Ask a US employee whether their own employer has rolled out AI. A decent share of them cannot answer, and shadow AI grows in exactly that kind of confusion.
Gallup changed the question because of it. The methodology note says, “Starting in Q3 2025, Gallup added a ‘don’t know’ option to this question to capture uncertainty about AI adoption.” Results from Q3 2025 onward are no longer directly comparable with earlier measurements.
A polling company broke its own time series because too many people had no idea what was happening inside the building they work in.
The second number nobody quotes
As of May 2026, 47% of US employees say their organization has implemented AI. Only 25% say the organization communicated a clear plan.
Every headline takes the first number, but the second one is the story.
Between “we have this thing” and “somebody told me how to use it” sits a gap, and in that gap are contracts, patient records, draft tenders, source code, whatever your people happen to be pasting today.
Shadow AI is the default state of that gap.
Adoption is the wrong argument
There is a long running fight about how many people use AI. Gabriel Weinberg of DuckDuckGo summed up the skeptical side in June 2026 as “one third actively using AI, one third occasionally using AI, and one third never using AI”. He cites Microsoft telemetry putting it at “more than 30 percent of the US working-age population is using AI, an increase of 3 percentage points from the end of 2025”.
Gallup’s workplace numbers run higher. 15% of US employees use AI daily. Weekly or more is 30%, and 52% touch it at least a few times a year.
Pick whichever camp you like, it changes nothing for my job.
Move the user base up or down, the 25% who got a clear plan stays where it is. That fight pulls attention away from the only question that matters, which is who wrote the rulebook and who read it.
Shadow AI is a confidentiality problem with no attacker
Strip the vocabulary and that is all this is.
No phishing mail, no exploit, no command and control, nothing that trips an alert. An employee opens a browser tab and pastes a client document into a chatbot to get a summary. The data leaves the organization. Most of what you bought assumes somebody is trying to break in. Shadow AI walks out the front door during working hours, moved by people who just want to finish faster.
OWASP keeps an entry for sensitive information disclosure in its Top 10 for Large Language Model Applications, and almost all of that guidance assumes an application you built. The tab your sales team opened this morning is nobody’s application.
Scott Brinker named the shape of this back in 2013 and called it Martec’s law. Technology changes exponentially, organizations change logarithmically. Your staff adopted AI in an afternoon, your document set moves at the speed of a committee.
The Gallup manager numbers show the same thing from the other side. 36% strongly agree their manager supports the team using AI. Where that support exists, employees are 1.7x more likely to use AI weekly or more and 8.7x more likely to report a transformational change in how they work. Encouragement travels by conversation and rules travel by document. Shadow AI takes the faster route.
What shadow AI looks like on a Tuesday
Nobody sits down and decides to run shadow AI. It shows up as small, reasonable moves.
A sales rep pastes a signed contract into a chatbot to pull the renewal dates out of it. An HR assistant drops a salary spreadsheet into a chatbot to reformat the columns. A developer sends a stack trace holding a production connection string to a free tier account. A clinic receptionist rewrites a referral letter with the patient name still in it.
None of those people are careless. All of them were told AI makes them faster, and none of them were told where the line sits.
Deleting the client name before pasting does not turn the text into anonymous data either, and I went through the research on that in ChatGPT privacy leak.
Every one of those actions is invisible to the security team, because nothing was breached and nothing alerted.
Low numbers are not safe numbers
Daily use runs at 42% in technology, 27% in finance, 22% in professional services, and 9 to 15% everywhere else.
Read the low end carefully, because a law firm or a clinic sitting in that bottom band is not in a better position. It is a place where a smaller group does the same thing with far more sensitive material, and with less chance that anyone in IT has ever looked at it. Low usage hides shadow AI.
The 65% of employees in AI-implementing organizations who report a positive effect on productivity are not lying either. It works, and that is exactly why nobody is going to stop when you ask them to. A ban moves shadow AI further out of sight.
One page before you buy anything
Do not start with a tool. Start with one page that answers four things.
Which categories of data never go into an external model.
Which tools are approved, listed by name.
Who an employee asks when the answer is not obvious.
What happens when something has already gone in, and who hears about it first.
That page will not cover a regulated environment or replace a contract with the vendor. It covers what is leaking today.
I keep the editable template for it behind my shadow AI risk calculator, so you do not have to start from a blank file.
Then do the boring part and send it to everyone, with one person named as the owner. A rule nobody can find works the same as no rule at all, and that is where shadow AI restarts. It is not fancy work and it does not need a consultant.
One page beats a procurement cycle. If you cannot write it, you do not have an AI program, you have 47% and hope.
So remember, if you write only one line on that page, write this one. Never put anything into an LLM that you would not email to a stranger.
Two hundred seventy-two international AI experts just built an AI risk ranking based on probability instead of guesswork. Most regulators still haven’t managed that in three years.
The study, “Prioritization of Risks From Artificial Intelligence,” comes from MIT FutureTech and the University of Queensland. The paper lists 188 co-authors. Core authorship goes to Peter Slattery, Alexander Saeri, Jess Graham, Michael Noetel and Neil Thompson. They used the Delphi method, a research process that gathers expert judgment over multiple rounds until agreement and disagreement both become visible. The same method shows up in the International AI Safety Report 2026, which cites this same body of work. The underlying data lives in the MIT AI Risk Repository, a running catalog of more than 1,600 documented threats used by policymakers and technologists.
Experts scored 24 risk domains across a five-year horizon, 2025 to 2030, under two scenarios. One scenario assumed business as usual, where organizations and governments keep doing what they’re doing now. The other assumed pragmatic mitigation, where everyone makes cost-effective efforts to reduce harm. Under business as usual, 18 of the 24 domains had at least a 10% probability of catastrophic outcomes. Catastrophic meant more than a million deaths or more than $100 billion in losses, with damage at a comparable civilizational scale in either case. That’s the baseline nobody wanted written down until now. It’s a sharper, numbers-first cut at the risk spectrum this blog already maps.
Why most people are reading this wrong
Most people hear “AI risk” and picture something years out, like rogue models or autonomous weapons in some future conflict. That’s not what this AI risk ranking found. Even under pragmatic mitigation, five domains still cleared 10% probability of catastrophe. Dangerous capabilities and AI-enabled weapons or cyberattacks each sat at 12%. So did environmental harm, a domain most people wouldn’t put anywhere near cybersecurity. Inequality and unemployment came in a point lower at 11%, right alongside power centralization. Two of the five are cybersecurity’s problem, and they didn’t drop much even when everyone tries.
Security work comes down to one job, pushing the attacker’s cost high enough that the attack isn’t worth it anymore. No system stays secure forever, so the alternative just needs to be expensive enough to matter. AI doesn’t invent a new phase of attack. It collapses the cost of the phases that already exist. Reconnaissance gets automated.
Weaponization gets templated, and delivery gets more convincing because a generated phishing email or a cloned voice doesn’t need a skilled operator anymore. It’s the same mechanism behind the AI-enabled cyberattacks already hitting ordinary companies today. As Slattery putand hacking are where AI capability is moving quickest, and that growth shows up on the cost side of the equation more than the probability side.
Competitive pressure works as the mechanism that keeps the other four risks running. When a company or a country believes AI confers an advantage, slowing down for safety just hands that advantage to whoever doesn’t slow down. Nobody wants to be the one who raises their own costs while the competition doesn’t, so the race to the bottom on governance keeps going. It’s the same dynamic that keeps patch cycles too slow and security budgets too small, just running at AI speed instead of IT speed.
Treating this AI risk ranking as a one-time compliance project misreads what the data says. It isn’t something you finish once and file away.
What this means if you’re the one holding the risk
The study also names who’s exposed and who’s responsible, and the two lists don’t overlap. Developers and regulators carry most of the responsibility for addressing these risks. Users and the people affected by AI systems carry most of the exposure. That mismatch is why nobody feels urgency at the right level. The people who could slow the collapse aren’t the ones who’d get hurt by it.
Exposure doesn’t spread evenly. Information absorbs it through misinformation and manipulation, the sort that erodes trust in what people see and read, while national security picks up cyberattacks and weapons development, with surveillance going to whichever hostile actor moves first. Finance isn’t spared either, where fraud and market manipulation get easier and privacy failures ripple into the wider economy on top of that. AI makes doing harm cheaper for anyone who was already capable of it, and possible for people who weren’t.
Slattery framed the findings as a list of what’s worth paying attention to now, drawn from probability rather than certainty. The response belongs in the governance conversation companies already run for cybersecurity and privacy. It needs a place in business continuity planning too, not a separate checkbox with its own deadline.
If you run security for an organization deploying AI, the number that should stick with you about AI risk isn’t 272 experts or 24 categories. It’s that even in the best-case scenario the researchers modeled, cyberattacks and dangerous capabilities didn’t fall out of the top five. Mitigation lowers the odds. It doesn’t remove cybersecurity from the list.
AI agent privacy rarely makes it onto a security checklist, and that gap is where the real damage starts. Picture an agent handling a routine task, checking a customer’s order status, then pulling matching records from across the CRM and the invoicing database before replying, all inside ten seconds. Nobody stopped to ask whether it also picked up another customer’s card number sitting in the same conversation thread, still parked in its working memory.
The problem, stripped down
An LLM agent today operates across databases, document collections pulled through RAG, external APIs, and other agents further down the task chain. Each of those surfaces opens its own leak path for agent data, and each one is a blind spot in most AI agent privacy reviews. The survey traces how sensitive data actually leaves a system. Some of it exits through the queries an agent writes for itself. The rest slips out through intermediate results parked in memory or through messages passed to another agent mid
Most security policies were built to catch one of those paths, leaving the other two wide open. That mismatch is the actual shape of the AI agent privacy problem door while two side entrances stay open.
Why most teams get this wrong
Most agent security reviews start from attack scenarios like prompt injection or a jailbreak attempt slipping past the model. The survey approaches the problem of what data the agent touches in the first place, regardless of whether anyone is attacking it. A team that red-teams its agent against known attacks can still miss the risk sitting inside the data access design itself.
Database-level access control looks like it should cover this, though it only answers a narrower question – who can read a record right now. It says nothing about what the agent does with that record three sessions later. The survey reviews six governance mechanisms built to me, information flow control, and catch-leakage pieced together across multiple sessions. The rest only catch a single request. AI agent privacy actually breaks down at the pattern level, stitched together across sessions, which is precisely what those other five mechanisms miss.
What this means for you
Deploying agents for clients, or running them inside your own company, changes what belongs on your vendor checklist. Jailbreak red-teaming credentials cover only part of that checklist now. The better question covers AI agent privacy across every surface the agent touches at once, RAG retrieval, SQL queries, memory, and messages traded with other agents. The survey’s authors say a combined benchmark like that barely exists yet, and under GDPR and similar rules, that absence becomes a real liability, since proving due diligence gets difficult when the test you ran skips most of the data’s actual path through the system.
The technical bit, plainly
Take a concrete case that shows what AI agent privacy risk looks like in practice. An HR agent answers an employee’s question about vacation days. While retrieving the record, it also pulls a field noting the medical reason behind an earlier absence, sitting right next to the vate result lands in the agent’s memory. Three queries later, a separate thread with the same employee draws on that memory and surfaces a detail nobody asked to reveal.
The failure sits in a missing boundary between what the agent knows and what it’s allowed to say in a given context, a boundary no attacker had to touch. Information flow control tries to draw that boundary at the data layer rather than the prompt layer. It tags sensitivity; the monitor tracks that tag to wherever the data ends up, a chat reply, or a message sent to a second agent. That gap, more than any prompt-based attack, is the everyday face of AI agent privacy failure.
Four questions before you ship an agent
Before an agent touches production data, four questions cut through most of the risk described above.
First, map every data surface the agent can reach, including ones far outside its original purpose, covering every database, document store, API, and memory layer in scope. Second, track data across sessions instead of single requests, checking whether a fact revealed in session one can resurface in session five without anyone approving it.
Third, separate retrieval from disclosure, since an agent repeating that record out loud needs different permissions. Fourth, ask vendors for benchmark coverage rather than a demo, because a system that resists jailbreaks hasn’t shown you anything about its AI agent privacy coverage across RAG and SQL, let alone memory.
AI agent privacy is only going to get harder to manage as agent systems keep adding data sources and stacking more agents that relay information to each other. Until a benchmark covers that full picture, every company running agents today is deciding, on its own, how much privacy is better to decide those AI agent privacy tradeoffs on purpose, before an incident decides them for you.
Artificial Intelligence is moving faster than our ability to manage it. What began as an experimental field is now woven into economies, governments, and daily life. The pace of AI’s growth is creating new kinds of AI risk: economic, political, and even existential.
The problem isn’t that AI exists. It’s that our systems of control, regulation, and understanding can’t keep up. The gap between what AI can do and how prepared society is to handle it keeps getting wider.
We’re now facing a spectrum of AI risks:
Immediate AI risks that threaten social trust, fairness, and jobs
Systemic risks that expose cracks in governance and global cooperation
Long-term risks that question whether we’ll stay in control of the technology we create
This article maps that spectrum. It draws on research from the UNDP, Stanford, and the World Economic Forum to show where we are and where the real dangers lie.
The Acceleration Problem
AI’s progress isn’t just fast. It’s accelerating. Each year, models become larger, cheaper, and more capable. That speed creates both opportunity and instability.
Shrinking timelines
Predictions for when we might see advanced, human-level AI keep moving closer. In 2024, a survey of nearly 2,800 AI researchers found the median forecast for “High-Level Machine Intelligence” to be 2047, thirteen years earlier than the same group predicted in 2022. Some experts, like Ray Kurzweil, expect Artificial General Intelligence by 2029.
Exploding resource use
The computing power behind frontier AI systems doubles roughly every five months, according to Stanford’s 2025 AI Index. Training a top-tier model now costs tens of millions of dollars, up from just hundreds in 2017. GPT-4 alone is estimated to have cost $79 million to train.
Cheaper, faster adoption
As training costs rise, usage costs fall. In 2024, 78% of businesses reported using AI, up sharply from 55% the year before. Meanwhile, the cost to run AI models like GPT-3.5 dropped over 280 in 18 months.
This mix of shorter expert timelines, huge compute growth, and cheaper access creates a perfect storm. AI risks that once took years to appear can now spread globally in weeks. Institutions move slowly. AI doesn’t.
What Counts as an AI System
Before we can talk about AI risks, we need to be clear about what AI actually is. Following the OECD (Organization for Economic Cooperation and Development) definition, an AI system is any machine-based system that takes human-set goals, interprets data, and produces outputs, predictions, content, or decisions that affect the real or digital world.
That covers everything from basic algorithms used in public services to complex generative models capable of writing, drawing, and reasoning. Because this definition is so broad, the AI risks are too. They range from small scale bias in decisions to large scale disruptions in economies and politics.
The Immediate AI Risks: What’s Already Happening
AI speed of growth isn’t just a technical story. It’s already reshaping how we work, what we trust, and how safe we feel online. The biggest problems are emerging faster than governments or companies can react. These aren’t future AI risks. They’re here now.
The Collapse of Information Integrity
The biggest short-term threat from AI is the breakdown of trust in information. Generative tools make it easy for anyone to create fake videos, cloned voices, or realistic text at scale. The World Economic Forum ranked AI-driven misinformation as the top global risk in its 2024 report.
We’ve already seen it play out in real elections:
In Pakistan, deepfakes of political leaders circulated right before the national vote, urging people not to participate.
In the United States, OpenAI shut down a Russian-linked operation using ChatGPT to flood Telegram with fake comments from accounts posing as ordinary citizens.
This kind of synthetic content floods the internet faster than fact-checkers can respond. It doesn’t just spread lies. It erodes confidence in everything, even the truth. When anyone can fake anything, public trust collapses.
Bias, Fairness, and Inequality
AI systems don’t invent prejudice, but they can amplify it. Models trained on biased data replicate the patterns they see. When used in hiring, credit scoring, or policing, those patterns can turn into real harm.
The Netherlands’ childcare benefits scandal is a clear example. A fraud detection algorithm wrongly targeted thousands of families, many with migrant backgrounds, as potential fraudsters. The damage was life-changing.
Bias also appears in subtle ways. Something as simple as using a postal code as a risk factor can indirectly discriminate, because location often tracks with ethnicity or income.
Globally, the problem runs deeper. The UNDP Human Development Report 2025 found that most large AI models are trained on data dominated by high income countries. That tilts the cultural balance of AI toward a narrow slice of the world and reinforces existing inequalities.
Even large vision-language models, those that combine text and image understanding, tend to amplify racial stereotypes. Bias isn’t a technical glitch. It’s a reflection of social and historical inequalities that AI ends up scaling.
Jobs, Productivity, and Disruption
AI brings both opportunity and disruption. It can make people more productive, but it can also automate work faster than new roles appear.
According to UNDP research, 60% of people believe AI will create new opportunities. About half also think it will eliminate jobs. Both are right.
The Stanford HAI report shows that AI can boost productivity and close skill gaps in some sectors. But freelancers in fields like software development, data entry, and content writing are already seeing falling demand and lower pay due to automation.
The outcome isn’t just a question of technology. It depends on policy and business choices. We can use AI to extend human capability, or we can let it hollow out the workforce.
AI as a Cybersecurity Threat
AI is also a growing weapon for attackers. It lowers the skill barrier for creating deepfakes, phishing scams, and realistic social engineering campaigns.
In surveys, 60% of Dutch citizens say they see AI as a cybersecurity threat. That fear is justified. Criminal groups are already using AI tools to scale scams, generate fake IDs, and breach systems faster.
AI gives defenders new tools, but it gives attackers even more. It’s a new kind of arms race, where speed and realism replace brute force.
The Cracks in Our Governance
The social AI risks we’re seeing aren’t just side effects of technology. They’re symptoms of weak oversight. AI is spreading faster than the rules, knowledge, and accountability needed to manage it.
Local Governments: Flying Blind
At the local level, AI is already being used in ways that directly affect citizens, but few officials understand how it works.
A study of Dutch municipalities found serious gaps in oversight:
Most had little to no visibility into which AI systems they were using
Local council members admitted they didn’t understand AI well enough to make policy decisions. One said simply, “Councillors know nothing about AI. It’s scary.”
92% of municipalities said they need clear national frameworks or rules for democratic control over AI systems
Without that, they can’t judge AI risks, protect citizens, or ensure accountability. AI risks is entering public administration through the side door, without proper scrutiny.
National and Global Regulation
The same problem appears at the national level. The EU AI Act is a major step toward responsible regulation, but many deadlines for public sector compliance stretch years into the future.
Globally, regulation remains fragmented. Countries are moving in different directions, each with their own rules and standards. The World Economic Forum warns that this fragmentation can spark tension when AI systems operate across borders.
What’s needed are shared international standards, rules for safety, accountability, and transparency that apply everywhere. Without that, AI governance becomes a patchwork of laws that criminals and corporations can easily exploit.
The Geopolitical AI Race
AI has also become a tool of power politics. The U.S. and China are competing for dominance in AI development, patents, and model performance.
Area of Competition
United States
China
Frontier AI Models (2024)
40 models
15 models
Private AI Investment (2024)
$109.1 billion
$9.3 billion
AI Patents (2010–2023)
14.2% of global total
69.7% of global total
Model Performance
Led in 2023, gap closing fast
Catching up on key benchmarks
The U.S. leads in private investment and cutting edge models, but China dominates in patents and state driven R&D. This fuels an AI arms race where both sides prioritize speed over safety.
The WEF (World Economic Forum) lists “interstate armed conflict” among its top global AI risks. As AI risk moves deeper into military systems, intelligence operations, and cyber warfare, the danger grows that competition, not caution, will shape the future.
Long-Term and Existential AI Risks
The logical endpoint of today’s acceleration and weak governance is a set of high impact, low probability AI risks that can’t be ignored. These are the scenarios that move from policy debates to questions of human survival.
Expert Views on Catastrophic Risk
A 2024 survey of 2,778 AI researchers showed that many experts take existential AI risks seriously.
Between 38% and 51% believe there’s at least a 10% chance advanced AI could cause catastrophic outcomes, including human extinction.
Even among optimists, almost half assign a 5% chance to that scenario.
The median estimated probability of extinction from AI was between 5% and 10%.
The message is clear, even those closest to the technology can’t rule out the worst outcomes. When experts who build the systems say extinction is possible, policymakers have a duty to listen.
The Alignment Problem
The alignment problem is at the heart of these concerns. It’s the challenge of ensuring that advanced AI systems pursue goals that truly match human values. As AI becomes more autonomous, even small misalignments could have large consequences.
A related issue is explainability. The more complex a system becomes, the harder it is to understand how it makes decisions. The same 2024 survey found that for advanced systems expected by 2028, there’s only a 10–40% chance users will know why the AI made a given choice.
That lack of transparency makes control difficult. You can’t manage what you can’t explain. If alignment and explainability fail together, AI could act in ways that no one predicts or stops.
Building a Safer Future
AI risks are serious but not unmanageable. The key is to act early, cooperate widely, and focus on systems that serve people rather than replace them.
Stronger Governance and Global Cooperation
Effective governance is the foundation. Governments and international bodies need to close the gap between innovation and oversight.
Algorithm registration – Public institutions should keep a public record of the AI systems they use. That builds transparency and accountability.
International standards and audits – Countries need shared safety and ethics standards. Independent AI safety institutes should test and evaluate models before they’re deployed.
Cross border cooperation – The UNDP recommends collaboration on things like content authenticity standards and joint model evaluations. This helps smaller nations participate safely in the AI economy.
Corporate Responsibility and Transparency
Most frontier AI models come from the private sector. That gives companies a direct responsibility for safety and transparency.
A 2024 McKinsey survey found that the top AI risks businesses are addressing are cybersecurity (66%), regulatory compliance (60%), and privacy (57%). But 51% of firms cite a lack of internal expertise as their main barrier to responsible AI adoption.
Transparency also remains limited. The Foundation Model Transparency Index shows improvement, but most companies still don’t disclose enough about training data or how copyrighted material is used.
Some companies, like Anthropic, are taking proactive steps. Its Responsible Scaling Policy (RSP) includes safeguards for model security, such as strict protections for model weights to prevent theft or misuse.
Keeping Humans at the Center
The long term goal should be simple. AI that helps people, not replaces them.
The UNDP Human Development Report argues for a “complementarity economy”, where AI tools are designed to augment human work, not automate it away. That shift requires deliberate policy, education, and corporate incentives.
We also need to protect human agency. AI systems should expand people’s choices, not make them on our behalf. In high stakes areas like healthcare, law, and defense, humans must stay “in the loop” or “on the loop”, able to question, correct, and override automated systems.
AI should be explainable, contestable, and aligned with democratic values. The goal isn’t to hand control to machines but to use them wisely, with clear boundaries and shared benefits.
Conclusion
The future of AI risks isn’t written yet. It’s not a path we discover. It’s one we choose. Every policy, design decision, and ethical choice we make today shapes that path.
AI can amplify the best of human creativity and knowledge. It can also deepen inequality and confusion. The difference lies in governance, transparency, and intent.
Building a safer AI future means acting now. Regulating what matters, educating decision makers, holding companies accountable, and keeping people at the center of every system we create.
That’s how we close the gap between progress and control, and make sure AI remains a tool for humanity, not a threat to it.
FAQ
What are the risks of AI?
AI risks range from immediate threats like misinformation, deepfakes, algorithmic bias, and job displacement to long-term existential risks where advanced AI systems might become uncontrollable or misaligned with human values.
What are 5 disadvantages of AI?
The five major disadvantages of AI are: job displacement through automation, algorithmic bias that amplifies discrimination, erosion of information trust through deepfakes and synthetic content, increased cybersecurity threats from AI-powered attacks, and lack of transparency
What are the 4 levels of AI risk?
(1) Individual risks affecting single users through bias or privacy violations, (2) Organizational risks impacting businesses through security breaches or compliance failures, (3) Societal risks undermining social trust, jobs, and democratic institutions through misinformation and automation, and (4) Existential risks threatening human survival if advanced AI systems become uncontrollable or misaligned with human values.