Generative AI considered an emerging risk

Generative AI considered an emerging risk

Enterprise risk executives said that generative AI – such as ChatGPT and Google Bard – were a top concern, according to a recent survey by the analyst Gartner. “Generative AI was the second most-frequently named risk in our second quarter survey, appearing in the top 10 for the first time,” said Ran Xu director, research in…

Enterprise risk executives said that generative AI – such as ChatGPT and Google Bard – were a top concern, according to a recent survey by the analyst Gartner.

“Generative AI was the second most-frequently named risk in our second quarter survey, appearing in the top 10 for the first time,” said Ran Xu director, research in the Gartner Risk & Audit Practice. “This reflects both the rapid growth of public awareness and usage of generative AI tools, as well as the breadth of potential use cases, and therefore potential risks, that these tools engender.”

Areas of concern

From an enterprise risk perspective, the survey identified three core areas of concern: intellectual property, data privacy and cybersecurity.

“Information entered into a generative AI tool can become part of its training set, meaning that sensitive or confidential information could end up in outputs for other users,” said Xu. “Moreover, using outputs from these tools could well end up inadvertently infringing the intellectual property rights of others who have used it.”

In addition, generative AI tools may share user information with third parties, such as vendors or service providers, without prior notice. This has the potential to violate privacy law in many jurisdictions. For example, regulation has already been implemented in China and the EU, with proposed regulations emerging in USA, Canada, India and UK among others, the report said.

“We’ve seen examples of malware and ransomware code that generative AI has been tricked into producing, as well as ‘prompt injections’ attacks that can trick these tools into giving away information they should not. This is leading to the industrialization of advanced phishing attacks,” the report said.

Top priority

A survey earlier this year showed that 67 per cent of IT leaders intend to prioritise generative AI for their business – one third said it was their top priority. 

An article in the Harvard Business Review said that the development of generative AI should be based on sound ethical principles. Those included accuracy, safety, honesty, empowerment and sustainability.





← Previous

New pandemic risk a reality
Another pandemic and disrupted energy supplies ranked as two of the most significant risks to…






Next →

Whitepaper: Mitigating risk with SAI360’s GRC investment guide
In this GRC Investment Guide, SAI360 breakdown how a technological approach is no longer just…

9 SEPTEMBER 2026

Owning your space: confidence, visibility & voice

This event marks the formal public launch of the IRM Women in Risk Special Interest Group. The session is themed around the most pressing personal and professional challenges identified by women in the risk profession today.

Find out more

10 SEPTEMBER 2026

Beyond compliance

Managing equity compensation risk through automation, governance and the unified equity compensation risk & automation framework (UECRAF).

Find out more

17 SEPTEMBER 2026

Building an effective risk culture in your organisation

The proactive cultivation of an effective risk culture can serve as a strategic differentiator, enhancing the organisation’s resilience, agility, and reputation in the eyes of customers, investors, and regulators alike.

Find out more

Advertisement