AI Security Risks: What Organisations Should Check Before Using Generative AI

The supplied headline about rising security concerns around artificial intelligence could not be independently verified as a report of a specific incident. It should therefore not be treated as evidence of a new breach, attack or local event. The wider issue is nonetheless clear: organisations adopting generative AI need to manage both security risks in AI-enabled workflows and the growing use of AI in fraud and impersonation.

AI security risks matter because generative tools can handle sensitive information, connect to business systems and produce convincing content at speed. A sound response is not to assume every AI tool is unsafe, but to define acceptable use, protect data, test integrations and retain reliable human verification for important actions.

Key takeaways

  • AI security risks include data exposure, prompt injection, misuse of connected tools and AI-enabled impersonation.
  • The underlying WKRN News 2 report was not independently available from the supplied material, so no specific incident is confirmed here.
  • NIST identifies privacy, information-security and misuse risks as material considerations for generative AI use.
  • Voice, email and video that appear convincing should not replace established identity and approval checks.
  • Finance teams should keep segregation of duties, independent payment approvals and auditable review processes when using AI.

Why this is an AI security explainer, not a report on a confirmed incident

The available Google News link identified a WKRN News 2 headline concerning AI security, but the original article and its underlying claims could not be independently assessed from the supplied research. There is no reliable basis here to state what event may have prompted that headline, when it occurred, or who was affected.

That distinction is important. Security reporting should separate verified facts from broader context. This article therefore explains established risk-management considerations using public guidance from NIST, the FBI and the US Cybersecurity and Infrastructure Security Agency (CISA), rather than presenting an unverified headline as a confirmed development.

What AI security risks actually include

AI security is not one issue. It covers technical attacks on models and AI applications, weaknesses created when AI is connected to data or operational systems, and malicious use of AI to deceive people.

Data privacy and information security

A common risk arises when staff paste confidential material into a tool that has not been approved for that purpose. Customer records, source code, contracts, passwords, bank details and commercially sensitive forecasts may be exposed beyond the organisation’s intended controls if data-handling terms, retention settings and user permissions are not understood.

The risk depends on the tool, configuration and data involved. Organisations should therefore know which services are approved, what information may be entered, where data is processed, how long it is retained and whether it may be used to improve a service.

Prompt injection and unsafe connected actions

Prompt injection is an attempt to influence an AI system or AI-assisted workflow with untrusted instructions. For example, content in an email, document or web page might seek to make an AI assistant disregard its intended task, reveal information or take an inappropriate action.

This becomes more significant when an AI tool can search internal files, send messages, update records or call other software services. The issue is not merely whether a model gives an odd answer; it is whether a manipulated output can affect data, decisions or transactions. Permissions, confirmation steps and narrow task design are therefore essential.

Attacks on AI systems and AI-enabled fraud

NIST’s guidance on adversarial machine learning distinguishes several categories of concern, including evasion, poisoning, privacy and misuse attacks. In plain terms, attackers may try to evade a system’s safeguards, corrupt data used by a system, extract protected information or misuse capabilities for harmful ends.

These risks should also be distinguished from AI-enabled fraud. A criminal may use generated text, cloned audio or altered imagery to make an ordinary social-engineering attempt appear more credible. In many cases, weak identity checks, rushed procedures or excessive access rights remain the route to harm rather than a failure of the AI system itself.

What authoritative guidance says about AI security risks

On 26 July 2024, NIST published its Generative Artificial Intelligence Profile. The profile highlights privacy, information-security and misuse considerations among the risks that organisations should address when designing, using or governing generative AI. It is a risk-management resource, not a claim that every deployment is insecure.

On 24 March 2025, NIST also published information on its adversarial machine-learning taxonomy and terminology. That work provides a more technical framework for understanding attacks and mitigations affecting AI systems, including generative applications. It reinforces the need to assess the whole system: the model, its data, connected tools, users and operating environment.

CISA’s AI Cybersecurity Collaboration Playbook, released on 14 January 2025, focuses on voluntary sharing of incident and vulnerability information. For organisations, the practical lesson is that AI governance should have a route for reporting security concerns, learning from incidents and updating controls as threats change.

Impersonation and deepfakes: why verification matters

On 15 May 2025, the FBI warned that malicious actors had used AI-generated voice messages while impersonating senior US officials. The warning is a useful reminder that a familiar-sounding voice, plausible email or realistic video is not sufficient proof of identity.

Businesses should independently verify unexpected requests involving payments, changes to bank details, credentials, confidential documents or urgent access. Use a known telephone number, established contact channel or pre-agreed approval process; do not rely solely on the contact method included in a suspicious message.

This is a procedural safeguard rather than a technology race. A finance director, supplier or colleague may be impersonated using conventional methods as well as AI-generated content. Consistent call-backs, dual authorisation and prompt reporting remain effective controls.

Practical controls before staff use generative AI

Controls should be proportionate to the use case. Drafting generic internal material carries a different risk from allowing an AI assistant to access customer data or trigger actions in a business system. Before wider rollout, organisations should consider the following checklist.

  • Set an approved-use policy: specify approved tools, permitted purposes and information that must never be entered into public or unapproved services.
  • Classify the data: identify personal, financial, confidential and regulated information before it is used in an AI workflow.
  • Apply least privilege: give AI-connected applications and users only the access necessary for a defined task, supported by strong authentication.
  • Assess suppliers: review data processing, retention, training terms, security documentation, access controls and incident-notification arrangements.
  • Test workflows: check for prompt injection, unexpected disclosure, inaccurate retrieval and unsafe automated actions before production use.
  • Keep meaningful human review: require a responsible person to approve consequential decisions, external communications and transactions.
  • Maintain records: document the intended benefit, owner, data involved, controls, exceptions and review dates for material use cases.

Considerations for accounting and finance teams

For accounting and finance functions, client information, payroll data, bank details, tax records and business forecasts should generally be treated as high-risk information. Teams should not assume that convenience tools are suitable places to upload such material, even when a tool produces useful summaries or draft analysis.

AI can support lower-risk tasks such as structuring a draft, explaining a concept or suggesting questions for review. But where it is used in reconciliations, reporting support or document analysis, finance leaders should define what must be checked, who signs off the work and what audit trail is retained. AI-generated output requires professional judgement; it does not guarantee accuracy, security or compliance.

Payment controls deserve particular care. An AI-drafted email, a convincing voice request or a summarised supplier message must not bypass segregation of duties and independent approval. Any change to payment instructions should be verified through established channels and recorded according to the organisation’s existing procedures.

Risks and limitations

There is no single checklist that makes an AI deployment secure. The risk changes with the model, supplier, configuration, data sensitivity, integrations and user behaviour. Technical safeguards can reduce exposure, but cannot substitute for clear accountability and staff awareness.

Equally, organisations should avoid treating AI as uniquely responsible for every cyber risk. Many effective attacks exploit familiar weaknesses: stolen credentials, excessive permissions, poor supplier oversight and hurried approval processes. AI may increase the scale or realism of an attack, which makes established security disciplines more important rather than obsolete.

What to watch next

Watch for changes in how AI tools retain and use business data, the addition of integrations or autonomous actions, new vendor security documentation and emerging guidance on incident reporting. Review controls whenever a use case expands beyond its original scope, especially when a tool gains access to internal systems or sensitive records.

A sensible starting point is a limited, lower-risk use case with a named owner and documented safeguards. Responsible adoption combines security design, staff awareness and dependable verification processes. Explore more practical AI news and explainers from AI Accounting Tutor.

Related reading

Sources

Explore more practical AI news and explainers from AI Accounting Tutor.

Frequently asked questions

What are AI security risks?

AI security risks are threats involving AI systems or AI-enabled workflows, including data exposure, prompt injection, unauthorised actions, model attacks and impersonation fraud.

What is prompt injection in generative AI?

Prompt injection is an attempt to manipulate an AI system through untrusted content so that it ignores intended instructions, exposes information or takes an unsafe action.

Can staff paste confidential data into a public AI tool?

Staff should only enter confidential data where their organisation has explicitly approved the tool, use case and data handling arrangements.

How can an organisation reduce AI data leakage?

Use approved services, classify data, restrict access, review supplier terms and prevent sensitive information from being entered into unapproved tools.

Are deepfakes only a risk for large organisations?

No. Any organisation can be targeted by convincing voice, email or video impersonation designed to bypass normal approval processes.

How should a business verify a suspected AI voice scam?

Contact the person through a known, independently sourced telephone number or established channel rather than replying through the unexpected request.

Should AI be allowed to approve payments automatically?

High-consequence payment actions should retain independent human approval, clear authority limits and segregation of duties.

What should finance teams check before adopting an AI tool?

They should assess data sensitivity, permissions, supplier security, audit trails, review requirements and the effect on existing financial controls.

Does AI-generated output guarantee accurate financial information?

No. AI-generated output can be inaccurate or incomplete and requires appropriate professional review before it is relied upon.

Why is least-privilege access important for AI tools?

Least privilege limits an AI-connected tool and its users to the minimum access needed, reducing the potential impact of error, misuse or compromise.

Share this post:

AI Accounting Tutor

AI Accounting Tutor

Support Team

I will be back soon

AI Accounting Tutor
Welcome to AI Accounting Tutor. Click on an icon below to contact us via WhatsApp, Email or Phone.
Start Chat with:
chat