CTO AI Corner: Have you considered the risks that AI implementations can cause to your business?

Most companies are already leaning heavily on AI. It is in customer-facing web applications, in internal processes, and quietly lurking in dozens of other places. The AI sector moves fast. Fast enough that not all controls can keep up. Not legal controls, not data protection controls, not security controls, and certainly not technical controls. So, what happens when the AI is no longer available? Or when the information you pass to an AI service leaks? These are real risks that should be considered and mitigated.


Building resilience for AI downtime and data security risks

The availability of AI services is nowhere near the .999s we have gotten used to in cloud environments. Minor outages happen often. So far we have avoided long-lasting major incidents, which is nice, but the pace of development suggests that something will eventually break. Move Fast and Break Things, as the saying goes. Do you have a backup plan? Can your critical processes survive a week without your current AI provider? For the most important operations you should at least be able to handle manually what AI normally takes care of. And having alternative AI vendors ready to switch to is not a bad idea either.

And then there is data security. We have already seen some accidental data leaks from vendors. Some small, some embarrassing, all inconvenient. On top of that, these services are a very attractive target for bad actors. Would you enjoy knowing what your competitors' management is strategizing with AI? Or the questions their R&D team is feeding into it? The value of AI data is huge and the potential for leaks is not negligible. So, are you using a controlled AI environment for your sensitive information, or is it sitting in the same pool as everyone else's daily AI chatter?

I am not a fan of fear mongering, so I will not claim disaster is guaranteed if you do nothing. But the risk is real, and mitigation will probably improve your sleep quality. So think about what would happen if your company lost AI for a full week. Or if every AI conversation your personnel had in the last month suddenly became public. If that thought is uncomfortable, it might be time to write or update your AI policy and start the mitigation work.

December 10, 2025
ai-corner
Authors
Tomi Leppälahti
CAIO & CTO
Share

Thinking about AI issues? Leave a message and let's explore together how and where to use AI.

Thank you for your message! We will be in touch soon.
Whoops! Something went wrong with the form submission.