AIBez Strachuv0.5
BooksRandom
Courses›The Visual Encyclopaedia of AI for the Over-40s›⚖️ Risk & Governance
Chapter 06

⚖️ Risk & Governance

~20 min read

📖 Text🎨 App

The EU AI Act

The EU AI Act classifies AI systems by risk: unacceptable (banned), high-risk (regulated), limited (transparency obligations), minimal. UK GDPR and the Algorithmic Accountability principles apply in parallel.

  • EU AI Act came into force August 2024; phased obligations from 2025–2027.
  • High-risk AI (HR tools, credit scoring, medical) requires conformity assessment.
  • UK approach: principles-based, sector-led — lighter touch than EU in 2024.

---

GDPR and AI

AI that processes personal data triggers GDPR obligations: lawful basis, data minimisation, right to explanation for automated decisions. Most enterprise AI tools need a DPIA.

  • Automated decisions with legal/significant effects require human review under GDPR Art. 22.
  • Training AI on customer data without explicit consent is a GDPR risk.
  • DPIA (Data Protection Impact Assessment) is mandatory for high-risk AI processing.

---

Intellectual Property and AI

AI-generated content ownership is unsettled. UK copyright law does not protect purely AI-generated work. Training AI on copyrighted works without licence is legally contested globally.

  • UK IPO: AI-generated works with 'no human author' are not copyrightable.
  • Getty Images vs Stability AI: landmark case on training data IP rights.
  • Document your AI contribution to creative work for IP clarity.

---

Hallucination Risk Management

AI confidently produces wrong facts. In client-facing or regulated contexts, unverified AI output is a reputational and legal risk. Implement systematic verification for high-stakes outputs.

  • LLM hallucination rates: 3% on simple factual queries, up to 20% on complex ones.
  • Mitigation: RAG (cited sources), output confidence scores, mandatory human review.
  • Legal and medical AI tools: always require expert sign-off before use.

---

Cybersecurity and AI

AI introduces new attack vectors: prompt injection (manipulating AI via malicious inputs), model poisoning (corrupting training data), and deepfake social engineering. Your security posture needs updating.

  • Prompt injection is the #1 attack on AI systems in 2024.
  • AI-generated phishing emails are 40% more effective than human-written ones.
  • Deepfake audio fraud: executives impersonated in £20M+ wire transfer fraud cases.

---

Building an AI Governance Framework

A governance framework covers: approved use cases, prohibited uses, data handling policies, audit requirements, and escalation paths. It should be documented, trained, and reviewed annually.

  • 79% of organisations have no formal AI governance policy (Gartner 2024).
  • Components: AI registry, risk classification, ethics review board, incident response.
  • Governance frameworks reduce AI-related incidents 60% in organisations that implement them.

---

Ethics Committees and AI Review

High-impact AI deployments benefit from cross-functional ethics review: legal, HR, technology, and business leads. This is not bureaucracy — it's risk management that catches issues before they become headlines.

  • Walmart, HSBC, and Unilever all have formal AI ethics review boards.
  • Ethics review catches 80% of foreseeable harms at spec stage vs. 20% post-deployment.
  • Include diverse voices — bias in AI often reflects the homogeneity of the team building it.

---

Insurance and Liability for AI

Who is liable when AI makes a wrong decision? Product liability, professional indemnity, and D&O insurance policies need updating for AI-assisted decisions. Your broker may not know this yet.

  • UK product liability law is evolving to cover AI-related harms.
  • Professional indemnity: check whether AI-assisted advice is covered in your policy.
  • First AI-related class action lawsuits against corporates filed in US courts in 2023.

Sign in to track your progress and earn a certificate.

Sign in
🏢 Enterprise Tools🔨 Building with AI