Euphoria meets reality
Artificial intelligence is no longer merely an IT issue, but a strategic success factor. Many companies are currently rolling out generative AI at a rapid pace. However, the associated risks are often only considered superficially.
The term «AI risk» encompasses a range of challenges. When asked what this specifically entails, the initial focus is often on cyber-attacks and hallucinations. This can present a strategic challenge for companies. After all, risks that are not clearly identified cannot be prioritised, delegated or budgeted for appropriately.
IBM’s ‘Cost of a Data Breach Report 2025’ illustrates the extent to which actual usage is, in some cases, ahead of management’s awareness. In one in five of the companies surveyed that had suffered a data breach, ‘shadow AI’ played a role. This refers to the use of AI without the employer’s knowledge or authorisation. 63 per cent of the affected companies had no policy on AI governance.
Consequently, usage often begins not only after official authorisation, but directly in the browser. This makes it more difficult for companies to maintain an overview of data flows and the basis for decision-making. Management is therefore increasingly faced with the question of how to ensure that AI usage is controlled and structured.
Category 1: Data risk – what is being input?
The most immediate risk arises where employees feed information into AI tools. This includes, for example, documents, emails, customer data or source code. Depending on the service and configuration, this data may be stored externally, processed in other jurisdictions or used to train future models.
As a result, confidential information may leave the company’s control without a traditional security incident occurring or the disclosure having been deliberately authorised.
Just how real this risk is was demonstrated in March 2025 by a case in Australia. An external contractor uploaded an Excel spreadsheet containing over 12,000 rows to ChatGPT. This contained the names, addresses and, in some cases, health information of flood victims. The personal data of 2,031 individuals was demonstrably exposed.
This was neither an attack nor the result of malware. An employee simply used a tool that had not been authorised. The underlying pattern can be applied to many organisations: protective mechanisms built up over years are not breached, but circumvented.
For example, a customer list that would not be sent by email to external parties can still be entered into a chat window. It may be less obvious that sensitive information can leave the company in this way.
At the same time, the volume is increasing. According to Cyberhaven’s ‘AI Adoption and Risk Report 2025’, a good third of the data that employees enter into AI tools is now classified as sensitive. This trend is on the rise.
Category 2: Output risk – hallucinations
AI systems can provide answers that are formulated in a coherent and convincing manner, regardless of whether the information they contain is correct. For example, a model may invent sources, distort calculations, generate biased recommendations or suggest code containing security vulnerabilities.
The risk therefore lies not only in the technology itself, but also in how its results are handled. People may trust the output because it is competently worded, and base real-world decisions on it.
The case of Deloitte Australia in October 2025 demonstrated that even leading companies can be affected by this. A 237-page report for the Australian Government contained AI-generated errors, fabricated study references and a made-up quotation from a Federal Court judgement. Deloitte was forced to refund the final instalment of its fee of 440,000 Australian dollars. This was compounded by the resulting damage to its reputation.
The judiciary is also increasingly addressing this issue. In 2025, the English High Court made it clear in its landmark ruling on the Ayinde and Al-Haroun cases that lawyers are liable for unverified AI output. In one of the cases, 18 of the 45 cited judgements were fabricated. Worldwide, several hundred court cases involving AI hallucinations had been documented by early 2026.
Lloyd’s of London demonstrates that the market also takes this risk seriously. From 2025, it will offer insurance products specifically designed to cover losses arising from AI hallucinations.
For senior management, this leads to a key insight: companies must therefore ensure that AI-generated content is properly checked before it is used. The output risk is therefore primarily a matter of process. It must be clearly defined where AI results may be used directly and where human verification is required.
Category 3: Compliance risk – what the law requires
Compliance risks relating to AI are already a reality. The EU AI Act is coming into force in stages. The prohibitions on unlawful practices have been in force since February 2025 and are enforceable by fines of up to 35 million euros or seven per cent of global turnover.
The obligations for providers of large AI models will take effect from August 2025. From 2 August 2026, the European Commission will be able to impose fines of up to 15 million euros or three per cent of turnover in this area. Although no fines had been imposed by the time of going to press, enforcement of the requirements has already begun.
For Swiss companies, the scope of the regulations is particularly relevant. Market exposure is the decisive factor, not the location of the server.
Switzerland is deliberately pursuing a more streamlined approach. In February 2025, the Federal Council decided against introducing its own AI law and is instead relying on the Council of Europe’s AI Convention, as well as targeted sector-specific adjustments.
However, this does not mean that AI is used in Switzerland in a legal vacuum. In 2025, the Federal Data Protection Commissioner reaffirmed that the revised Data Protection Act is directly applicable to AI-supported data processing. In cases involving high risks, this also includes the obligation to carry out a data protection impact assessment.
The challenge in this category is that non-compliance can arise simply by using AI without systematically checking that its specific application complies with the applicable requirements.
Category 4: Risk of attack – AI against one’s own company
Whilst the first three categories arise from a company’s own use of AI, the fourth stems from external sources.
Just how immediate this risk can be was demonstrated in January 2026 by a case in the canton of Schwyz. According to reports by SRF, a business owner transferred several million Swiss francs to Asia. This was preceded by a series of telephone calls over a two-week period, during which fraudsters used an AI-cloned voice to impersonate a trusted business partner. The case is currently under investigation.
This example is indicative of a broader trend. According to the security firm Hoxhunt, the proportion of AI-generated phishing attacks rose from 4 per cent to 56 per cent between November and December 2025. In 2025, the Federal Bureau of Investigation (FBI) classified AI-enabled fraud as a separate category for the first time. In the US alone, losses of almost 900 million US dollars were reported.
Defences rely less on AI-specific technology alone and more on tried-and-tested security practices, which must be adapted to the new nature of these attacks. These include awareness-raising measures to prepare staff for deceptively realistic messages and voices, robust approval processes, and detection systems that keep pace with the speed of the attacks.

What you can specifically conclude from this
The benefit of the four categories is that each category requires different responsibilities and different measures.
Data risks are addressed through governance, clear rules of use and approved tools. For output risks, the focus is on defined processes and checkpoints. Compliance risks require an inventory of existing AI usage and a clear allocation of the relevant obligations. Attack risks must be taken into account, particularly in the areas of security operations and awareness.
Four questions can therefore serve as a self-assessment for the next executive board meeting:
– Do we know which AI tools are being used with which data?
– Where is AI output being incorporated into decisions or customer communications without being checked?
– Have we ensured that our use of AI complies with the EU AI Act and data protection legislation?
– Do our approval processes also account for AI-generated impersonations, such as a cloned voice?
Questions that cannot yet be answered definitively may indicate a need for action or responsibilities that still need to be clarified.
Conclusion and Outlook
Breaking the concept down into four areas transforms the general term ‘AI risk’ into specific, actionable work packages with clear lines of responsibility. Companies that manage this issue successfully do not necessarily have the most sophisticated technology at their disposal. What is crucial, rather, is that they identify and assess risks across the four categories and plan appropriate mitigation measures.
Looking ahead, it is clear that the need for action is set to increase further. The high-risk obligations under the EU AI Act will be phased in until the end of 2027. At the same time, ISO/IEC 42001 is establishing a certifiable standard for AI management systems.
Furthermore, as AI agents operate with increasing autonomy, a new area of vulnerability is emerging. As early as 2025, the first vulnerabilities were documented, in which a single specially crafted email was able to extract data from an AI assistant without it being noticed.
Architecture & Consequently, the central question is also evolving: from «Who uses which tool?» to «Which systems act autonomously on our behalf?».
Those who take stock of the four categories today will lay the foundations for developing their own governance in a targeted and structured manner.
How Axians can help
The biggest challenge is often not a lack of expertise, but a lack of transparency regarding the actual use of AI within the organisation.
Axians supports companies in increasing the visibility of their AI usage, assigning risks to the appropriate decision-makers and establishing a governance framework that works effectively in day-to-day operations. This can take the form of a consultancy engagement, a workshop or a part-time Chief Information Security Officer (CISO) as a Service role.
We start with a free 30-minute consultation, during which we work together to assess your current situation.
LAZAR JOVANOV
Information Security Consultant, Axians BNC AG