AI RISK · HUMAN FACTORS · TRAINING & ADVISORY

Closing the gap between AI Policies & Human Behaviours

Addressing the behavioural layer of AI risk, for regulated and risk-conscious organisations.

What is the risk?

Most organisations now have an AI policy. Far fewer know for certain what their people are really doing with AI, which tools they use, what data goes into them, and why capable staff work around the rules they’ve been given.

That gap, between what the policy says and how people actually behave, is where the real exposure sits. GDPR non-compliance, intellectual property leaks, and stalled adoption among uneasy staff are all challenges for AI strategies.

Technical controls and written policy, however good, are insufficient in isolation and can be perceived as compliance theatre.

Regulators will start with your governance structures and policies, but they will scrutinise whether this has been effectively communicated throughout your organisation too. However, compliance should be considered the floor we build from, not the ceiling we strive for. The risks beyond non-compliance, which are already materialising, have tangible financial, reputational, and operational consequences.

This is further complicated by nefarious actors using the technology maliciously.

There is a bigger picture, too. Technology is moving faster than our institutions can adapt, and the organisations that get AI adoption right now will be the ones still trusted when everyone else is catching up.

The solution?

Good looks like an organisation where AI is adopted with confidence, not anxiety. Where policy and behaviour are aligned, staff understand the tools they use and their limits, and leaders can evidence genuine control rather than the appearance of it. Where people are the strongest line of defence, not the weakest.

Recipient of the 2025 Imbert Award · Ambassador, Association of Security Consultants