Share this:
Why 84% of Enterprises Fear AI Risk
(And Why the Biggest Risks Aren’t Always What Executives Think)
AI adoption is accelerating, but many organizations are discovering that the biggest risks have less to do with the technology itself and more to do with how information, decisions, and work are managed. Drawing on his experience helping enterprise leaders implement AI, GuruOps Founder, Saquib Kothawala, explores why organizational readiness is the foundation of successful AI adoption and what leaders should focus on before scaling AI.
I’ve been spending a lot of time talking with executive teams about AI, and the conversations are surprisingly similar. Some organizations are worried they’re moving too quickly. Others are worried they’re falling behind. Almost everyone is trying to figure out how to take advantage of AI without introducing unnecessary risk.
That’s not surprising. Recent research from TechRadar found that 84% of enterprise leaders are concerned about AI-related risks, from security and compliance to governance, privacy, and reputational impact. Those concerns are real, and they’re worth taking seriously.
What I’ve found interesting, though, is that many of these conversations start by asking whether AI is ready for business. After working with organizations that are moving AI from experimentation into production, I think the more important question is whether the business is ready for AI.
Those are two very different things.
Most organizations tend to focus on the technology itself:
- Is the model secure?
- Will the model produce accurate results?
- How can we truly trust the output?
- Are we exposing sensitive company information?
These questions matter, but they also assume that the biggest source of risk is the AI. In my experience, that’s rarely what slows organizations down. More often, AI exposes issues that were already there:
- Knowledge is fragmented across documents, spreadsheets, CRM systems, email, messaging platforms, and the experience of long-tenured employees.
- Different teams define the same information differently.
- No one clearly owns the data or the workflow AI is expected to support.
- Processes have evolved over time, but the documentation hasn’t kept up.
People learn to work around these challenges. They know which spreadsheet everyone trusts. They know who has the latest information. They know when the documented process isn’t the one the business actually follows.
AI doesn’t automatically have that context. It depends entirely on the quality and organization of the knowledge it’s given access to.
That’s why so many AI initiatives become organizational challenges rather than technical ones.
AI Doesn’t Create Most Problems. It Reveals Them.
One of the first things I expect to find when I start working with a new client is a lack of data governance. Organizations often don’t have a clear understanding of what data they own, where it lives, who maintains it, or how much of it can actually be trusted.
This isn’t a new problem. It was true fifteen years ago, and it’s still true today.
Think about how many times you’ve heard someone say, “Don’t use that spreadsheet. Terry has the current version,” or “The process says to do this, but here’s how we actually handle it.”
Those kinds of workarounds have been quietly slowing organizations down for years. AI is forcing organizations to address them instead of working around them.
It could be something as simple as onboarding a new customer, approving an invoice, or escalating a support issue to a manager. The documented process might say one thing, but the actual people doing the work every day often know about workarounds, exceptions and unwritten “rules” that never made it into a team’s process documentation.
Humans are remarkably good at navigating that chaos. AI isn’t. It works with the information it’s given and if that information is incomplete, inconsistent, or disconnected, the output will reveal it.
“Most organizations think they’re preparing for AI by evaluating models, platforms, and vendors. In reality, many aren’t ready because they haven’t solved a more fundamental problem: they don’t know where their knowledge lives.”
— Saquib Kothawala, Founder, GuruOps
The Risk of Building AI on Unreliable Knowledge
AI is only as useful as the information it has access to. It needs information that is reliable, connected, and current. The challenge is that many organizations still rely on disconnected systems, duplicate records, inconsistent definitions, and years of institutional knowledge that exists only in the heads of tenured employees.
That’s why I often talk about building a reliable knowledge layer. Not because AI needs more information, just better information.
Think about a new employee on their first day. They can only make good decisions if they’re given accurate information and shown how the business actually works.
AI is no different – it can only work with the information it’s given. It needs access to knowledge that reflects the way the business operates today, not the way it looked when someone last updated the documentation. That’s the real risk.
Governance Reduces Risk by Creating Clarity
I think governance is often misunderstood. People hear the word and immediately think slower decisions and more bureaucracy. In reality, good governance gives people clarity. They know which tools they’re allowed to use, what information can be shared, when human review is needed, and who is accountable if something goes wrong.
At GuruOps, governance isn’t something we treat as a separate policy exercise. We think about it alongside the business objective, the data being used, the AI workflow being built, and the risks that need to be managed.
That starts by clarifying the use case.
- What decision or workflow is AI supporting?
- Who will use the output?
- Will it affect customers, employees, financial decisions, operational decisions, or simply improve internal productivity?
From there, we work backward.
- What information does the system actually need?
- Is that data reliable?
- Who owns it?
- What quality issues need to be addressed?
- What level of access should the AI have?
Not every AI system requires the same level of governance. An AI assistant that helps employees summarize meeting notes carries very different risks than one approving insurance claims or responding directly to customers. Treating every AI use case the same often leads to either unnecessary bureaucracy or unnecessary risk.
The goal is to apply the right amount of governance for the level of risk involved. Instead of remaining a policy document that sits on a shelf, governance becomes part of the delivery process. Every decision about what to build, what to restrict, what to test, what to monitor, and who is accountable is informed by the level of risk the AI system introduces.
The Nature of AI Risk Is Changing
Today, many organizations still think of AI as a tool that creates and processes content – it can write emails, summarize a meeting, or draft a report. That’s changing. The next phase of AI is all about action — how work gets done.
As organizations begin trusting AI to take action, governance, testing, monitoring, and human oversight will become significantly more important. We’re already seeing AI draft customer responses, route support tickets, trigger workflows, recommend purchases, schedule appointments, and approve routine requests. Automated actions like this becomes less about whether AI can perform a task and more about whether it should.
Waiting Has Risks Too
Some executives tell me they’re waiting until AI becomes safer, and while I certainly understand that instinct, waiting is still a strategy, and every strategy has its trade-offs.
The organizations investing today aren’t just experimenting with models. They’re developing internal talent and improving their data inputs. They’re building governance by learning where AI creates value and where it doesn’t.
All of this takes time to build and test, and even a company that starts today may not see immediate results. On the other hand, a company that waits, may eventually realize that it can’t build those capabilities quickly enough to keep pace with competitors that have been learning all along.
The goal is to increase organizational capacity at a pace that makes sense for your business, not just because everyone else is using AI.
The Most Important Question
One question I don’t think gets asked often enough is, who is this AI actually meant to help?
For all the conversations about models, prompts, infrastructure, and governance, it’s easy to lose sight of that.
Every AI system exists to support someone. If your AI is helping employees find information faster, that’s one set of design decisions. If it’s helping customer service representatives respond more consistently, that’s another. If it’s approving financial transactions, the expectations around governance and oversight change completely.
That’s why the first question isn’t, “What can AI do?” It’s, “Who is this AI meant to help?”
If you can’t clearly answer who the AI is serving, it’s going to be difficult to create meaningful value, no matter how capable the technology becomes.
Managing AI Risk Starts With Understanding Your Business
Every organization is going to approach AI differently because every organization has different goals, different limitations, and different ways of working. That’s why there isn’t a single roadmap.
In the end, the organizations that get the most from AI won’t necessarily be the ones using the newest tools. They’ll be the ones that understand their own business well enough to know where AI can genuinely help.
The conversations we have with leadership teams are rarely about choosing a model. They’re usually about understanding the business well enough to know where AI can actually make a difference. If your organization is working through those same questions, we’d be happy to have that conversation with you. Contact GuruOps.

