Identifying AI Risks

AI Literacy: A Legal Mandate

Under the EU AI Act (Article 4), maintaining AI literacy is no longer just a best practice—it is a legal requirement for all employees as of February 2025.

With full enforcement and significant penalties beginning in August 2026, understanding AI risks is essential for your individual accountability and our company's compliance.

To use AI responsibly in our daily work, we must first understand the legal landscape that governs it. Since February 2025, the EU AI Act has mandated that all staff using AI systems possess a sufficient level of AI literacy. Full enforcement begins in August 2026, making individual accountability a cornerstone of our corporate compliance strategy.

Hallucinations: The 'Confident Error' Risk

AI models are word predictors, not fact-checkers. A hallucination occurs when the AI generates information that sounds plausible but is factually incorrect.

Imagine you are using AI to draft a legal summary or a technical report. The AI might confidently cite a court case or a product specification that simply does not exist. Because the tone is so professional, these 'hallucinations' are easy to miss without active human oversight. Exactly. By clicking to verify against our internal database, we catch the error before it reaches a client. Remember: you are the 'Human-in-the-Loop' responsible for the final output.

Algorithmic Bias in the Workplace

AI learns from historical data, which may contain human prejudices. If left unmonitored, AI can amplify bias in critical decisions like hiring or performance reviews.

Example: An AI screening tool might favor certain demographics because it was trained on skewed historical hiring data.

Consider an AI tool used to screen hundreds of job applications. If the historical data used to train the AI reflects past imbalances, the tool may inadvertently filter out qualified candidates from underrepresented groups. This is why the EU AI Act emphasizes human oversight—to ensure AI-assisted decisions remain fair and non-discriminatory.

Data Privacy: Public vs. Enterprise AI

The most critical area for daily compliance is data privacy. Not all AI tools are equal.

Public AI (e.g., Free ChatGPT)Enterprise AI (Approved)
Data used for training future models.Data is isolated in a "walled garden."
High risk of data leaks.Meets GDPR & Corporate Security standards.

There is a fundamental difference between the AI tools you use at home and those provided by the company. In public AI tools, anything you paste can be used to train future models, meaning your sensitive data could technically 'leak' to other users globally. Conversely, company-approved Enterprise AI keeps our data secure and isolated—never using it for training.

Exercise: Sanitize Your Prompt

Practice the Sanitize workflow. You are about to use a Public AI tool to summarize a meeting note. Identify and remove any sensitive data before hitting submit.

Here is a draft prompt containing a client name and a sensitive project detail. Your task is to rewrite or 'sanitize' this prompt so it is safe to use in a public AI tool. Remove any specific identifiers.

The 'Verify & Sanitize' Workflow

To remain compliant, follow this three-step workflow for every AI interaction:

  1. Sanitize: Remove PII and trade secrets.
  2. Verify: Fact-check every output.
  3. Own: Take responsibility for the final result.

Compliance is a daily habit. First, sanitize your data by stripping out sensitive identifiers. Second, verify the AI's output against a trusted source—never take its word for granted. Finally, remember that you 'own' the result. As the human-in-the-loop, you are ultimately responsible for the work you submit.