
Nearly $893 million in reported losses were tied to cybercrime complaints categorized as AI-related.
AI risk, however, is not limited to cybercrime. Employees now use AI to draft emails, summarize documents, review information, and support everyday operations. Issues begin when employees accept that output without enough review or enter sensitive information into the wrong tool.
The risks of AI in business include inaccurate decisions, data exposure, weak accountability, and loss of control over how AI tools interact with company information and systems.
As more New York City businesses use these systems, oversight becomes increasingly important where confidential client, financial, or employee information is involved.
The goal is to gain the benefits of AI while keeping people in control of important decisions, sensitive data, and business processes.
This blog explores human oversight, AI data security, output validation, IT governance, monitoring, and incident response.
When Does Productive AI Use Become Over-Reliance?
AI can assist with research, document summaries, administrative work, and early drafts while employees remain responsible for the work.
Over-reliance begins when that support starts replacing checks, approval, or independent judgment.
Common warning signs include:
-
Employees accept answers without checking them.
-
Customer-facing content is released without approval.
-
Sensitive information is entered without authorization.
-
Important decisions rely on recommendations employees cannot explain.
-
Essential work stops when an AI platform is unavailable.
At that point, responsible AI use requires defined limits, clear ownership, and fallback procedures for critical work.
What Can Go Wrong When AI Outputs Are Accepted Without Review?

AI-generated information can create problems when employees treat ’it as reliable without checking the source, context, or business consequence.
The effects may include inaccurate work, poor decisions, exposure of sensitive information, and misuse of protected material.
Hallucinations & Inaccurate Information
Generative AI can produce false or unsupported information that appears credible. NIST calls this confabulation, which can include fabricated facts, faulty logic, incorrect dates, or false citations.
In business, that may appear as an incorrect figure in a financial summary, a missing clause in a contract summary, an unsupported research conclusion, or code that fails in production.
|
A well-known example came from the Southern District of New York in Mata v. Avianca. Attorneys submitted court filings containing nonexistent cases and fabricated quotations produced by ChatGPT. The court imposed a $5,000 sanction on the attorneys and their firm. |
Detailed explanations, formatting, and references can make incorrect information look authoritative, which makes independent checking especially important.
Automation Bias
Frequent exposure to useful AI responses can make employees less likely to question later results. NIST describes automation bias as excessive deference to automated systems and notes that users may rate generative AI content more highly than information from other sources.
The risk grows when AI recommendations influence hiring, security, financial, client, or operational decisions simply because the output appears confident or objective.
|
In New York City, certain automated employment decision tools used for hiring or promotion require a recent bias audit and specified notices before use. The rule reflects the additional scrutiny applied when automated recommendations affect employment decisions. |
Confidentiality & Data-Security Risks
AI use also creates exposure when employees enter sensitive information into personal accounts, public tools, or unapproved services.
Client information, financial records, employee data, credentials, internal documents, or contract-controlled information may leave normal company controls once submitted.
Connected AI assistants can create additional exposure if they receive broader access to email, cloud storage, shared drives, or other systems than the task requires.
For example, an employee may paste a confidential client document into a public AI service to create a summary without knowing how that service stores or uses the submitted information.
Intellectual Property Concerns
Protected company or client material creates a separate issue. Employees may upload proprietary source code, internal methods, research, product information, or licensed content without first checking whether the AI service is approved for that material.
AI-generated text, code, images, and other content can also raise questions about copyright, ownership, licensing, and permitted reuse before publication or commercial use.
The U.S. Copyright Office has addressed this issue in registration decisions, finding that AI-generated material without sufficient human authorship is not eligible for copyright protection.
Why AI-Assisted Work Still Requires Human Review?
Human oversight in AI means an authorized employee reviews and approves AI-assisted work before it affects a business decision, reaches a client, or becomes part of a sensitive process.
The level of review should reflect the consequence of an error. A routine internal draft needs less scrutiny than a contract or policy summary, a financial calculation, an employment decision, a security recommendation, client communication, or work involving confidential or regulated information.
Review should go further than a quick approval. The reviewer should assess the output's accuracy, context, and business impact and have the expertise and authority to question, correct, or reject it.
Higher-impact work should follow a defined validation and approval process before use.
AI can assist with the task, but the person or team authorized to approve the work remains responsible for the final decision.
How Should Businesses Control AI Tools, Access & Sensitive Data?

IT governance for AI defines which tools employees may use, what information they may enter, who can access them, and which business systems those tools can connect to.
Businesses should maintain an approved list of AI platforms and define the permitted use for each one. The approval should specify the account type, authorized users, restricted data, and allowed integrations.
Set Access & Security Controls
Approved AI tools should use company-managed accounts wherever possible. IT should apply:
-
Multifactor authentication
-
Role-based permissions
-
User provisioning and account removal
-
Restricted access to sensitive information
-
Approved third-party integrations
-
Retention and logging settings
Access should match the employee’s role and business task, not provide broader permissions than required.
Set Rules for Sensitive Business Data
Employees should know what information is permitted in each approved AI platform and what must stay out.
Rules should address client information, employee records, financial data, credentials, proprietary material, and contract-controlled information. Review vendor privacy practices and data-retention terms before allowing sensitive information.
Assign Ownership for AI Governance
Leadership should define who approves new AI tools and permitted business uses. IT should manage account configuration, access, integrations, and technical reviews.
Reassess existing platforms when vendors change features, permissions, or data-handling terms. Send questions about copyright, licensing, ownership, contractual obligations, or regulatory interpretation to qualified legal counsel.
What Should an AI Output Validation Workflow Include?

An AI output validation workflow gives employees a clear process for checking AI-generated information before using it in business work. The process should address both the information submitted to the tool and the output it produces.
Classify the Task
Start by identifying how you will use the AI-generated output. Work involving customers, finances, employees, security, confidential information, or important operations should receive more scrutiny than a routine internal draft.
Classification also determines whether you need additional approval or specialist review.
Review the Input
Before submitting information, confirm that the data is approved for the AI platform and intended use.
Employees should check whether the prompt, uploaded document, or connected data contains confidential, restricted, or regulated information. If the platform is not approved to handle that information, do not submit it.
Verify the Details
Check factual claims against reliable records rather than relying on the AI response itself.
Confirm names, dates, calculations, statistics, quotations, and cited sources against company systems, original documents, or authoritative external sources.
Recalculate important figures where necessary.
Check the Context
An answer may be factually correct but still wrong for the specific business situation.
Review whether the output reflects the company’s actual policies, customer requirements, contractual terms, operating procedures, and circumstances.
Generic recommendations should not replace company-specific requirements.
Assign the Reviewer
Send higher-impact or specialized work to someone with the knowledge and authority to evaluate it properly.
For example, financial analysis may require finance review, employment-related material may require an authorized HR reviewer, and security recommendations should be assessed by the appropriate technical personnel.
Record the Outcome
Some AI-assisted work requires a record of what was reviewed, corrected, or approved.
Document significant changes, approvals, and recurring errors when they affect an important business process or when company policy requires evidence of review.
Repeated problems may also indicate that a prompt, workflow, or approved use needs adjustment.
Maintain a Fallback
Essential work should not depend entirely on one AI platform’s availability or reliability.
Businesses should maintain an alternative process for critical tasks so employees know how to continue if the service is unavailable, produces unreliable results, or must be suspended because of a security or data-handling issue.
What Happens If an AI Tool Exposes Data or Causes an Operational Error?
AI-related incidents require a clear escalation process so employees know what to report and what to do.
-
Know What Requires Escalation: Confidential data entered into an unauthorized platform, incorrect AI-generated information sent to a customer, suspicious account activity, unauthorized integrations, or inaccurate recommendations affecting financial or operational decisions should trigger the response process.
-
Stop Further Use: Stop using or distributing the affected output and disable the relevant account or integration when necessary.
-
Notify the Right Contact: Inform the designated manager, IT team, or managed service provider. Employees should know these contacts before an incident occurs.
-
Preserve Evidence: Keep relevant prompts, files, account details, and activity logs for investigation.
-
Assess the Impact: Determine which information, systems, users, customers, or business processes were affected.
-
Escalate Specialist Concerns: Refer legal, privacy, contractual, or regulatory issues to qualified advisers.
-
Address the Cause: Update policies, training, permissions, integrations, or other technical controls where needed to reduce the likelihood of recurrence.
How Can a Managed Service Provider Support Safer AI Use?
AI policies still need technical follow-through. A managed service provider helps keep accounts, permissions, integrations, monitoring, and security controls aligned with the standards the business has already set.
An MSP can support that work through:
-
Unauthorized-use Reviews: Identify unapproved AI applications, personal accounts, or unmanaged tools being used for company work.
-
Access Oversight: Review user permissions, connected applications, administrative access, and integrations for unnecessary exposure.
-
Identity Protection: Apply and maintain account-security controls such as MFA, access restrictions, and user account administration.
-
Security Monitoring: Review available system activity for suspicious access, unexpected changes, or other issues that require investigation.
-
Policy Support: Reinforce data-handling requirements through technical controls, documentation, and employee security training.
-
Governance Records: Maintain current records of approved tools, access requirements, review procedures, and escalation contacts.
-
Control Updates: Adjust configurations and access requirements as AI products add features or the business approves new uses.
iTeam Technology helps businesses apply AI governance requirements through its managed IT services, including access administration, security monitoring, configuration review, documentation, and ongoing technical support.
iTeam supports the IT, security, and governance controls around AI use. Refer legal, licensing, and regulatory matters to qualified counsel, and note that AI platform development is outside its scope.
Review Your AI Governance & Risk Controls with iTeams

AI governance works best when company policies are backed by the right access, security, monitoring, and response controls.
iTeam Technology brings more than 25 years of experience serving businesses in Manhattan and across New York City, including professional services firms. Its technical team helps put company AI requirements into practice through ongoing IT management and security oversight.
Frequently Asked Questions (FAQs)
1. What are the main risks of AI in business?
The main risks include inaccurate output, automation bias, exposure of confidential information, intellectual property concerns, unauthorized access, and weak oversight. Risk increases when employees rely on AI without appropriate review, access controls, or data-handling rules.
2. What does human-in-the-loop mean in an AI workflow?
Human-in-the-loop means an authorized employee reviews AI-assisted work before using it in a decision, sharing it with another person, or applying it to a business process. The reviewer checks the output and can correct or reject it.
3. What information should employees avoid entering into AI tools?
Employees should avoid entering confidential client information, employee records, credentials, financial data, proprietary material, or contract-restricted information into tools that are not approved for that data.
4. What should an AI governance policy include?
An AI governance policy should define approved tools, permitted uses, restricted data, account and access requirements, review procedures, authorized integrations, escalation contacts, and who approves or reassesses AI platforms.
5. How can a managed IT provider help reduce AI-related security risks?
A managed IT provider can help manage accounts, permissions, integrations, security controls, monitoring, and technical documentation. It can also identify unmanaged tools and review access or configuration changes as business AI use expands.
