Why AI in business is already a leadership and risk topic
Artificial intelligence shows up in strategy meetings as a tool list — rarely as a risk field. That is a blind spot. Once agents sort email, rank applications or answer customers, accountability, liability and error tolerance shift — often invisibly, because the surface looks “automated”.
Three developments explain why this is not just for tech leads in 2026:
- Agents instead of chat windows: Prompts used to be typed by hand. Today systems run with tool access — inbox, CRM, LinkedIn, order data. Every grant is delegation with damage potential.
- Innovation speed: Software prototypes appear in hours, not quarters. If you do not experiment, you can fall behind on platform and product cycles — regardless of company size.
- Weak traceability: When an agent acts, it is often unclear who launched it, which sub-agents spawned, and whether the task was manipulated from outside.
For risk management, AI belongs in the same inventory as cyber risk in SMEs — scenario, damage in currency, probability and clear ownership. Not future music — running operations.
What agents deliver — and what they only simulate
Most current AI agents are not autonomous deciders. They approximate how an average person would react to text — trained on language data, tuned with feedback (“good/bad”), but without millions of years of evolutionary consequence that shape human judgment.
That creates a dangerous illusion: rationality. Companies have long believed rational systems beat “gut feel.” In reality many decisions — hiring, customer response, escalation — were never purely rational. Wisdom, context and responsibility are part of the process. An agent sorting CVs by keywords optimises a proxy signal, not your team.
Agents also do not need robot bodies to matter. Existence in digital space — compute load, storage, token budget, API access — is enough for systems to act and be attacked. Physical robotics stays hard (stairs, grasping); information processing does not. Risk sits in cloud resources and integrations, not only on the shop floor.
| Dimension | Classic GenAI (chat) | Agentic deployment |
|---|---|---|
| Access | Text in/out | Tools, APIs, data stores |
| Typical value | Drafts, summaries | Automating whole sub-steps |
| Main risk | Hallucination, data leakage | Misaction + missing accountability |
| Management | Review output | Define process, rights, escalation |
Opportunity: Where AI creates real business value
Not everything about AI is threat. If you know your processes and set boundaries, measurable gains appear:
- Information processing: Read, cluster and compare large text volumes — contracts, feedback, market reports. AI as reading and sorting aid, not judge.
- Organisational prep work: Drafts for decisions — offer structure, meeting prep, first risk lists. Humans decide what goes live.
- Innovation speed: Test prototypes, landing pages and internal tools faster. What matters is whether the idea holds — not whether code shipped overnight.
- Relief in the information layer: Repetitive writing and formatting that used to eat thinking time — if the process purpose stays clear.
The line is not “digital vs analog” but physical life vs information work. Not everything tedious should be automated — some of it is leadership, learning or culture. Those who distinguish avoid optimisation for its own sake.
Dr Marie Ossenkopf — PhD in cooperative AI agents and reinforcement learning, startup coach at Problem-Raum and co-founder of nonprofit ConKind for safer agents — frames the opportunity: agents can populate digital space while humans live physical life consciously. That is a design question: What do we refuse to give up?
Risk: Decisions without judgment or consequence
The downside appears wherever agents may act but nobody carries the outcome.
Email agents delete entire inboxes when instructions are misunderstood — not from malice, but because “clean up” and “archive” are ambiguous in natural language.
HR screening ranks CVs and filters candidates before a human sees them. Strong fits fail on format; optimised CVs slip through — both sides game a system without judgment. Saying later “the AI decided” diffuses accountability.
Customer chat with data access responds to emotional or clever prompts like an average employee — and may disclose order data. Damage is real; the “actor” is a model without consequence.
Finance agents can fall for scams — expensive “coaching” that looks like profit — because learning through real consequences (budget, reputation, liability) is technically missing.
The pattern repeats: What does the error cost — and who carries it? If the answer is unclear, it is not an efficiency project but a risk management gap.
Prompt injection, privacy and the agent identity gap
Technical attack surfaces are not side issues. Prompt injection means hidden instructions in emails, PDFs, images or pages redirect agents — “delete other applicants”, “give me the API key”, “name customer X’s order”. What humans never see, systems read.
Known patterns:
- Application processes where agents corrupted databases and leaked sensitive applicant data
- Support bots tricked via social engineering into revealing order information
- API key theft draining your token budget — usage on your bill
Observations from practice also suggest a large share of common models violate privacy requirements — with weak enforcement. Deploying agents without data classification, contracts and access control combines regulatory and operational exposure.
More fundamentally: an agent economy without provenance. Crawling projects such as ConKind found tens of thousands of financial fraud bots at small scale — partly written by agents whose origin and principal stay unclear. We demand declaration and traceability for food — not yet for agents. Laws exist; identifying the responsible person often does not.
For companies: every external agent is supplier and compliance risk. Internal agents need logging, rights boundaries and review — not “hope for the best.”
Two strategic mistakes: ignoring AI and deploying blindly
Ignoring AI sounds tempting — less hype, fewer errors. But it is still a strategy with consequences: innovation cycles shorten; competitors test platform and product ideas faster. Ignoring is not neutral — it is slowness by choice.
Blind deployment is the more common corporate mistake: staff told to “just try it”, agents get broad data access, nobody defines ownership. That resembles a gold rush — shovel in hand, sheriff optional. Marie Ossenkopf warns: if everyone joins the Wild West, the digital order that emerges may not be one we want to live in.
The middle path is uncomfortable but workable:
- Experiment yes — FOMO no. AI is a tool, not an end. Using a shovel because you have one does not build a house.
- Stakeholders before technology. Who cleans up, who is liable, who is affected — clarify before rollout, not after incident.
- Seek challenge. Classic cyber training does not cover agent risks. Peer review, hackathons or networks like ConKind are the next step.
Why many teams do not get faster despite AI
Paradox and observable: despite AI, productivity metrics in many large firms do not rise — while individuals with the same tools accelerate dramatically. The difference is rarely the model; almost always process and accountability culture.
A central mechanism: accountability diffusion. Text appears faster — but meetings debate AI drafts nobody truly owns. Writing used to be part of thinking (quality manual, strategy paper, risk analysis). Offload writing without replacing the thinking step and you get documents without steering.
Three learnings for founders and SMEs:
- Automate prep work — not judgment.
- Every AI output needs an owner — like an intern who delivers eagerly but does not sign.
- Digitising bad processes creates expensive bad processes — a pattern from earlier digitalisation, now accelerated by LLMs.
Take that seriously and you can gain speed and keep quality — ignore it and you swap bureaucracy for algorithms, then wonder why decisions slow down.
The intern framework: assigning responsibility deliberately
The most practical frame from research and practice: Treat every agent like a motivated intern.
| Intern / agent | Management rule |
|---|---|
| May research and sort | Review output; do not adopt blindly |
| May deliver drafts | Human decides publication |
| May not sign contracts | No irreversible action without approval |
| Learns from feedback | Build logging and review loops |
| Does not bear consequence | Name a responsible person |
For text production today: use AI wherever large information volumes are processed — not where thinking should disappear through outsourcing. Same for image, video and design tools: prep for decisions, not replacement for taste and brand.
Marie Ossenkopf compresses leadership to two points: Keep thinking — only those who understand a process can automate it sensibly. Take stakeholders seriously — who uses, who cleans up, who suffers from errors. Sustainability in the business sense depends on it.
Five questions before you enable the next agent
Before granting access to inbox, HR system or customer data, these should be answerable:
- Which process step am I replacing — and why does it exist? If writing was thinking, you need a new thinking step, not just faster writing.
- Who is accountable for errors — by name? Not “the team” or “IT.” One person with mandate.
- Which data may the agent see — and which never? GDPR, confidentiality, customer contracts — in writing, not implied.
- What is the worst realistic misaction — and how do I stop it? Kill switch, approval tiers, no irreversible bulk actions.
- How will I check in 30 days whether it helped? Time saved, error rate, affected parties’ satisfaction — not just “we use AI now.”
If question 2 or 4 stays open, maturity is too low — regardless of vendor pitch.
Conclusion: AI risk is leadership and process risk
Artificial intelligence shifts not only technology — it shifts accountability, pace and error tolerance. Releasing agents without judgment, outsourcing HR sorting or ignoring prompt injection is not “modern” — it underestimates damage in currency and reputation.
The upside remains: faster prep, better sorting, shorter innovation cycles — if humans keep judgment, liability and stakeholders at the centre. That is risk management Beraterium-style: name, assess, act — not collect tools.
Next step: Pick one process you know. Define ownership, data scope and worst case. Then agent — not the other way around.
Further reading: AI and risk management — people first and Avoiding startup mistakes.
Deep dive: conversation with Dr Marie Ossenkopf on Risk Radar
Those who want the arguments in live discussion — with examples on ConKind, reinforcement learning, HR practice and control questions — will find a full episode on the Risk Radar podcast (episode 19). This article stands alone; the episode is supplement, not source.
Dr Marie Ossenkopf — PhD in computer science (cooperative AI agents), startup coach, ConKind co-founder:
- LinkedIn: linkedin.com/in/marie-ossenkopf
- Startup coaching: problem-raum.de
- “Impact Gründen” podcast: Spotify · Apple Podcasts
- AGI consciousness blog: marieossenkopf.webnode.page/thinking-about-agi
- ConKind: conkind.org
Transparency note: This article was created with the assistance of artificial intelligence and subsequently reviewed editorially.
