Skip to main content
Module 1: Why Governance, and the Frameworks

The AI risk landscape

A structured map of what can actually go wrong with organizational AI.

To govern AI you need a clear picture of what can go wrong. The risks fall into recognizable categories — this map is what your policies, approvals, and oversight will target.

Data risks. Sensitive data (customer PII, health or financial records, IP, source code, secrets) leaking into AI tools that retain or train on it. This is the most common and immediate risk — the shadow-AI and data-leakage problems from the last lesson. Consumer AI tiers are the usual culprit.

Output risks. The AI produces something harmful: a hallucination (confident falsehood) that reaches a customer or informs a bad decision; biased output in a consequential context (hiring, lending); or content that violates policy or law. Remember Air Canada — you're accountable for what your AI outputs.

Security risks. AI as a new attack surface: prompt injection (malicious instructions hidden in content the AI reads), especially dangerous for agents that can act; compromised AI tools or connectors; and AI-generated code introducing vulnerabilities.

Agentic risks. Autonomous agents amplify everything: they take real actions, chain steps before anyone intervenes, hold credentials, and can act on injected instructions. An agent's mistake or compromise can be irreversible and fast (the deleted-database incident). This is a distinct, growing risk class (Module 3).

Compliance and legal risks. Violating regulations (the EU AI Act, sector rules, privacy law), failing to meet contractual data obligations, or being unable to prove how an AI decision was made when a regulator or court asks.

Third-party risks. The AI vendors and connectors you rely on — their data practices, security, and reliability become your exposure (Module 4).

Operational and reputational risks. Over-reliance, skill erosion, and public embarrassment when AI goes wrong visibly.

Two things to notice. First, these risks compound with autonomy and access — a chatbot answering questions is lower-risk than an agent with credentials taking actions on live systems. Your governance should be proportionate: heavier controls where the risk is higher, lighter where it's low (Module 3's risk assessment). Second, most of these risks are manageable with the practices in this course — policy, data classification, tool vetting, oversight, and auditing each target specific risks here. Governance isn't about eliminating risk (impossible) or avoiding AI (self-defeating); it's about knowing your risks and putting proportionate controls on each. This map is the target; the rest of the course is the controls.

Try it

For your organization, rank these risk categories by how exposed you are right now. The top two or three are where your governance effort should start.

Stay in the loop

Enjoying the free lessons? Get an email when we publish new courses and updates — no spam, unsubscribe anytime.

Discussion (0)

Ask a question or share what worked for you. Comments are reviewed before they appear.

Log in to join the discussion and ask questions about this lesson.

No comments yet. Be the first to start the discussion!