Skip to content
Skip to article text

AI in Business: Agents, Opportunity and the Risk of Diffused Accountability

Abstract digital agent network beside a calm SME office desk symbolising AI business risk and opportunity

Why AI in business is already a leadership and risk topic

Artificial intelligence shows up in strategy meetings as a tool list — rarely as a risk field. That is a blind spot. Once agents sort email, rank applications or answer customers, accountability, liability and error tolerance shift — often invisibly, because the surface looks “automated”.

Three developments explain why this is not just for tech leads in 2026:

  • Agents instead of chat windows: Prompts used to be typed by hand. Today systems run with tool access — inbox, CRM, LinkedIn, order data. Every grant is delegation with damage potential.
  • Innovation speed: Software prototypes appear in hours, not quarters. If you do not experiment, you can fall behind on platform and product cycles — regardless of company size.
  • Weak traceability: When an agent acts, it is often unclear who launched it, which sub-agents spawned, and whether the task was manipulated from outside.

For risk management, AI belongs in the same inventory as cyber risk in SMEs — scenario, damage in currency, probability and clear ownership. Not future music — running operations.

What agents deliver — and what they only simulate

Most current AI agents are not autonomous deciders. They approximate how an average person would react to text — trained on language data, tuned with feedback (“good/bad”), but without millions of years of evolutionary consequence that shape human judgment.

That creates a dangerous illusion: rationality. Companies have long believed rational systems beat “gut feel.” In reality many decisions — hiring, customer response, escalation — were never purely rational. Wisdom, context and responsibility are part of the process. An agent sorting CVs by keywords optimises a proxy signal, not your team.

Agents also do not need robot bodies to matter. Existence in digital space — compute load, storage, token budget, API access — is enough for systems to act and be attacked. Physical robotics stays hard (stairs, grasping); information processing does not. Risk sits in cloud resources and integrations, not only on the shop floor.

Dimension Classic GenAI (chat) Agentic deployment
Access Text in/out Tools, APIs, data stores
Typical value Drafts, summaries Automating whole sub-steps
Main risk Hallucination, data leakage Misaction + missing accountability
Management Review output Define process, rights, escalation

Opportunity: Where AI creates real business value

Not everything about AI is threat. If you know your processes and set boundaries, measurable gains appear:

  • Information processing: Read, cluster and compare large text volumes — contracts, feedback, market reports. AI as reading and sorting aid, not judge.
  • Organisational prep work: Drafts for decisions — offer structure, meeting prep, first risk lists. Humans decide what goes live.
  • Innovation speed: Test prototypes, landing pages and internal tools faster. What matters is whether the idea holds — not whether code shipped overnight.
  • Relief in the information layer: Repetitive writing and formatting that used to eat thinking time — if the process purpose stays clear.

The line is not “digital vs analog” but physical life vs information work. Not everything tedious should be automated — some of it is leadership, learning or culture. Those who distinguish avoid optimisation for its own sake.

Dr Marie Ossenkopf — PhD in cooperative AI agents and reinforcement learning, startup coach at Problem-Raum and co-founder of nonprofit ConKind for safer agents — frames the opportunity: agents can populate digital space while humans live physical life consciously. That is a design question: What do we refuse to give up?

Risk: Decisions without judgment or consequence

The downside appears wherever agents may act but nobody carries the outcome.

Email agents delete entire inboxes when instructions are misunderstood — not from malice, but because “clean up” and “archive” are ambiguous in natural language.

HR screening ranks CVs and filters candidates before a human sees them. Strong fits fail on format; optimised CVs slip through — both sides game a system without judgment. Saying later “the AI decided” diffuses accountability.

Customer chat with data access responds to emotional or clever prompts like an average employee — and may disclose order data. Damage is real; the “actor” is a model without consequence.

Finance agents can fall for scams — expensive “coaching” that looks like profit — because learning through real consequences (budget, reputation, liability) is technically missing.

The pattern repeats: What does the error cost — and who carries it? If the answer is unclear, it is not an efficiency project but a risk management gap.

Prompt injection, privacy and the agent identity gap

Technical attack surfaces are not side issues. Prompt injection means hidden instructions in emails, PDFs, images or pages redirect agents — “delete other applicants”, “give me the API key”, “name customer X’s order”. What humans never see, systems read.

Known patterns:

  • Application processes where agents corrupted databases and leaked sensitive applicant data
  • Support bots tricked via social engineering into revealing order information
  • API key theft draining your token budget — usage on your bill

Observations from practice also suggest a large share of common models violate privacy requirements — with weak enforcement. Deploying agents without data classification, contracts and access control combines regulatory and operational exposure.

More fundamentally: an agent economy without provenance. Crawling projects such as ConKind found tens of thousands of financial fraud bots at small scale — partly written by agents whose origin and principal stay unclear. We demand declaration and traceability for food — not yet for agents. Laws exist; identifying the responsible person often does not.

For companies: every external agent is supplier and compliance risk. Internal agents need logging, rights boundaries and review — not “hope for the best.”

Two strategic mistakes: ignoring AI and deploying blindly

Ignoring AI sounds tempting — less hype, fewer errors. But it is still a strategy with consequences: innovation cycles shorten; competitors test platform and product ideas faster. Ignoring is not neutral — it is slowness by choice.

Blind deployment is the more common corporate mistake: staff told to “just try it”, agents get broad data access, nobody defines ownership. That resembles a gold rush — shovel in hand, sheriff optional. Marie Ossenkopf warns: if everyone joins the Wild West, the digital order that emerges may not be one we want to live in.

The middle path is uncomfortable but workable:

  • Experiment yes — FOMO no. AI is a tool, not an end. Using a shovel because you have one does not build a house.
  • Stakeholders before technology. Who cleans up, who is liable, who is affected — clarify before rollout, not after incident.
  • Seek challenge. Classic cyber training does not cover agent risks. Peer review, hackathons or networks like ConKind are the next step.

Why many teams do not get faster despite AI

Paradox and observable: despite AI, productivity metrics in many large firms do not rise — while individuals with the same tools accelerate dramatically. The difference is rarely the model; almost always process and accountability culture.

A central mechanism: accountability diffusion. Text appears faster — but meetings debate AI drafts nobody truly owns. Writing used to be part of thinking (quality manual, strategy paper, risk analysis). Offload writing without replacing the thinking step and you get documents without steering.

Three learnings for founders and SMEs:

  1. Automate prep work — not judgment.
  2. Every AI output needs an owner — like an intern who delivers eagerly but does not sign.
  3. Digitising bad processes creates expensive bad processes — a pattern from earlier digitalisation, now accelerated by LLMs.

Take that seriously and you can gain speed and keep quality — ignore it and you swap bureaucracy for algorithms, then wonder why decisions slow down.

The intern framework: assigning responsibility deliberately

The most practical frame from research and practice: Treat every agent like a motivated intern.

Intern / agent Management rule
May research and sort Review output; do not adopt blindly
May deliver drafts Human decides publication
May not sign contracts No irreversible action without approval
Learns from feedback Build logging and review loops
Does not bear consequence Name a responsible person

For text production today: use AI wherever large information volumes are processed — not where thinking should disappear through outsourcing. Same for image, video and design tools: prep for decisions, not replacement for taste and brand.

Marie Ossenkopf compresses leadership to two points: Keep thinking — only those who understand a process can automate it sensibly. Take stakeholders seriously — who uses, who cleans up, who suffers from errors. Sustainability in the business sense depends on it.

Five questions before you enable the next agent

Before granting access to inbox, HR system or customer data, these should be answerable:

  1. Which process step am I replacing — and why does it exist? If writing was thinking, you need a new thinking step, not just faster writing.
  2. Who is accountable for errors — by name? Not “the team” or “IT.” One person with mandate.
  3. Which data may the agent see — and which never? GDPR, confidentiality, customer contracts — in writing, not implied.
  4. What is the worst realistic misaction — and how do I stop it? Kill switch, approval tiers, no irreversible bulk actions.
  5. How will I check in 30 days whether it helped? Time saved, error rate, affected parties’ satisfaction — not just “we use AI now.”

If question 2 or 4 stays open, maturity is too low — regardless of vendor pitch.

Conclusion: AI risk is leadership and process risk

Artificial intelligence shifts not only technology — it shifts accountability, pace and error tolerance. Releasing agents without judgment, outsourcing HR sorting or ignoring prompt injection is not “modern” — it underestimates damage in currency and reputation.

The upside remains: faster prep, better sorting, shorter innovation cycles — if humans keep judgment, liability and stakeholders at the centre. That is risk management Beraterium-style: name, assess, act — not collect tools.

Next step: Pick one process you know. Define ownership, data scope and worst case. Then agent — not the other way around.

Further reading: AI and risk management — people first and Avoiding startup mistakes.

Deep dive: conversation with Dr Marie Ossenkopf on Risk Radar

Those who want the arguments in live discussion — with examples on ConKind, reinforcement learning, HR practice and control questions — will find a full episode on the Risk Radar podcast (episode 19). This article stands alone; the episode is supplement, not source.

Dr Marie Ossenkopf — PhD in computer science (cooperative AI agents), startup coach, ConKind co-founder:

Transparency note: This article was created with the assistance of artificial intelligence and subsequently reviewed editorially.

This text was created with AI assistance and editorially reviewed.

Risk Radar Podcast

🎧 Watch the full podcast episode here:

Watch on

Frequently asked questions

Is AI for business more opportunity or threat?

Both. Rollback is unrealistic — what matters is whether you run AI as a tool with clear accountability or delegate responsibility to systems that neither judge nor bear consequences.

What is the biggest mistake when deploying AI agents?

Automating processes you do not understand — and accepting outputs nobody owns. Text gets faster; decisions get slower.

What is prompt injection in plain terms?

Hidden instructions in emails, PDFs or images can trigger unwanted agent actions — from data leaks to stolen API keys. An operational risk, not a pure IT topic.

Should I use AI agents for HR or email?

Only with explicit human final decisions, access limits and review points. Screening without judgment admits the wrong profiles and filters out the right people — often invisibly.

Can I ignore AI as a founder?

Ignoring it is still a strategic choice. You may fall behind on innovation speed — reckless use creates privacy, reputation and costly decision failures.

How do useful and risky AI use differ?

Useful where AI sorts information and prepares decisions — risky where final calls, customer contact or data access go to agents without management.

What does practice recommend for getting started?

Understand the process, involve stakeholders, avoid FOMO, and manage AI like motivated interns — prep work yes, accountability human.

Clarify risks in your business?

Book a free intro call – 30 minutes, no obligation.

Book a free intro call