SME note · risk

Common risks

Talking about “AI risks” in the abstract produces a consultancy chapter nobody uses. In an SME the risks we have actually seen fit in five boxes: the model invents, data leaks, the vendor captures you, the team works worse, and the voucher file has no habit behind it.

None are removed entirely. All are cut with design: narrow scope, a human, a citation, a contract, a switch, a number. This article is that list, without a 40-row traffic light.

Hallucination and authority

The model fills gaps with a correct-sounding sentence. The risk is not that it is wrong. It is that it is treated as a source. Control: mandatory citation, “I do not know” allowed, a human on anything irreversible (price, lead time, posting, legal).

In support and on the web the harm is reputation. In billing, money and the tax office. The same model does not carry the same risk in both places. That is why there is no single “autonomy level” for the whole company.

Leaks and too much data

Pasting the spreadsheet, training on the archive, logs you do not control, a free account. Control: inventory, minimisation, processor, no-training in writing, perimeter poster, prompt review at day 14.

The typical incident is not a hacker. It is someone in-house in a hurry. A 30-minute briefing cuts more than a new antivirus.

Dependence and cost

Process knowledge stuck in their UI, price goes up, EU region closes, the connector will not export. Control: process written down outside, an afternoon plan B, exit price asked before you sign.

If only the vendor can explain the flow, the risk has already landed. Even if today’s price is low.

Operational bias (working worse)

The team accepts bad drafts to go faster. Or they stop learning the craft. Or the hero becomes more of a hero with private prompts. Control: accept rate and error metrics (not only speed), champions, review at day 14 and 45, permission to discard.

If customer-facing errors rise, the pilot is at risk even if minutes drop. Speed without quality is another name for a mess.

An empty justification

There is a deliverable on paper and zero use. Programme risk and internal reputation (“AI does not work”). Control: owner, a number at day 30, training on real cases. If there is no number, you cut or you stop. You do not paint it.

How to write the pilot’s risk page

One row per box: risk in a sentence, control, control owner, how you see it works (evidence). Example: “The model invents a lead time → citation + human sends → support champion → weekly review of three tickets.” Five rows. Stop.

If a row has no owner, the control does not exist. If it has no evidence, it is a wish. Colour traffic lights without those two columns are decoration.

Review it on day 14 with the metrics sheet. A risk that has not landed is not a celebration: you check the control is still alive.

Internal reputation risk (“AI does not work here”)

This is the one that is hardest to reverse. It lands when you launch big, fail in public and nobody cuts. Control: a narrow pilot, a number at day 30, permission to stop, and no company-wide announcement on day one.

If that sentence is already in the corridors, the next step is not another motivational workshop. It is a minimum flow that measures. A small, boring win cleans more than a speech.

Review the risk page the same Friday as the metrics. If customer-facing errors rise, hallucination or operational-bias risk is no longer theoretical: you cut autonomy that same day. Waiting for the committee is how a risk becomes an expensive anecdote.

Do not mix the pilot’s risks on the same page as “AI risks in general”. The latter have no owner and no control and exist to scare. The former are cut on Friday. If an advisor hands you only the latter, ask for the former or change advisor.

If you only have time for one control this week, pick the kill switch and the no-paste poster. They cut three of the five boxes at once. The rest of the page can wait fifteen days; those two should not.

Frequently asked questions

Do we need a 20-page risk report?

No. One page with the five boxes, the control and the owner. If a risk will not fit, the scope is big.

Is the biggest risk an open-source model?

Almost never. The biggest risk is the spreadsheet in a chat and nobody in charge. The model licence is a detail.

Can we insure this?

Sometimes there is a cyber policy. It does not replace the switch or the perimeter. Ask the broker; do not assume it in the memo.

Next: mistakes to avoid and minimum security. We will review the risks of the flow you have in mind.

Studio in Barcelona. Part of Clutch Developer. Oriented to Spain’s SME digitalisation programmes. Request an assessment.

Free assessment

Contact