Treadstone Associates
Ask an Expert · 4 min read

What's the biggest risk of using AI?

Ask about AI risk and the answer often reaches for the dramatic case — a poisoned model, a deepfake fraud. For most businesses, day to day, the real exposure is quieter than that.

Treadstone Associates · Updated 2026

Short answer

For most ordinary businesses, it isn't a sophisticated attack — it's an employee pasting sensitive information into a public AI tool as part of completely normal, well-intentioned work. Canada's Cyber Centre names this specifically as a generative-AI risk, and it's structurally the most common one because it requires no attacker, no technical skill and no malicious intent — just ordinary use without a policy governing it.

Why this one outranks the more dramatic risks, structurally

The named risk is “privacy of data”: “Users may unknowingly provide sensitive corporate data or personally identifiable information (PII) in their AI queries and prompts” (Cyber Centre, ITSAP.00.041). Compare what each risk actually requires to happen: a data-poisoning or model-inversion attack (see can an AI system be hacked) needs a threat actor with a specific goal and some technical capability. A deepfake fraud needs an attacker willing to run a targeted social-engineering operation. Pasting a client’s file into a chatbot to summarise it needs nothing except an employee trying to get their work done faster — which is precisely why it happens far more often.

No Canadian source publishes a frequency count of which AI risk materialises most often in practice, and none should be invented here — this is a structural argument about what each risk requires, not a statistic about how often each one occurs.

What the only Canadian survey data says businesses actually worry about

The closest real Canadian data point is what businesses report as barriers to adopting AI at all, which is a proxy for what concerns them rather than a measure of realized incidents: Statistics Canada's Q2 2026 survey found cybersecurity or privacy concerns were the most commonly reported barrier limiting AI use, at 13.4%, ahead of cost at 10.6% (StatCan, Analysis on artificial intelligence use by businesses in Canada, second quarter of 2026). That ranking is consistent with the structural argument above: privacy exposure is the concern businesses name first, even before what it costs to adopt the technology at all.

What actually reduces this specific risk

The fix for this particular exposure doesn't require new technical controls so much as a plain-language policy employees can actually follow: a short, specific list of what categories of information must never go into a public AI tool, told to staff before the tool is rolled out, not after something goes wrong. It's the cheapest control on this whole list, and the one most businesses skip precisely because it feels too basic to be the answer.

Once information has already gone in and something has gone wrong with it, the response duty is a separate, specific sequence — covered at what if AI leaks personal information. The more dramatic, documented failure cases — data poisoning incidents, algorithmic bias in screening tools — are catalogued at what actually goes wrong with AI in practice.

Where this goes next

A written policy for what can and can't go into an AI tool is a small, concrete piece of the operational discipline that keeps day-to-day AI use from becoming a recurring liability.