The AI Use Cases That Look Harmless May Carry the Most Risk
Show notes
An AI system that affects human safety will usually attract attention. People recognize the stakes, involve the right reviewers, and ask what could go wrong.
A résumé-screening feature can receive a very different response. Someone in HR has hundreds of applications to review, sees an option that can speed up the work, and turns it on. The goal is not to take a major risk. It is to make a routine task more manageable. The problem is that the tool may be powered by a sophisticated AI model that introduces questions about discrimination, privacy, consent, and disclosure.
Dan Clarke, President of Truyo and IntraEdge Solutions, says this gap between perceived and actual risk is where companies often get into trouble. In a survey of public-sector organizations, his team found that respondents generally recognized systems related to human safety as high risk. Résumé screening and chatbots, however, were frequently ranked as having almost no risk.
That assumption changes how a use case is handled. When people recognize risk, they investigate it. When a feature feels ordinary, they may deploy it without asking which data it uses, whether the organization has permission to use that data, who could be affected, or what happens when the system makes a mistake.
Clarke joined Sachin Kamdar and Doyle Irvin on Building For Others to discuss why these quiet, everyday deployments deserve more attention, and what enterprises can do to govern AI without giving up its competitive benefits.
How Truyo Helps Companies See and Govern Their AI Use
Truyo’s approach to AI governance grew out of its work in enterprise privacy and consent. Clarke was originally recruited by Intel to help companies prepare for GDPR, and he sees substantial overlap between the privacy questions of that period and the governance questions companies face today.
The overlap begins with data. Before evaluating what a model can do, a company needs to know whether it had permission to use the underlying information in the first place. It also needs to understand where AI is operating across the organization. That is difficult when AI capabilities are embedded in software employees already use and can be enabled without a formal implementation project.
Truyo’s platform helps companies discover and maintain an inventory of AI use cases. Once a company knows that it is using AI for résumé screening, customer support, image recognition, or another workflow, it can assess the relevant business and regulatory risks. It can document how the decision was made, trace consent and data permissions, apply controls, and provide the appropriate notice to the people affected.
This inventory is foundational to Clarke’s view of governance. Many organizations assign AI oversight to IT, but important use cases regularly emerge in HR, marketing, and finance. Employees in those departments may not realize that a feature qualifies as AI or that switching it on introduces new obligations. Truyo combines automated scanning with the company’s existing privacy infrastructure to make more of that activity visible.
The platform also uses both deterministic controls and AI-based analysis. Fixed rules are effective for structured information such as Social Security numbers or credit card numbers. They are less effective when sensitive information appears in ordinary language. A sentence about being unable to ride an exercise bike because of a broken leg may contain relevant health information, even though it does not match a clean numerical pattern. Semantic analysis can detect context that traditional compliance rules miss.
Gartner recently named Truyo a Leader in its inaugural Magic Quadrant for AI Governance Platforms. Of the companies evaluated, Truyo joined IBM and ServiceNow in the Leaders quadrant. Clarke attributes part of Truyo’s differentiated approach to the way it brings privacy, consent, and AI governance together rather than treating them as separate programs.
The Rest of the Discussion
- Many AI lawsuits are really about data permission. Clarke argued that cases involving chatbots, model training, and automated screening often turn on familiar privacy and consent questions. The presence of AI may be new, but the central issue is frequently whether a company had the right to use the data in that way.
- The United States needs a consistent federal standard. A patchwork of state laws may create more demand for automated compliance platforms, but Clarke still supports federal legislation. Companies trying to comply in good faith face 21 state laws, or 22 for social media companies, with meaningful differences among them.
- AI enforcement could be more aggressive than privacy enforcement. Clarke recounted a conversation with a state attorney general who said voters care about AI in a way they historically have not cared about privacy. That public concern creates pressure for elected officials and regulators to act. Clarke expects a significant wave of US enforcement, while Europe may apply the EU AI Act as aggressively as, or more aggressively than, GDPR.
- Open-weight models bring both opportunity and additional governance challenges. These models expand access and give companies more options, but altering model parameters can make bias, hallucination, and guardrail problems harder to manage. Clarke’s emphasis is on governing how a model will be used, especially in situations involving employment, health, housing, finance, or human safety.
- Even a model’s creators may not understand how it reaches a result. Clarke described a facial-recognition system that unexpectedly compared features of human faces with characteristics associated with different dog breeds. The system was fast and accurate, but its creators could not explain why it had developed that method. The story illustrates why companies cannot base governance on an assumption that model behavior will always be interpretable.
- AI may be necessary to govern AI. Deterministic controls still matter and should remain active. But fixed rules cannot understand every way a person might express sensitive information. Clarke believes AI-based sentiment and semantic analysis can complement those rules, particularly as enterprise AI use becomes too varied and fast-moving for manual review alone.
- Disclosure is one of the simplest protections available. Companies sometimes hesitate to say that AI is screening a résumé or powering a chatbot. Clarke recommends the opposite approach. Clear disclosure gives applicants and customers useful information and provides the company with a stronger legal position than trying to obscure AI’s role.
Clarke’s central message is not that companies should slow down their use of AI. He believes AI offers a competitive advantage that companies need to embrace. But if they wait to think about governance until after a harmful outcome, they risk litigation, regulatory action, and a loss of internal confidence that can stall the entire program.
The safer path begins with visibility: know where AI is being used, understand the data and people involved, document the risks, and put the right controls in place before an apparently harmless feature becomes a serious problem.
About the guest: Dan Clarke is President of Truyo and IntraEdge Solutions and a nine-time CEO. His work spans enterprise privacy, consent, and AI governance. Learn more about Truyo and connect with Dan on LinkedIn: https://www.linkedin.com/in/danclarke/
Transcript
More podcasts
Customer success stories
Transform your workflows today
Learn how we can help you modernize your business.


