navigation

Artificial intelligence: AI risks and ethics in business — what the real threats are and how to protect yourself

Guide: AI in business › AI law, risk and ethics

ARTIFICIAL INTELLIGENCE IN MARKETING

The biggest threats artificial intelligence poses to a company today are not a machine uprising but very down-to-earth matters: leaks of data pasted into a chat, fabricated facts in publications, deepfake fraud, copyright disputes and decisions about people made by an untested algorithm. Each of these risks can be named and reduced. We show how, and along the way suggest which AI ethics principles make sense in a mid-sized company and which will end up as a dead document in the legal department’s folder.

12 min readUpdated: 24 September 2026Author: Sebastian Kopiej

In 60 seconds AI risks in brief

  • Main risks: data leaks, fabricated facts, deepfakes, copyright and discrimination in decisions about people.
  • Who it applies to: any company where people use AI chats, including without the IT department’s knowledge.
  • Legal stakes: for prohibited practices, the AI Act provides for fines of up to €35 million or 7% of turnover. Protection itself costs mainly time: an AI policy, training, a few procedures.
  • First move: an inventory of who uses AI and for what, and what data goes into it.
  • Red flag: an urgent request for a transfer on a video call with the “CEO”. It may be a deepfake, so you confirm it through another channel.
78%of AI users at work bring their own tools rather than those provided by their employer (survey of 31,000 people in 31 countries)BENCHMARKMicrosoft and LinkedIn, Work Trend Index, 8 May 2024
$25mthe amount engineering firm Arup lost after a video call with a deepfake of its chief financial officerFACTCNN, 16 May 2024
€35mor 7% of worldwide turnover — the upper limit of fines for prohibited AI practicesFACTAI Act, Article 99

Is artificial intelligence an opportunity or a threat?

Both, often in the same company and in the same week. The same chat that prepares a draft report in an hour may also accept a pasted client contract or insert a non-existent study into the report. So the question of whether artificial intelligence is dangerous has a practical answer. What is dangerous is using it without rules.

The debate about the threats artificial intelligence poses to humanity, i.e. losing control over highly advanced systems, is taking place among scientists and regulators and is a serious one. The board of a mid-sized company, however, has to deal with risks that could materialise next Monday, and that is what this piece focuses on. A broader map of the topic, from choosing tools to an implementation plan, is drawn in our guide to artificial intelligence for business.

AI ethics, in turn, means the principles for using AI fairly towards the people it affects: customers, employees, audiences. Transparently, without discrimination, with an accountable human at the end of the process. In a company, ethics is not philosophy. It is a list of decisions about what is allowed, what isn’t and who is responsible for what.

Seven AI threats that really affect companies

Here are the risks we come across most often. Where does the danger come from? AI works fast and sounds confident, but it is not responsible for the consequences of its answers, so all the responsibility stays with the company that uses it.

RiskWhat it looks like in practiceConsequences
Data leakagean employee pastes customer data, a contract or pre-publication results into a public chatbreach of GDPR and confidentiality, loss of client trust
Hallucinationsthe model makes up figures, quotes and sourceserrors in publications, reputational crisis
Deepfakes and frauda fake voice or video of the CEO, fake brand statementsfinancial losses, disinformation about the company
CopyrightAI-generated graphics or text without clear rights, similarity to someone else’s workdisputes, no protection for your own materials
Discriminationa recruitment algorithm replicates biases from its databreach of employment law and the AI Act, damage to employer branding
Attacks on AI systemsprompt injection into a company chat, data leaks via an assistantdisclosure of information, erroneous actions by AI agents
Legal compliancemissing labels, prohibited practices, no trainingAI Act fines, inspection by the supervisory authority

Data leaks and “do-it-yourself” AI

According to a Microsoft and LinkedIn study from May 2024, 78% of people who use AI at work bring their own tools instead of using those provided by the company. The phenomenon even has its own name: BYOAI (bring your own AI, i.e. “bring your own AI”). The company then doesn’t know what data is leaving the organisation. Nor does it know on what terms the provider stores it.

This is where the most common threats associated with ChatGPT and similar tools in their free versions lie, because data pasted into a private account may, depending on the settings and terms of service, be used for further model training, and the company has no control over it whatsoever. Business versions usually offer better guarantees. On one condition: employees actually have to use them.

Deepfakes, attacks on AI systems and cybersecurity

In 2024 the engineering firm Arup confirmed that one of its employees in Hong Kong had transferred around USD 25 million to fraudsters after a video call in which the chief financial officer and other “colleagues” were generated by AI. This is the best-known example of AI playing on both sides in cybersecurity. It helps defend networks. It also lowers the cost of impersonating people. How to recognise a fake recording and what to do when it concerns your company we described in the article on deepfakes.

The second area is the security of AI systems the company runs itself: a chat on the website, an assistant working on documents, agents carrying out tasks. A typical attack is prompt injection (prompt injection), i.e. hiding instructions in the content of a web page, email or document that take control of the model’s behaviour and tell it, for example, to disclose data or send a message. So the security of AI models is not just the provider’s business. What also matters is which data and actions the company gives them access to.

Artificial intelligence and copyright

Polish copyright law protects a work as a “manifestation of creative activity of an individual nature” (Article 1(1)). In the prevailing view of Polish lawyers, only a human can be an author, so material generated entirely by AI, without a significant creative contribution from a human, may not be a work and may not be protected. What does this mean in practice? A competitor can copy campaign artwork generated with a single prompt, and you may have no way of defending yourself.

The US reached a similar conclusion. In March 2025 the appeals court in Thaler v. Perlmutter confirmed that protection requires a human author, and on 2 March 2026 the US Supreme Court declined to hear the case. The second thread, i.e. the question of whether models could have been trained on other people’s works, is still the subject of litigation around the world.

The takeaway for companies is practical. For material meant to build the brand for years (logo, key visual, slogan), the human creative contribution must be clear and documented, for example in the form of sketches, successive versions and the designer’s decisions. In contracts with agencies and freelancers, specify whether and how they use AI and who is responsible for the rights. Where the generator’s role ends and branding begins we show in our piece on AI-generated graphics and logos.

AI ethics at work: principles sized for a mid-sized company

AI ethics at work comes down to a few questions you ask with every new application. Does the recipient know they are talking to AI? Could the algorithm unfairly pass someone over (a candidate, a customer, a supplier)? Who is responsible when the system gets it wrong? Can we explain the decision to the person it concerns?

  • Transparency. We tell customers and candidates where AI is at work, and we label deepfakes and content that requires it. What exactly must be labelled from August 2026 we explain in our piece on labelling AI content.
  • Fairness. We test tools for assessing people for bias before they make their first decision.
  • Accountability. Every AI process has a named owner, and decisions about people and money are made by a human.
  • Privacy. Only data for which we have a legal basis and which the company policy allows goes into AI tools.
  • Truth. We don’t publish facts from AI without checking the source.

Who is responsible for AI ethics in a company

In large organisations, there is a role of AI ethicist (AI ethicist) or an AI committee with a lawyer, people from IT and HR, and someone from communications. In a mid-sized company, one person responsible for the AI policy and a short route for raising concerns is enough, for example an email address that someone actually answers. Anyone who wants to specialise in this can choose postgraduate studies in AI ethics and law; we have put together an overview of programmes in our article on postgraduate studies in AI.

On the state side, the Komisja Rozwoju i Bezpieczeństwa Sztucznej Inteligencji (KRiBSI) is due to begin operating in November 2026. It is the Polish market surveillance authority for AI, which will accept reports of irregularities and issue individual opinions to companies. We discuss the obligations under the AI Act, including the list of prohibited practices, in the piece The AI Act in Poland. Recruitment is a particularly sensitive area, and we have devoted a separate piece to it: AI in HR and recruitment.

How to reduce AI risks in your company, step by step

You can implement the plan below in a few weeks without a big budget. The order is not accidental. First, knowledge of what is really going on, then rules, and finally tools and procedures, because a policy written blind usually regulates the wrong things and ends up in a drawer.

  1. STEP 01Inventory of AI use

    A short survey or conversations in each department: who, for what, in which tools, and what data goes into them. No judging, because the point is an honest picture of the situation.

  2. STEP 02A safe tool for the team

    A business licence instead of private accounts. With clear data processing terms, without fail.

  3. STEP 03An AI policy on one or two pages

    Prohibited data, human approval, labelling, accountability. Add an example to each point. Ideally from the work of a specific department, because a generality teaches nobody anything.

  4. STEP 04Security procedures

    Confirming financial instructions through another channel, limited access of AI assistants to data and actions, testing the chat before launch.

  5. STEP 05Training and an exercise

    A short training session on the risks and one exercise, for example a simulated deepfake fraud attempt. The list of participants will serve as evidence of action under Article 4 of the AI Act.

  6. STEP 06Quarterly review

    New tools, incidents, questions from the team. A policy that nobody updates describes, after a year, a company that no longer exists.

What safe use of AI costs

The budget depends mainly on one thing: whether the company only uses off-the-shelf tools or builds its own solutions, such as a customer chat, agents or an assistant working on documents. In the latter case, security testing and ongoing oversight come on top, and that is a separate line in the plan for the whole year.

ItemWhat drives the costNotes
Business licences for AI toolsnumber of users, chosen providercheaper than the consequences of a leak from private accounts
AI policy and legal consultationcompany complexity, high-risk areasone-off, then a periodic review
Training and exercisesnumber of people, format, frequencythe best cost-to-benefit ratio
Security testing of your own AI systemsnumber of integrations and assistant permissionsbefore launch and after changes
Crisis plan for an AI incidentwhether the company already has crisis proceduresdeepfakes and leaks are scenarios for the crisis manual

Signs it is time to deal with AI risks

Don’t wait for an incident if you see even one of these signs: employees talk about “their own” AI chat, HR is testing a CV screening tool, you are planning a customer chat, clients ask about your AI policy in tenders, or there have been fraud attempts in your sector with people impersonating the board. It is less urgent where AI is used only for internal drafts. Provided that everything that goes out is checked and signed off by a human.

An AI incident is often a reputational crisis, because a fabricated piece of information in a publication or a fake recording of the CEO spreads faster than a correction. What to do before the first hour is up is described in the piece AI and crisis communication. Where models’ fabrications come from and how to catch them is explained in our piece on AI hallucinations. The classic rules are summarised in the crisis management process in a nutshell, and we prepare companies for such situations as part of our service crisis management.

Where companies open the door to AI risks themselves

1

A total ban on AI with no alternative

Employees go on using chats, only privately and quietly, so the company loses track of what data is leaving the organisation, and that is precisely the biggest risk.

2

An AI policy without examples

The line “don’t paste confidential data” doesn’t answer whether you may paste a draft announcement that is under embargo. Generalities end with everyone reading the rules their own way.

3

No deepfake procedure

Without a rule of confirming instructions through another channel, one convincing conversation is enough for money to leave the company. A single mistake can cost more than the annual marketing budget.

4

Assuming that AI materials are “ours”

Content generated entirely by AI may not be protected by copyright. If you build the most important elements of your brand on it, competitors may be able to copy them with impunity.

5

An AI assistant with excessive permissions

An agent with access to the entire mailbox and drive, which on top of that can send messages, is an easy target for prompt injection. The principle of least privilege costs less than a leak.

Board questions about AI safety and ethics

Is artificial intelligence dangerous for a company?

The technology itself isn’t. What is dangerous is using it without rules, and the most common real threats are data leaks through private chat accounts, fabricated facts in publications, deepfake fraud and copyright disputes.

What are the biggest risks of using ChatGPT at work?

Pasting customer data and company secrets into private accounts, publishing answers without checking the facts and treating the model’s confident tone as proof; you will reduce most of these risks if you give the team a business version of the tool and a clear AI policy.

Is AI-generated content protected by copyright?

According to the prevailing view in Poland, only a human can be the author of a work, so material generated entirely by AI may have no protection. The greater and better documented the human creative input, the stronger the company’s position.

What is AI ethics?

These are the principles of responsible use of artificial intelligence: transparency towards audiences, avoiding discrimination, protecting privacy, truthfulness of information and clear human accountability for decisions. In a company, they usually take the form of a short AI policy.

Who supervises AI safety in Poland?

The Komisja Rozwoju i Bezpieczeństwa Sztucznej Inteligencji (KRiBSI, the Commission for the Development and Safety of Artificial Intelligence), established by the Act of 3 July 2026 on artificial intelligence systems (Journal of Laws 2026, item 1003). According to the Polish Ministry of Digital Affairs, it is due to start operating in November 2026.

How can you protect your company from deepfake fraud?

Introduce a rule that every unusual payment instruction or request for data is confirmed through another channel: by calling back a known number or with an agreed password. Train finance staff, board members and their assistants on it.

Where should a small company start with AI risk management?

With a short inventory: who uses AI, for what and what data goes into it. Then one secure tool for the team, a one-page policy and a short training session, which is enough to reduce the most common risks.

Sources

Read next

Want to use AI faster, but without risking your data and reputation?

We start by diagnosing how the team really uses AI. Then we set up rules, tools and training, and finally we check whether it all works.

Sebastian Kopiej, CEO of Commplace®. In public relations since 1996. Written with the help of AI tools and editorially verified by the author. Data current as of 24 September 2026.

Call me Customer panel Contact