium, if EU exposure — Annex III deadline moved to December 2027 (Latham & Watkins, 2026)
  • Model bias in hiring or credit decisions — High in those functions only — Narrow but serious
  • Vendor model deprecation — Medium — Breaks workflows, rarely catastrophic
  • Frontier safety concerns — Low operationally — Real, but not your operating risk

On regulation specifically: the EU pushed the Annex III high-risk compliance deadline from August 2026 to December 2027, and product-embedded systems to August 2028 (Latham & Watkins, 2026). But Article 50 transparency requirements — telling people they're interacting with AI, labeling AI-generated content — held their original August 2026 date. If you serve EU customers with a chatbot, that one already applies to you.

Why do governance failures kill AI projects more often than technical ones?

Because the model almost always works well enough. What fails is the scaffolding around it.

Gartner predicts over 40% of agentic AI projects will be canceled by the end of 2027, attributing it to escalating costs, unclear business value, and inadequate risk controls (Gartner, 2025). Not model quality. In May 2026 Gartner added a sharper prediction: by 2027, 40% of enterprises will need to decommission or demote autonomous agents already in production because live incidents expose governance gaps.

That's the pattern worth internalizing. The project doesn't die because the AI was bad. It dies because nobody could answer "who approved this, what can it touch, and who checks it" when something went wrong — so leadership pulled the plug. We've written about the mechanics of that collapse in why 95% of AI pilots fail to reach production.

IBM's data says the same thing from a cost angle: AI adoption without governance — not AI itself — is the primary driver of the $1 million premium AI-related breaches now carry (IBM, 2026).

What does proportionate AI risk management actually look like?

Five controls. They take weeks, not quarters, and they cover the large majority of realistic exposure for a company under ~1,000 people.

1. An approved-tools list with a data tier. Name which tools are allowed and, for each, what class of data may enter it. Three tiers is enough: public, internal, confidential. Most leakage happens because nobody ever said which bucket a tool belonged in.

2. A named owner per AI system. One person accountable for each deployed tool or agent — not a committee. Gartner's analysis of surviving agent projects found a named governance owner per agent was a shared trait of the ones that shipped. See who should own AI automation inside a mid-market company.

3. Human verification gates mapped to stakes. Not every output needs review. Anything that reaches a customer, commits the company, or touches money does. Internal drafting doesn't. Grade the gate to the consequence.

4. Scoped permissions for anything agentic. Give each agent the narrowest possible read and write access, and log what it does. The 92% figure on missing access controls is the single most actionable statistic in this entire post.

5. A monthly cost and usage review. One recurring 30-minute look at spend, seats, and actual weekly usage. It catches runaway cost and dead deployments in the same pass.

That's the whole program. If you want the policy-document version of this, do you need an AI policy? covers what to write down and what to skip.

The risk nobody puts in the framework

The most expensive AI risk we see at Mesh Flow isn't a breach or a lawsuit. It's spending a year producing governance artifacts and never shipping anything — then watching a competitor automate the same workflow in six weeks.

Over-governance is a real failure mode, and it's more common at mid-market than under-governance. It feels responsible. It produces committees, risk registers, and vendor questionnaires. It produces no automated workflows.

The honest calibration: the five controls above are close to sufficient for most companies below enterprise scale. If your risk process is generating more documents than deployed systems, the process is the problem. Governance exists to let you ship faster with less anxiety — not to prove diligence to an auditor who isn't coming.

And the inverse trap is just as real. Stanford found the Foundation Model Transparency Index dropped from 58 to 40 out of 100 between 2024 and 2025, with training data and post-deployment usage the most opaque categories (Stanford HAI, 2026). You will not get full visibility into your vendors' models. Plan controls you own — access, verification, logging — rather than waiting for vendor transparency that isn't arriving.

Frequently Asked Questions

Do we need an AI risk framework before we start using AI?

No. You need an approved-tools list and a rule about what data goes where — that can be written in an afternoon. Full frameworks are worth building once you have multiple systems in production. Waiting for the framework is how companies spend a year not shipping.

Is our AI vendor liable if the output is wrong?

Almost certainly not, in any way that helps you. Moffatt v. Air Canada established that the deploying company owns what its AI says to customers, and the tribunal explicitly rejected the argument that the chatbot was a separate responsible entity (ABA, 2024). Read your vendor terms, but assume the liability is yours.

How do we know if we have a shadow AI problem?

Assume you do. IBM found shadow AI incidents more than doubled to 43% of breached organizations in one cycle, and 68% of breached organizations had no AI use policy (IBM, 2026). Ask your team what they actually use before you ask what they're allowed to use — the gap is your answer.

Does the EU AI Act apply to us if we're a US company?

If you offer AI-touching services to EU customers, some of it does. The Annex III high-risk deadline moved to December 2027, but Article 50 transparency obligations — disclosing AI interaction and labeling AI content — kept their August 2026 date (Latham & Watkins, 2026). A customer-facing chatbot serving EU users is the common trigger.

What's the single highest-leverage control if we can only do one thing?

Scoped access controls on every AI system, with logging. 92% of organizations that suffered an AI-related breach lacked them, and those breaches averaged $5.33 million versus $4.70 million for non-AI breaches (IBM, 2026).

How much should AI risk management cost us?

For a mid-market company, the five controls above are mostly process, not spend — a few weeks of an operations lead's time plus whatever your identity and access tooling already does. If someone is quoting six figures for an AI governance program before you have three systems in production, get a second opinion.

The bottom line

  • Your AI risk is overwhelmingly about access, verification, ownership, and cost — not model behavior.
  • You are liable for what your AI tells customers. No vendor clause changes that.
  • Governance failures, not technical ones, kill the majority of AI projects — Gartner puts agentic cancellations above 40% by end of 2027.
  • Five controls cover most realistic exposure: approved-tools list, named owners, verification gates, scoped permissions, monthly cost review.
  • Over-governance is a real and underrated risk. If you're producing more documents than working systems, recalibrate.

If you'd rather put controls in place while shipping rather than before, that's how we run engagements at Mesh Flow — governance built into the automation, not bolted on ahead of it.

Sources

Filippo Pietrantonio

Founder of Mesh Flow. Builds and ships AI automation systems for mid-market companies and founders.