Governance OF AI: AI Risk, Explained Simply

In the first article in this series, we drew a line between two conversations that often get collapsed into one: governance OF AI (overseeing how your organisation uses AI) and governance WITH AI (using AI to make the board's own work better). This article focuses on the first conversation, identifying some of the major areas of risk.

AI risk is a handful of distinct, ordinary risks that show up together whenever AI is involved. None require a technical background to understand, and none require the organisation to have a formal AI strategy before they become the board's problem. As established in the first article, if AI is already embedded in HR, finance, or customer-facing systems, these risks are already alive.

Here are the five worth knowing:

  1. Bias

AI systems learn patterns from the data they are trained on. If that data reflects historical inequities, the system can reproduce or amplify them, often without anyone intending it to. A résumé-screening tool trained on ten years of hiring data will learn whatever patterns were in that data, including ones the organisation would never endorse if stated outright. A lending or credit-risk model can end up systematically disadvantaging a group of applicants, even if it was not trained to discriminate against protected characteristics directly, because other data points can act as proxies for those characteristics.

  1. Privacy

AI systems are hungry for data,  the more data a model has, the better it tends to perform. That creates a pull toward collecting more data, retaining it longer, and feeding it into systems for purposes beyond what it was originally gathered for. A customer service chatbot that logs full conversation transcripts, or a marketing platform that builds detailed behavioural profiles, can quietly drift into territory that regulators and customers both care about.

In addition to this, employees pasting sensitive company or customer data into a public chatbot to save time is now a routine, everyday privacy exposure, not a hypothetical one.

  1. Regulatory Exposure

The regulatory picture for AI is moving quickly and unevenly, and an organisation doesn't necessarily have to operate in a heavily regulated industry to be exposed. Australia doesn't have a standalone AI Act. Instead, AI use is governed through a patchwork of existing, technology-neutral laws layering on top of one another: the Privacy Act 1988 (Cth), the Australian Consumer Law, anti-discrimination law, employment and workplace-surveillance law, and sector-specific oversight (ASIC and APRA in financial services, the TGA where an AI tool qualifies as a medical device). From 10 December 2026, amendments to the Privacy Act will require organisations to clearly disclose in their privacy policy when a computer program is used to make, or substantially assist in making, decisions that significantly affect an individual's rights or interests. AI doesn't create these obligations, but it does make them easier to breach at scale, faster, and without anyone noticing until an outside party or the OAIC does.

  1. Failure to Identify Inaccurate Information

This risk is less about the technology failing and more about people trusting it too much. Generative AI tools are fluent, confident, and frequently wrong in ways that are hard to catch. A team that leans on AI-generated summaries, forecasts, or drafts without verification can end up making decisions on foundations that look solid but aren't.

This risk grows quietly. It's a gradual erosion of the habit of double-checking, especially once a tool has been right often enough that people stop questioning it.

  1. Reputational Risk

This is the category that ties the others together. A quiet internal AI issue becoming a public one. A biased hiring algorithm, a chatbot that gives a customer bad advice, or a mishandled data set can all become a headline once discovered as the Administrative Review Tribunal's February 2026 ruling on Bunnings' use of facial recognition technology showed. The Tribunal found Bunnings could rely on a privacy exemption to collect facial images without consent, given the scale of theft and violence it was addressing, but still upheld breaches of the transparency and notification principles for failing to properly disclose the technology's use and for failing to conduct a documented risk assessment. The lesson for AI generally: governance and disclosure failures can attract regulatory findings even where the underlying use of the technology is defensible. Reputational risk will occur when any of the first four go unmanaged long enough to surface externally.

What This Means for Oversight

Bias, privacy concerns, regulatory exposure, unreliability, and reputational fallout are risks boards already have some muscle memory of. These oversight questions aren't fundamentally different from the ones boards already ask about other operational risks: Who owns this? How is it being monitored? What would we need to see to know if something had gone wrong? But AI changes their shape and speed.

As noted in article one, this is generally Risk or Audit Committee territory, and it can be treated as an extension of existing risk oversight rather than a brand-new, freestanding category that needs its own separate infrastructure. At some point in the future we will delve into how boards are managing these AI risks.

About the author

Gary Haase

Content Manager at BoardCloud