
Your AI Strategy Has Six Blind Spots. Here Are All of Them.
Part 1 of 2 — Leadership + AI Strategy Briefing
The conversation around AI and the future of work has never been louder, or more anxious. But the risks generating the most noise are rarely the ones causing the most damage. The real threats are quieter, more organisational, and almost entirely preventable: executives making decisions on hallucinated data, companies shedding experienced talent for automation that was never ready, enterprises connecting their most sensitive systems to AI without the security architecture to protect them.
These are not technology failures. They are leadership failures, and every one of them is solvable. This first issue maps all six blind spots. The next issue sets out the five principles that close them.
Key statistics: $67.4B in estimated global losses from AI hallucinations in 2024. 55% of AI-driven layoffs are predicted to be quietly reversed (Forrester, 2026). 95% of enterprise AI projects fail — a strategy problem, not a technology one.
Risk 1: The Boardroom Built on Hallucinations
Executives bringing AI output into strategy sessions without checking it. AI invents plausible-sounding answers with the same confidence whether it is right or wrong.
Key statistic: 38% of executives have made a major decision on AI output that later proved incorrect (Deloitte, 2025).
Large language models do not look up facts. They generate the most statistically likely next word. When pushed into complex or specialist territory, they produce fluent, confident, wrong answers. Stanford researchers found that general-purpose AI tools gave wrong answers on 58 to 88% of legal queries. Even tools built specifically for legal research still produced errors in 17 to 34% of cases.
The problem is getting harder, not easier. The Foundation Model Transparency Index dropped from an average score of 58 in 2024 to 40 in 2025, with the biggest falls in areas covering how models are built and what happens after they are released. Regulators and risk managers are increasingly being asked to accept decisions made by systems whose inner workings they cannot inspect.
What this demands of leaders: Treat every AI output as a first draft from a smart but unreliable analyst. It needs a human to check it before it reaches a boardroom slide. Your accountability does not transfer to the model. Ask harder questions of vendors too: what are the known failure modes, and what are their obligations if the system causes harm?
Sources: Deloitte Switzerland, AI Hallucinations — New Risk in M&A (2025); Stanford RegLab/HAI, Large Legal Fictions (2024); Stanford HAI, 2026 AI Index Report (April 2026).
Risk 2: The Talent Exodus Disguised as Innovation
Replacing people with AI before it is ready, and losing institutional knowledge that cannot be rebuilt quickly.
Key statistic: 31% of organisations found rehiring staff cost more than the original savings (Careerminds, 2026).
Two in three organisations that cut jobs due to AI have already begun rehiring the same workers, often within months. Among those that went ahead with AI-driven layoffs, 33% reported losing critical skills that automation could not replace, and a further 28% said the remaining workforce lacked the ability to fill those gaps.
Klarna is the most visible example. The Swedish fintech replaced roughly 700 customer service staff with an AI chatbot, declaring it could handle two thirds of all customer conversations. Within two years, customer satisfaction had fallen sharply. The CEO publicly said the company had focused too much on efficiency and that quality had suffered. Klarna is now rehiring human agents.
A late-2025 survey of large enterprise executives found no statistical link between AI-driven workforce reductions and return on investment from AI. The organisations achieving the strongest returns were those investing in upskilling their people, not replacing them.
What this demands of leaders: Before any role is cut in the name of AI efficiency, answer three questions honestly. Can the AI actually do this work at the required quality level? What institutional knowledge lives in this role that is not written down anywhere? And what will it cost to rebuild that capability if you are wrong?
Sources: Forrester Research, AI-Led Job Disruption Will Escalate (January 2026); Careerminds, AI-Led Layoffs: What HR Leaders Wish They Knew (March 2026).
Risk 3: The Open Door You Did Not Know You Left Unlocked
Connecting AI to internal systems creates attack surfaces of real value to bad actors, including through accidental data leakage, not just deliberate breaches.
Key statistic: 87% of organisations experienced at least two successful identity-related breaches in the past 12 months (CyberArk, 2025).
68% of organisations say they lack identity security controls specifically for AI systems. 47% cannot account for unauthorised AI tools being used within their own organisation. Human and machine identities with privileged access are expected to double in 2025, according to CyberArk's Identity Security Landscape Report.
AI agents need broad access to data to work: credentials, personal information, financial records, internal communications, strategic documents. Within AI agent systems, sensitive data can move through multiple internal pathways including tool outputs, workspace files, memory entries, and webhook responses.
The subtler risk is accidental leakage through over-permissive access. Models trained on internal data, including HR records or executive communications, can surface that information to the wrong users through routine requests like drafting an email. The leak is not a hack. It is a misconfigured permission boundary.
What this demands of leaders: Security architecture for AI is not a conversation that happens after deployment. It is a condition for deployment. Access controls, permission separation, data classification, and incident response plans must be in place before the first enterprise system is connected to an AI layer.
Sources: CyberArk, 2025 Identity Security Landscape Report; ISACA, 2026 AI Pulse Poll — The AI Security Gap (March 2026).
Risk 4: The Vendor Trap Being Built Into Your Infrastructure
Deep dependency on a small number of AI providers, with no exit plan. AI lock-in is harder to escape than cloud lock-in.
Key statistic: 38% of enterprise leaders fear vendor lock-in and 81% feel pressure to speed up AI adoption regardless of readiness (Zapier, 2025).
Enterprise leaders say the number one issue when choosing AI tools is the high cost of vendor solutions, and vendor lock-in is cited as a major structural fear alongside rising costs. Switching AI providers would require rewriting applications, retraining staff, migrating prompt libraries, rebuilding integrations, and renegotiating data agreements, all at the same time.
When underwriting models, customer service AI, operational forecasting, and developer tools all run on one provider's infrastructure, a pricing change, policy shift, model withdrawal, or acquisition can cause disruption across the entire AI capability stack at once.
The major AI providers are all moving from selling API access to becoming the operating layer of enterprise AI workflows, embedding themselves at the level of memory, orchestration, agent management, and developer tooling. Each is pursuing the same approach: make their AI the path of least resistance, then make switching increasingly expensive.
What this demands of leaders: Ask your CTO today which critical workloads depend on which providers, what the switching costs are, and whether abstraction layers are in place. Every AI vendor contract should include data portability, reasonable notice periods, and clear terms around ownership of fine-tuned models. No vendor relationship should begin without an exit plan.
Sources: Zapier, 34 Enterprise AI Statistics 2026; Zapier, 78% of Enterprises Struggling to Integrate AI (2025).
Risk 5: The Legal Exposure Nobody Put in the Strategy Deck
A growing body of law now makes AI-related harm your organisation's legal problem. Most AI strategies do not mention it.
Key statistic: full EU AI Act compliance for high-risk systems is due August 2026, and there are already more than 200 active legal cases involving AI.
The EU Product Liability Directive, in effect by December 2026, classifies software and AI as products. If an AI system is found defective, organisations face strict liability with no need to prove fault. Italy's AI Law 132/2025 already carries fines of up to 774,685 euros plus disqualification from public contracts.
In the United States, California's AI Safety Act took effect in January 2026. Multiple states are advancing bills that create new rights of action for AI-caused harm, including employment discrimination from AI-powered hiring tools. When courts have penalised lawyers for submitting AI-generated false legal citations, those penalties fall on counsel regardless of which department chose the AI tool.
The liability is no longer theoretical. If your AI-powered hiring tool consistently disadvantages a protected group, that is an employment claim. If your AI summarises a contract incorrectly and you act on it, that may be an errors and omissions claim. If your AI agent completes a commercial transaction it was not fully authorised to complete, the other party's claim against you stands regardless of what the agent was told to do.
What this demands of leaders: legal and compliance need a seat at the AI design table before deployment, not after an incident. Vendor contracts should address liability for wrong outputs, autonomous agent actions, and regulatory compliance. The NIST AI Risk Management Framework and EU AI Act compliance documentation are your first line of defence when a claim arrives.
Sources: Regulation (EU) 2024/1689 (official text); WilmerHale, Managing Legal Risk in the Age of Artificial Intelligence (February 2026); NIST AI Risk Management Framework (AI RMF).
Risk 6: The Environmental Liability Building Quietly in Your ESG Disclosures
AI infrastructure carries a largely undisclosed carbon and water footprint. If you have net-zero commitments, a large-scale AI rollout may already be quietly undermining them.
Key statistic: AI data centres are estimated to produce 32.6 to 79.7 million tonnes of CO2 in 2025 (journal Patterns, Dec 2025).
Most AI providers disclose almost nothing about per-query energy use or Scope 3 emissions. The Foundation Model Transparency Index's falling scores are partly a story about environmental non-disclosure. Beyond carbon, data centres draw heavily on water-stressed regions for cooling, and the rapid replacement cycle for AI-specific hardware creates a growing e-waste problem.
This creates three risks for any organisation with public sustainability commitments. First, a large-scale AI deployment may be quietly undermining net-zero targets in ways that will not become visible until the next reporting cycle. Second, as sustainability disclosure rules tighten, including the EU's Corporate Sustainability Reporting Directive already in force for large companies, AI-related emissions may need to appear in your Scope 3 accounting. Third, the gap between saying "we are committed to responsible AI" and being unable to account for what your AI infrastructure consumes will become increasingly hard to defend to investors and regulators.
What this demands of leaders: before scaling AI infrastructure, run a basic environmental footprint assessment. Ask vendors directly for per-query energy data and push back when they cannot provide it. Factor AI-related energy and emissions into your sustainability reporting now, before regulators require it.
Sources: journal Patterns (Cell Press), The Carbon and Water Footprints of Data Centers and What This Could Mean for AI (December 2025); Stanford HAI, 2026 AI Index — Research and Development Chapter (April 2026).
Coming next, Part 2 of 2: now that the six blind spots are mapped, the next issue sets out the five principles that close them, from building security architecture before you connect a single system, to putting legal and ESG into the design, not the aftermath.
The models are not plotting against you. The risks live in the gap between the pace of adoption and the depth of organisational readiness. The opportunity is real. So is the responsibility.


