Perkins SmartOps logo Perkins SmartOps logo
Book a free strategy session Book a call
AI Risk · Plain English

AI risk, for businesses that just want to use the stuff safely

Not the killer-robot conversation. The plainer one: is the AI your business has already turned on doing what you think, with your data, and who is accountable when it gets something wrong.

Most of the AI in your business did not arrive as a project. It arrived as a feature. A tick-box in software you already pay for, a licence someone expensed, a note-taker that joined a call. Nobody sat down and decided to take on the risk. It just accumulated.

This is a plain English guide to what that risk actually is, what the rules actually require of you, and a short check you can run this week. I am David Perkins, an IIA-certified internal auditor. For about fifteen years my job was to find where a business was exposed before it found out the hard way. This is that job, pointed at AI.

The shift01

Risk you took on without a meeting

The AI got switched on faster than anyone worked out what it touched.

Ask a business owner what AI they use and you often get a shrug and one answer: ChatGPT, maybe. Then you look properly. The accounting software now categorises invoices with AI. The email client drafts replies. The CRM scores leads. Someone runs meeting notes through a transcription tool that sends the audio to a server you have never heard of. A recruiter screens CVs with a feature the vendor turned on by default.

None of that was a decision. It was a drift. And every one of those points is a place where something can go wrong quietly, which is the worst way for it to go wrong. AI risk is not a future problem you might adopt. For most businesses it is a present position they already hold and have not measured.

Nobody sat down and decided to take on the risk. It just accumulated.
The four families02

The four things that actually go wrong

Strip away the noise and AI risk for a normal business comes down to four families.

01 / Data

Where your information goes

The AI feature reads a client email, a contract, a spreadsheet of staff details. Where does that data travel, who stores it, and is that allowed under your obligations? The ICO is clear that inferences AI makes about people count as personal data too, not just the data you fed in.

02 / Vendor

Who you are really depending on

The tool is only as sound as the company behind it, and often as sound as the company behind that one. Many AI products are a thin layer over someone else's model. If that provider changes terms, raises prices, or disappears, what happens to the work you built on it?

03 / Output

Confidently wrong answers

AI does not know when it is wrong. It produces a fluent, plausible answer either way. The risk is not that it fails loudly. It is that a wrong figure, a misread clause, or an invented fact reaches a customer or a decision before a human catches it.

04 / Accountability

Who owns it when it breaks

When an automated routine sends the wrong thing or a model makes a poor call, who is answerable? If the honest answer is nobody, or the vendor, or we are not sure, that is the risk in its purest form. Accountability does not transfer to software.

Worth saying plainly

Every AI build we do includes a check we call a Judge: a step that validates an AI output before it reaches a person or a customer. Guardrails are not an add-on to worry about later. They are the part that makes AI safe to use at all.

The rules03

What the rules actually are, and who sets them

There is no single UK AI law. The bodies you already answer to are applying the rules you already have to AI, and the bar is rising.

A lot of owners assume there is now an "AI Act" they are quietly breaking. It is worth being precise, because the honest picture is different on each side of the Channel.

In the UK, there is no AI Act. The government has chosen not to pass one big law, and to let existing regulators apply existing rules to AI instead. The only AI-specific bill in Parliament is a private member's bill, Lord Holmes's Artificial Intelligence (Regulation) Bill, which has passed the House of Lords and moved to the Commons but is not yet law, and as a bill without government backing it may not get there. So the obligations that bind you are the ones you already have, on data, on fairness, on treating customers properly. They do not pause because the tool is clever.

In the EU, there is an AI Act, and it is already in force. The EU AI Act is being switched on in stages, and some of the heavier duties on high-risk systems were recently pushed back to December 2027. Its reach mirrors data protection law: it can apply to a UK business if it puts an AI product on the EU market, or if the output of its AI is used by people inside the EU. If neither is you, it is context worth knowing, not a bill you have to pay.

The regulator most UK businesses actually need to think about is the Information Commissioner's Office. Its guidance confirms that automated decision-making rules apply to AI, that a confident but wrong AI output about a person can count as inaccurate personal data, and that the inferences a model draws about people are personal data you are responsible for. Alongside it, the UK government backs AI assurance: the principle that AI should be independently checked to confirm it does what it claims, rather than taken on trust from whoever sold it.

And if you sit anywhere near financial services, the bar is higher again. The Bank of England now treats AI as a financial-stability issue it actively watches, and its joint survey with the Financial Conduct Authority found around three quarters of UK financial firms already using AI. For a finance-adjacent business, an accountancy practice, a broker, a lender, "the software does it" is no longer an answer that ends the conversation with a regulator.

The other half of this AI governance: how you stay in control of it

Risk is what can go wrong. Governance is the light structure you put around AI so those things are caught, owned, and answerable, without turning your business into a compliance department. The two pages are a pair. If risk is the diagnosis, governance is the treatment.

Do it yourself04

Five questions to run this week

This is the shape of an internal audit, compressed to five lines. If you cannot answer one, that is your finding.

  • What AI are we actually running? List every tool and every AI feature switched on inside other software. Most businesses stop at three and find twelve.
  • What data does each one touch, and where does it go? Follow the information out of your building. Client records, staff details, financials. Name the destination.
  • Who owns each tool inside our business? A named person, not a department. If nobody owns it, nobody is watching it.
  • What happens when it gets something wrong? Is there a check before the output reaches a customer, and a way to know it failed? Or does it just go out?
  • Could we prove any of this to a client, an insurer, or a regulator? If the evidence lives only in someone's head, you do not have it.

Run those honestly and you will have a rough map of where you stand. The gaps are not a failing. They are the normal result of AI arriving faster than anyone could keep up with. The point is to see them before someone else does.

Where we come in05

An independent set of eyes

We do not sell you the AI. So we are free to tell you the truth about it.

If the five questions turned up more gaps than answers, that is exactly the work we do. Our AI and Automation Assurance review looks at what you are already running, against evidence rather than opinion, and hands you a report you can act on, take to your board, or use to push back on a vendor. No AI vendor pays us and no commission rides on any finding. The party that sold you the tool is not the party to tell you whether it is safe.

If you are earlier than that, still deciding where AI would even help, the free strategy session is the honest first conversation. Either way, you leave knowing where you stand.