AI Insider Risk Isn’t One Thing. Why Are We Talking About It Like It Is?

Cezanne Huq 30 min read
AI Insider Risk whiteboard pic

Satya Nadella raises some legitimate concerns about AI and superintelligence, but I think we’re getting ahead of ourselves. The data tells a different story about where most businesses actually are, and there’s a more practical way to assess the risks.

I’m going to troll Microsoft CEO Satya Nadella a little. 😄 On October 10, Microsoft CEO Satya Nadella, published an interesting piece, Models as Insider Risks in the Super Intelligence Era, arguing that increasingly capable AI models should be treated as potential insider risks. His concerns are legitimate, and I agree with much of what he’s proposing. But frankly, I think we’re developing an ivory-tower problem with how LLMs, agentic AI and superintelligence are being discussed.

The language is getting increasingly abstract, the accompanying coverage can be quite sensational, and we’re spending a disproportionate amount of time debating scenarios that are several steps removed from what most businesses are actually doing with the technology. It’s not that the concerns are unfounded. It’s that we’re taking some very advanced possibilities, wrapping them in terminology that perhaps a fraction of the audience fully understands, and presenting them as though every business needs to be preparing for an imminent encounter with superintelligence.

Meanwhile, many organizations are still trying to figure out how to get reliable information out of their existing systems, how to connect their customer data, whether their analytics can be trusted, and how to translate the investments they’re making into meaningful business outcomes. They’re trying to establish where AI fits into the operating model, how much of the work it can take on, what needs human oversight and, perhaps most importantly, who’s responsible for the results.

I’ve spent much of my career working across growth, acquisition, lifecycle, customer intelligence, analytics, media, technology and organizational transformation. One thing I’ve learned is that businesses don’t become more sophisticated simply because they’ve adopted more sophisticated technology. The quality of their decisions still depends on the information available, the economics they’re optimizing toward, how well the teams and systems are connected, and whether anyone has a clear understanding of what’s working and what isn’t.

I don’t see AI changing that fundamental reality. In fact, as we automate more of the work, those dependencies become more important because there’s potentially less human intervention between a decision being made and that decision affecting the business.

So while I appreciate Nadella’s concerns, I’d rather see the discussion move toward something businesses can put into practice today. We need to understand the actual level of exposure, establish appropriate standards for the systems we’re introducing and make sure our ability to supervise them develops alongside their ability to execute.

There’s also a fairly simple idea I think deserves consideration. We don’t give people unlimited access to sensitive business systems without first evaluating their qualifications, checking their backgrounds and establishing what they’re authorized to do. Why shouldn’t we apply a similar process to the agents we’re beginning to employ across our businesses?

Don’t take my word for it.

Let’s dig into the data, because there’s a meaningful difference between the number of businesses using AI and the number giving it authority to make consequential decisions.

McKinsey’s August 2026 research found that nearly nine in ten surveyed organizations reported using AI in at least one business function. That’s an impressive level of adoption, particularly when you consider how recently the technology became widely accessible. But the more interesting finding is what happens when we distinguish everyday usage from businesses actually scaling agents within their operations.

According to the same research, only 22% of respondents from smaller organizations reported scaling AI agents in at least one function, compared with 40% of respondents from companies generating more than $1 billion annually. In other words, a substantial portion of the market is using AI without necessarily operating the kind of autonomous, interconnected systems that dominate much of the current discussion.

The difference matters. Using a model to help analyze information, write code, produce creative assets or answer customer questions isn’t the same thing as allowing it to make financial decisions, change customer records, execute transactions or coordinate activities across several operational platforms.

Both might be counted as AI adoption, but the business requirements are quite different. One may be helping an employee complete a task more efficiently, while the other could be taking on responsibilities previously requiring several teams, approval processes and operational controls.

Now consider another statistic. Deloitte’s 2026 research, which surveyed 3,235 business and technology leaders across 24 countries, found that only 21% of respondents reported having mature governance for agentic AI. That’s a fairly significant gap between the availability and usage of the technology and the maturity of the processes designed to supervise it.

We should be careful about comparing those figures directly. McKinsey and Deloitte surveyed different populations and measured different things. They’re not components of a single risk calculation, and the findings don’t tell us that organizations lacking mature governance are necessarily experiencing failures.

But collectively, they paint a picture of a market where adoption is progressing much faster than the organizational capabilities needed to deploy these systems broadly and confidently.

There’s another McKinsey finding I consider particularly relevant to the business discussion. While 80% of respondents reported individual productivity improvements from AI, only 37% attributed some positive impact on enterprise EBIT to its use and it’s a familar pattern.

We’ve seen variations of this problem across technology, analytics, marketing automation and digital transformation for years. Companies invest in tools that make individual tasks faster, generate more information or automate parts of an existing process, but the financial benefits don’t always follow at the same rate.

A marketing team might generate ten times more creative variations without improving conversion or reducing acquisition costs. A customer service organization might automate more interactions while creating additional downstream contacts because the original issues weren’t adequately resolved. A sales team might produce more outreach without improving lead quality, conversion or customer value.

So while the activity improves business outcomes don’t necessarily follow. Which is why I find the gap between productivity and reported financial impact so interesting. It suggests that adoption alone isn’t the appropriate measure of progress, and that much of the work still lies in connecting the technology to better decisions, better processes and actual economic value.

And before we go too far down the path of discussing how to contain superintelligence, perhaps we should understand why so many organizations are still struggling to translate the intelligence they already have into measurable results.

That doesn’t mean they should ignore security or governance. It means the appropriate response needs to reflect where the business actually is, what it’s using and the consequences of the authority it’s delegating.

I See Three Variables That Determine How Exposed a Business Really Is

I think the discussion becomes much more practical when we stop treating AI risk as one broad category and examine the business environment in which the technology operates.

I’d look at three interdependent variables: the maturity of the organization’s governance, the prevalence and autonomy of AI across its operations, and the complexity of the underlying data environment.

The distinction is important because a business using a very capable model in a controlled environment may have relatively limited exposure, while another business using a less sophisticated system with broad access and few restrictions could face substantially greater consequences.

These variables aren’t intended to produce a mathematical formula. Stronger governance should generally reduce exposure, while greater authority and more complicated system connections can expand it. What we’re trying to understand is how those conditions interact and whether the business has the necessary controls to manage the decisions being delegated.

1. Governance maturity: do we actually have the controls in place?

Let’s start with governance, although I’d rather think about it in terms of the operating standards and responsibilities a business already uses.

We have established processes for giving employees access to applications, approving financial transactions, protecting customer information and controlling changes to operational systems. These processes vary from one organization to another, and they’re not always implemented particularly well, but the underlying principles aren’t new.

Someone needs to establish what a system can access, what it’s permitted to change, who owns the decision, and what happens if something goes wrong. We also need enough visibility to understand what actually occurred, rather than relying entirely on the system to explain its own behavior.

That last point is central to Nadella’s argument. We shouldn’t allow an agent to be the sole authority determining whether its own actions were appropriate, particularly when those actions involve sensitive information or consequential business decisions.

But I wouldn’t start by asking whether a company has a sophisticated governance platform. I’d start by understanding the existing operating model and whether its controls are being applied consistently.

Does the business know which AI tools its employees are using? Are those tools approved? What information is being shared with them, and where does that information go? If an agent is connected to a customer database or a financial system, are its permissions limited to the activities it actually needs to perform?

And perhaps more importantly, who has the authority to expand those permissions?

These are fairly standard questions that security, technology, finance and operational teams should already be familiar with. The challenge is making sure the answers remain relevant as software moves from helping employees perform tasks to executing parts of the work itself.

An agent that prepares a recommendation isn’t the same as an agent that can implement that recommendation. The business needs to distinguish between the two and establish the controls appropriate to each.

I also think we need to avoid turning governance into another elaborate compliance exercise that gives everyone the appearance of oversight without improving the quality of decisions. More policies, more committees and more documentation don’t automatically make an organization safer or better managed.

The objective should be to establish boundaries that can be enforced, maintain visibility into what’s happening and preserve the ability to intervene when necessary. If those controls are already available through existing infrastructure and procedures, we should build on them rather than introducing complexity for its own sake.

2. Adoption and autonomy: how much of the business are we handing over?

The second variable is the extent to which AI is being used across the organization and, more importantly, the authority we’re giving it.

I think we need to be careful about confusing prevalence with autonomy. A business with hundreds of employees using AI to support their daily work doesn’t necessarily have a greater risk profile than a business using one agent with permission to execute significant financial transactions.

The number of people using the technology is relevant, but what the systems are allowed to do matters considerably more.

Take a marketing organization as an example. At one level, AI can help analyze performance, identify customer segments, summarize research and develop creative variations. The team still decides which recommendations make sense and what should be implemented.

At another level, the system might prepare campaigns, recommend spending adjustments or identify customers for a lifecycle program. A person evaluates the recommendations, but much of the analysis and preparation has been automated.

Now consider a system that’s permitted to execute those decisions. It can change bids, move investment between channels, modify audience rules, initiate campaigns and interact with customers based on its interpretation of the available information.

The underlying technology may be similar, but the business has delegated a very different level of authority.

This is where the risk profile changes. We’re no longer evaluating only whether the system can produce useful information. We need to understand whether the decisions it’s making are appropriate, whether the underlying assumptions remain valid and how quickly the business can recognize and correct problems.

A flawed recommendation that an employee reviews might have relatively limited consequences. The same recommendation executed thousands of times across multiple systems could create a much larger problem, even if every individual action remains within the permissions originally granted.

And that’s an important distinction. We don’t need an agent to develop intentions, circumvent its instructions or behave maliciously for something to go wrong. We simply need to give it responsibility for decisions that depend on incomplete information, flawed assumptions or objectives that don’t adequately reflect the broader needs of the business.

The more autonomy we introduce, the more important the quality of those underlying decisions becomes.

I also think there’s an organizational issue here that isn’t receiving enough attention. As responsibilities move from employees into automated workflows, we’re changing how decisions are made and who participates in them. That can improve speed and efficiency, but it can also remove opportunities for people to question assumptions, identify inconsistencies or recognize when a technically correct recommendation doesn’t make commercial sense.

We should be evaluating those changes alongside the technical capabilities of the system, particularly when decisions have consequences extending beyond the function where the technology was introduced.

3. Data complexity: the part of the equation I think gets underestimated

The third variable is the complexity of the business’s data environment, and this is the area where I think many organizations are going to encounter some of their more immediate challenges.

I’ve worked with customer data, analytics, attribution, media platforms, CRM systems and marketing technology for much of my career. The problems are rarely as simple as collecting more information or connecting another application. Much of the difficulty involves understanding what the information represents, how it relates to other information and whether it’s appropriate for the decision we’re trying to make.

Consider the customer journey. A person may encounter a brand through paid media, visit the website, interact with content, create an account, receive lifecycle communications and eventually make a purchase. Each interaction generates information, but that information may be captured across several platforms, using different identifiers, business definitions and attribution methods.

A CDP might attempt to reconcile the customer identity. The data warehouse may contain transactional information, while the advertising platforms maintain their own modeled views of conversion and performance. Analytics may provide another interpretation based on the events and attribution rules available to it.

Even with considerable investment in these systems, businesses can struggle to establish a consistent view of the customer from unknown to known, and from initial engagement through acquisition, retention and lifetime value.

Now imagine giving an agent access to all that information and asking it to make decisions.

The system may be able to process large volumes of data quickly, but it doesn’t magically reconcile conflicting definitions, correct incomplete identities or determine which attribution methodology best represents incremental value. If the underlying information is inconsistent, we may simply be processing and acting on those inconsistencies more efficiently.

A customer might be counted as new in one platform, returning in another and reactivated in a third. A transaction could be attributed to several marketing channels, while the financial system recognizes only one purchase. An LTV model might forecast customer value based on historical behavior that no longer reflects current pricing, acquisition or retention conditions.

If the agent is preparing a report, those discrepancies might be caught before anyone acts. If it’s allowed to modify campaigns, change segmentation or make spending decisions, the same discrepancies can affect the business directly.

Then there’s the question of access. A system connected to several databases, financial applications and customer platforms may have the ability to retrieve or change information across functions that were previously managed separately.

That creates legitimate security concerns, but we shouldn’t assume that more data automatically means greater risk. A large business with sophisticated data infrastructure, well-defined access controls and documented dependencies can be better protected than a small organization with a handful of systems and unrestricted credentials.

What matters is the relationship between the information available, the connections between systems, the authority to act and the organization’s ability to understand what’s happening.

When I bring these three variables together, I’m not looking to create another academic framework. I’m looking for a way to assess the exposure of a particular business in the context of how it actually operates, rather than making broad assumptions based on the sophistication of the technology it’s using.

Same Agent, Different Business, Completely Different Risk Profile

Let’s make this a bit more tangible. Imagine an agent designed to analyze marketing performance and recommend improvements to customer acquisition. It’s been evaluated, performs well on the relevant tasks and comes from a provider with a credible development and security process.

A smaller business deploys it with read-only access to aggregated campaign reports. The agent identifies changes in acquisition costs, conversion and customer performance, then prepares recommendations for the marketing team. The team reviews those recommendations before making any changes.

There’s still a need to assess accuracy and protect the information being used, but the system has relatively limited authority. It can’t independently change campaigns, modify customer records or access unrelated business applications.

Now imagine another organization deploying the same agent with permission to access customer-level information, change campaign budgets and modify audience targeting across several media platforms.

The model hasn’t changed, but its ability to affect the business has expanded considerably. A poor recommendation can now become an operational decision without necessarily requiring another person to review it.

Take the same agent into a larger organization and connect it to multiple data lakes, a CDP, CRM, media platforms and financial systems. It can evaluate customer economics, adjust acquisition investment, initiate lifecycle communications and coordinate activity across several functions.

Again, the underlying model could be exactly the same, but the operating environment and potential consequences are very different.

The point isn’t that the largest organization automatically has the greatest exposure. It may also have the most mature security, analytics, technology and operational controls. The point is that we can’t assess the system independently of the authority it’s been given and the environment in which it’s operating.

A small business with unrestricted access to sensitive information may have a more serious problem than a much larger enterprise with carefully defined permissions and monitoring. Likewise, an advanced model operating within narrow boundaries may create less exposure than a comparatively simple system with broad authority.

That’s why I believe the discussion needs to move away from treating AI capabilities as a substitute for assessing business risk.

Nadella is rightly concerned about what increasingly capable models might do with access to important systems. I’d extend that argument by examining why businesses are giving them that access, what decisions they’re expecting them to make and whether the surrounding operating model can support those decisions.

This piece is for members

Members read every essay and framework in full, the moment it is published.

Join for $9.99/month