The AI Decisions You're Already Making
Part 2: The risk isn't where you're looking
In the first piece in this series I looked at two questions most leadership teams haven't explicitly answered: why the business is actually pursuing AI, and who's authorised to say yes before a new use case goes live. If you missed it, it's worth starting there.
This part is about where the risk tends to hide once those conversations have started. In my experience, it's rarely where people are looking for it.
Do you know where your sensitive data actually lives?
Ask this of most leadership teams and you'll get a confident answer, and it's usually an honest one. There's a list of systems, a way of flagging which ones hold sensitive data, a record of who's processing what and which vendors are involved. The static picture is often genuinely there.
What that map usually doesn't show is what happens once AI tools start connecting to each other: one tool quietly pulling information from another, a workflow stitched together by someone who just wanted something to work faster, with no single diagram showing the result. The inventory was built to answer "where does this data sit." It wasn't built to answer "what can now reach this data that couldn't before."
That distinction matters because the risk has moved. A static map tells you where data is kept. It doesn't tell you what's now able to retrieve it, combine it with something else, or act on it - often through a connection nobody formally approved - because connecting two tools together doesn't always feel like the kind of decision that needs sign-off.
If your honest answer is "we have the inventory, but not the connections," you're not behind, you're roughly where most businesses are right now. The question is whether anyone's actually looking for where those connections are forming, or waiting to find out the way most people do: after one causes a problem.
Could AI be harming customers through a tool you don't think of as customer-facing?
The instinct in most businesses is sensible on its face: start with internal use cases (analytics, efficiency tools, copilots for different roles) and say the real scrutiny kicks in once something touches a customer directly. It feels like the responsible order of operations.
The problem is the category doesn't hold. An internal analytics tool that quietly skews a judgement call, a copilot that speeds up how fast a decision gets made without anyone checking whether it's still a good one, a recommendation engine surfacing what looks profitable over what's actually right for the person on the other end. None of these are customer-facing in the way the label usually means, and all of them reach a customer eventually, just with a few more steps in between.
"Internal" was never really the safe category. It was just the category that hadn't been checked yet.
This isn't an argument for treating every internal tool like a regulated customer journey. That would grind everything to a halt for no reason. It's a smaller, harder ask: stop using "is this customer-facing" as the test for what gets scrutiny, and start asking "where does this eventually influence a decision about a customer" instead. Those two questions sound similar. The answers often aren't.
The third and final piece looks at whether your business could actually prove it's handling AI responsibly. Not what you intend to put in place, but what exists today, and whether you'd know if something went wrong.
Ed Ball is Head of Data and Security at a regulated UK lender, and the founder of Sapien Solutions.
← Part 1: Why you're doing this, and who's actually deciding
Part 3: What you'd actually find if someone asked you to prove it →