Guide: AI in business › AI law, risk and ethics
The biggest threats artificial intelligence poses to a company today are not a machine uprising but very down-to-earth matters: leaks of data pasted into a chat, fabricated facts in publications, deepfake fraud, copyright disputes and decisions about people made by an untested algorithm. Each of these risks can be named and reduced. We show how, and along the way suggest which AI ethics principles make sense in a mid-sized company and which will end up as a dead document in the legal department’s folder.
In 60 seconds AI risks in brief
- Main risks: data leaks, fabricated facts, deepfakes, copyright and discrimination in decisions about people.
- Who it applies to: any company where people use AI chats, including without the IT department’s knowledge.
- Legal stakes: for prohibited practices, the AI Act provides for fines of up to €35 million or 7% of turnover. Protection itself costs mainly time: an AI policy, training, a few procedures.
- First move: an inventory of who uses AI and for what, and what data goes into it.
- Red flag: an urgent request for a transfer on a video call with the “CEO”. It may be a deepfake, so you confirm it through another channel.
Is artificial intelligence an opportunity or a threat?
Both, often in the same company and in the same week. The same chat that prepares a draft report in an hour may also accept a pasted client contract or insert a non-existent study into the report. So the question of whether artificial intelligence is dangerous has a practical answer. What is dangerous is using it without rules.
The debate about the threats artificial intelligence poses to humanity, i.e. losing control over highly advanced systems, is taking place among scientists and regulators and is a serious one. The board of a mid-sized company, however, has to deal with risks that could materialise next Monday, and that is what this piece focuses on. A broader map of the topic, from choosing tools to an implementation plan, is drawn in our guide to artificial intelligence for business.
AI ethics, in turn, means the principles for using AI fairly towards the people it affects: customers, employees, audiences. Transparently, without discrimination, with an accountable human at the end of the process. In a company, ethics is not philosophy. It is a list of decisions about what is allowed, what isn’t and who is responsible for what.
Seven AI threats that really affect companies
Here are the risks we come across most often. Where does the danger come from? AI works fast and sounds confident, but it is not responsible for the consequences of its answers, so all the responsibility stays with the company that uses it.
| Risk | What it looks like in practice | Consequences |
|---|---|---|
| Data leakage | an employee pastes customer data, a contract or pre-publication results into a public chat | breach of GDPR and confidentiality, loss of client trust |
| Hallucinations | the model makes up figures, quotes and sources | errors in publications, reputational crisis |
| Deepfakes and fraud | a fake voice or video of the CEO, fake brand statements | financial losses, disinformation about the company |
| Copyright | AI-generated graphics or text without clear rights, similarity to someone else’s work | disputes, no protection for your own materials |
| Discrimination | a recruitment algorithm replicates biases from its data | breach of employment law and the AI Act, damage to employer branding |
| Attacks on AI systems | prompt injection into a company chat, data leaks via an assistant | disclosure of information, erroneous actions by AI agents |
| Legal compliance | missing labels, prohibited practices, no training | AI Act fines, inspection by the supervisory authority |
Data leaks and “do-it-yourself” AI
According to a Microsoft and LinkedIn study from May 2024, 78% of people who use AI at work bring their own tools instead of using those provided by the company. The phenomenon even has its own name: BYOAI (bring your own AI, i.e. “bring your own AI”). The company then doesn’t know what data is leaving the organisation. Nor does it know on what terms the provider stores it.
This is where the most common threats associated with ChatGPT and similar tools in their free versions lie, because data pasted into a private account may, depending on the settings and terms of service, be used for further model training, and the company has no control over it whatsoever. Business versions usually offer better guarantees. On one condition: employees actually have to use them.
Deepfakes, attacks on AI systems and cybersecurity
In 2024 the engineering firm Arup confirmed that one of its employees in Hong Kong had transferred around USD 25 million to fraudsters after a video call in which the chief financial officer and other “colleagues” were generated by AI. This is the best-known example of AI playing on both sides in cybersecurity. It helps defend networks. It also lowers the cost of impersonating people. How to recognise a fake recording and what to do when it concerns your company we described in the article on deepfakes.
The second area is the security of AI systems the company runs itself: a chat on the website, an assistant working on documents, agents carrying out tasks. A typical attack is prompt injection (prompt injection), i.e. hiding instructions in the content of a web page, email or document that take control of the model’s behaviour and tell it, for example, to disclose data or send a message. So the security of AI models is not just the provider’s business. What also matters is which data and actions the company gives them access to.
Artificial intelligence and copyright
Polish copyright law protects a work as a “manifestation of creative activity of an individual nature” (Article 1(1)). In the prevailing view of Polish lawyers, only a human can be an author, so material generated entirely by AI, without a significant creative contribution from a human, may not be a work and may not be protected. What does this mean in practice? A competitor can copy campaign artwork generated with a single prompt, and you may have no way of defending yourself.
The US reached a similar conclusion. In March 2025 the appeals court in Thaler v. Perlmutter confirmed that protection requires a human author, and on 2 March 2026 the US Supreme Court declined to hear the case. The second thread, i.e. the question of whether models could have been trained on other people’s works, is still the subject of litigation around the world.
The takeaway for companies is practical. For material meant to build the brand for years (logo, key visual, slogan), the human creative contribution must be clear and documented, for example in the form of sketches, successive versions and the designer’s decisions. In contracts with agencies and freelancers, specify whether and how they use AI and who is responsible for the rights. Where the generator’s role ends and branding begins we show in our piece on AI-generated graphics and logos.
AI ethics at work: principles sized for a mid-sized company
AI ethics at work comes down to a few questions you ask with every new application. Does the recipient know they are talking to AI? Could the algorithm unfairly pass someone over (a candidate, a customer, a supplier)? Who is responsible when the system gets it wrong? Can we explain the decision to the person it concerns?
- Transparency. We tell customers and candidates where AI is at work, and we label deepfakes and content that requires it. What exactly must be labelled from August 2026 we explain in our piece on labelling AI content.
- Fairness. We test tools for assessing people for bias before they make their first decision.
- Accountability. Every AI process has a named owner, and decisions about people and money are made by a human.
- Privacy. Only data for which we have a legal basis and which the company policy allows goes into AI tools.
- Truth. We don’t publish facts from AI without checking the source.
Who is responsible for AI ethics in a company
In large organisations, there is a role of AI ethicist (AI ethicist) or an AI committee with a lawyer, people from IT and HR, and someone from communications. In a mid-sized company, one person responsible for the AI policy and a short route for raising concerns is enough, for example an email address that someone actually answers. Anyone who wants to specialise in this can choose postgraduate studies in AI ethics and law; we have put together an overview of programmes in our article on postgraduate studies in AI.
On the state side, the Komisja Rozwoju i Bezpieczeństwa Sztucznej Inteligencji (KRiBSI) is due to begin operating in November 2026. It is the Polish market surveillance authority for AI, which will accept reports of irregularities and issue individual opinions to companies. We discuss the obligations under the AI Act, including the list of prohibited practices, in the piece The AI Act in Poland. Recruitment is a particularly sensitive area, and we have devoted a separate piece to it: AI in HR and recruitment.
How to reduce AI risks in your company, step by step
You can implement the plan below in a few weeks without a big budget. The order is not accidental. First, knowledge of what is really going on, then rules, and finally tools and procedures, because a policy written blind usually regulates the wrong things and ends up in a drawer.
- STEP 01Inventory of AI use
A short survey or conversations in each department: who, for what, in which tools, and what data goes into them. No judging, because the point is an honest picture of the situation.
- STEP 02A safe tool for the team
A business licence instead of private accounts. With clear data processing terms, without fail.
- STEP 03An AI policy on one or two pages
Prohibited data, human approval, labelling, accountability. Add an example to each point. Ideally from the work of a specific department, because a generality teaches nobody anything.
- STEP 04Security procedures
Confirming financial instructions through another channel, limited access of AI assistants to data and actions, testing the chat before launch.
- STEP 05Training and an exercise
A short training session on the risks and one exercise, for example a simulated deepfake fraud attempt. The list of participants will serve as evidence of action under Article 4 of the AI Act.
- STEP 06Quarterly review
New tools, incidents, questions from the team. A policy that nobody updates describes, after a year, a company that no longer exists.
What safe use of AI costs
The budget depends mainly on one thing: whether the company only uses off-the-shelf tools or builds its own solutions, such as a customer chat, agents or an assistant working on documents. In the latter case, security testing and ongoing oversight come on top, and that is a separate line in the plan for the whole year.
| Item | What drives the cost | Notes |
|---|---|---|
| Business licences for AI tools | number of users, chosen provider | cheaper than the consequences of a leak from private accounts |
| AI policy and legal consultation | company complexity, high-risk areas | one-off, then a periodic review |
| Training and exercises | number of people, format, frequency | the best cost-to-benefit ratio |
| Security testing of your own AI systems | number of integrations and assistant permissions | before launch and after changes |
| Crisis plan for an AI incident | whether the company already has crisis procedures | deepfakes and leaks are scenarios for the crisis manual |
Signs it is time to deal with AI risks
Don’t wait for an incident if you see even one of these signs: employees talk about “their own” AI chat, HR is testing a CV screening tool, you are planning a customer chat, clients ask about your AI policy in tenders, or there have been fraud attempts in your sector with people impersonating the board. It is less urgent where AI is used only for internal drafts. Provided that everything that goes out is checked and signed off by a human.
An AI incident is often a reputational crisis, because a fabricated piece of information in a publication or a fake recording of the CEO spreads faster than a correction. What to do before the first hour is up is described in the piece AI and crisis communication. Where models’ fabrications come from and how to catch them is explained in our piece on AI hallucinations. The classic rules are summarised in the crisis management process in a nutshell, and we prepare companies for such situations as part of our service crisis management.
Where companies open the door to AI risks themselves
Employees go on using chats, only privately and quietly, so the company loses track of what data is leaving the organisation, and that is precisely the biggest risk.
The line “don’t paste confidential data” doesn’t answer whether you may paste a draft announcement that is under embargo. Generalities end with everyone reading the rules their own way.
Without a rule of confirming instructions through another channel, one convincing conversation is enough for money to leave the company. A single mistake can cost more than the annual marketing budget.
Content generated entirely by AI may not be protected by copyright. If you build the most important elements of your brand on it, competitors may be able to copy them with impunity.
An agent with access to the entire mailbox and drive, which on top of that can send messages, is an easy target for prompt injection. The principle of least privilege costs less than a leak.
Board questions about AI safety and ethics
Is artificial intelligence dangerous for a company?
The technology itself isn’t. What is dangerous is using it without rules, and the most common real threats are data leaks through private chat accounts, fabricated facts in publications, deepfake fraud and copyright disputes.
What are the biggest risks of using ChatGPT at work?
Pasting customer data and company secrets into private accounts, publishing answers without checking the facts and treating the model’s confident tone as proof; you will reduce most of these risks if you give the team a business version of the tool and a clear AI policy.
Is AI-generated content protected by copyright?
According to the prevailing view in Poland, only a human can be the author of a work, so material generated entirely by AI may have no protection. The greater and better documented the human creative input, the stronger the company’s position.
What is AI ethics?
These are the principles of responsible use of artificial intelligence: transparency towards audiences, avoiding discrimination, protecting privacy, truthfulness of information and clear human accountability for decisions. In a company, they usually take the form of a short AI policy.
Who supervises AI safety in Poland?
The Komisja Rozwoju i Bezpieczeństwa Sztucznej Inteligencji (KRiBSI, the Commission for the Development and Safety of Artificial Intelligence), established by the Act of 3 July 2026 on artificial intelligence systems (Journal of Laws 2026, item 1003). According to the Polish Ministry of Digital Affairs, it is due to start operating in November 2026.
How can you protect your company from deepfake fraud?
Introduce a rule that every unusual payment instruction or request for data is confirmed through another channel: by calling back a known number or with an agreed password. Train finance staff, board members and their assistants on it.
Where should a small company start with AI risk management?
With a short inventory: who uses AI, for what and what data goes into it. Then one secure tool for the team, a one-page policy and a short training session, which is enough to reduce the most common risks.
Sources
- SOURCEMicrosoft and LinkedIn: 2024 Work Trend Index · 8 May 2024
- SOURCE
- SOURCEPolish Act on Copyright and Related Rights (ISAP) · accessed 24 September 2026
- SOURCEJustia: Thaler v. Perlmutter, D.C. Circuit · 18 March 2025
- SOURCE
- SOURCEAI Act, Article 99 — penalties · accessed 24 September 2026
- SOURCEMinistry of Digital Affairs: the Act on AI Systems · 27 July 2026
- SOURCEISAP (Sejm): Act of 3 July 2026 on artificial intelligence systems, Journal of Laws 2026, item 1003 · published 27 July 2026, accessed 24 September 2026
Read next
We start by diagnosing how the team really uses AI. Then we set up rules, tools and training, and finally we check whether it all works.
Sebastian Kopiej, CEO of Commplace®. In public relations since 1996. Written with the help of AI tools and editorially verified by the author. Data current as of 24 September 2026.