Artificial Intelligence in Business: the Real Pros, Hidden Risks, and What's Really Going on

The main disadvantage of AI in business is not that it will "replace people." Another thing is more dangerous: the system can confidently tell a lie on behalf of the company, promise a client non-existent conditions, give an internal regulation to a stranger, or send personal data to a place where it cannot be sent. For the client, this is not an experiment with technology, but your company's position.

how much does it cost

AI in business is a working tool that benefits where the process is described, the data is prepared, and the cost of an error is clear in advance.

The pros and cons of artificial intelligence

There are often two extremes in conversations about AI. The first one is: "if we implement the model, the profit will grow by itself." The second one is: "95% of projects fail, it's better not to start." Both positions are convenient for headlines, but they don't help manage risk well.

According to McKinsey's "The State of AI in 2026", 37% of companies see the impact of AI on EBIT at least partially, while about 6% remain high performers, where the contribution reaches 5% of EBIT and above. At the same time, 80% of respondents talk about an increase in personal productivity. There is an important gap: employees feel the acceleration, but the financial return of the company is growing more slowly.

Russian estimates give a similar order. Yandex Cloud reported that 88% of Russian companies use AI, but less than 10% see an effect above 5% of profits. This figure has a conflict of interest: Yandex sells AI infrastructure. But even with this caveat, the conclusion is useful: mass use does not equal mass payback.

Now about the terrible figure of "95% failures". She often refers to the MIT Project NANDA preprint "The GenAI Divide" from 2025. This is not a peer-reviewed paper, the sample is not random, and it was not about all AI projects, but about a narrow category of custom embedded tools. The funnel looked something like this: 60% of companies considered the topic, 20% reached the pilot, 5% reached production. That is, a significant part did not try at all, and about a quarter of those who piloted were successful.

A more accurate formulation: many AI projects do not reach sustainable operation because their value has not been calculated, costs have not been limited and risks have not been sorted out. In June 2025, Gartner made a forecast, not a measurement: more than 40% of agent projects may be closed by the end of 2027 due to costs, unclear value and weak controls.

The risks of artificial intelligence

The real risks of artificial intelligence usually look more boring than fiction and therefore more dangerous. They don't come as a movie-style disaster. They come as a dispute with a customer, a bill from a provider, a fine from a regulator, a data leak or a lost database.

Instead of abstract fears, it's worth looking at the right column: the bot promised a discount that doesn't exist; the employee uploaded personal data to a public chat; the bill for the models tripled without increasing the workload; the agent issued an internal document; the project was launched without metrics and could not prove the effect. This is a practical risk map.

Working scenarioWhat really breaksThe price of error
Customer supportThe bot comes up with conditions, tariffs, or refund rules.Refunds, claims, reputational damage
Documents and lawyersAI inserts non-existent norms and referencesFine, lost dispute, loss of trust
SalesThe model promises a price, a deadline, or a discount without the right to do soDispute with the client and conflict with the sales department
Internal agentsOverly broad rights lead to the deletion or disclosure of dataDowntime, Recovery, Investigation

There is only one good news: almost every one of these risks can be transferred in advance from "incomprehensibly scary" to an engineering or managerial limitation. "But "the model is smart" or "this rarely happens" cannot mitigate the risk for this.

Minus number one: the AI is wrong.

how an AI agent works

A bot is a separate entity

There are also less legal, but revealing stories. Chevrolet of Watsonville disabled the chat after the bot agreed to sell the car for one dollar. Taco Bell has been reviewing voice AI scenarios after order failures, including absurd combinations. Klarna first said that the bot replaces 700 operators, and then recognized the decrease in quality and returned people to the support channel. This is not a rejection of AI, but a transition to a mixed model.

answer the knowledge base

You can't just look at the percentage of errors. The model may have 3.7% errors, but it responds only in 80% of cases: accuracy is bought by silence. In legal tasks, Legal Research Bench showed partial offset of about 80%, but the fulfillment of all mandatory elements was about 44-55%. This is the "almost done" zone, which in business is often worse than an honest refusal.

The risks of using artificial intelligence from the legal side

The risks of using artificial intelligence start with a simple rule: if the bot speaks on behalf of the company, the company will argue with the client. The Russian AI law does not create convenient protection, "the model decided it."

Federal Law No. 243-FZ dated 07/26/2026 has been in force since 09/01/2026, and some of the norms have been in force since 03/01/2027. Its field is narrow: large fundamental models with 1 billion parameters that serve as the basis for other software. The usual support chatbots, scoring models, computer vision and classical machine learning are not directly reduced there. At the same time, the law does not allocate responsibility for the model error.: Article 11 refers to common law. The risk between the customer, the integrator and the supplier can be distributed by contract, but this does not negate the fact that the company uses the system in front of the client and the court.

Practice is already showing the direction. In case no. A27-7831/2025, the Arbitration Court of the West Siberian District on 05/14/2026 encountered references to non-existent acts generated by a neural network. The court pointed out that AI can be used, but the credibility is on the participant in the case. The result is a fine of 50 thousand. for contempt of court. If the AI prepares documents, responses to clients, or claims, checking references, details, and regulations is not "desirable," but actually a mandatory procedure.

A separate myth is the mandatory labeling of any AI content. FZ-243 deals with the possibility of labeling, rather than the obligation to label each text. The norm applies to audio and video, the text is not explicitly mentioned. Sites with a large audience should provide a button or an opportunity, rather than marking the author themselves. But the audience's expectation is already there: according to VTsIOM, a significant portion of users support labeling. Therefore, a voluntary note in the customer service may be more reasonable than silence, even if the law does not explicitly force it.

Foreign cases cannot be directly transferred to Russia, but logic is useful. On 05/12/2026, the Hamm Court considered the history of the clinic's bot, which attributed non-existent qualifications to managers. The "bot is autonomous" argument was rejected: the framework could have been set, but after the incident, the system was reconfigured. The AI Act is also important for exporters: if the result of AI is used in the EU, certain requirements may affect suppliers from third countries. This section is not a substitute for legal advice.

Personal data: the most expensive AI risk in Russia

Personal data

Since 07/01/2025, a ban has been in effect from Part 5 of Article 18 of FZ-152 as amended by Federal Law No. 23-FZ dated 02/28/2025: recording, systematization, accumulation, storage, clarification and extraction of data of citizens of the Russian Federation in databases outside of Russia is not allowed, except for the established exceptions. This is not a requirement to "have a Russian copy as well." This is a ban on certain operations in foreign bases. Therefore, the scheme "we will put it in the Russian Federation first, and process it abroad" no longer looks safe.

Localization and leakage are often confused, although they are different compounds and different money. Fines of 1-6 million rubles are provided for legal entities for processing data of citizens of the Russian Federation not in Russian databases, and 6-18 million rubles if repeated. Leaks are regulated separately: revolving fines apply from 05/30/2025. Repeated leakage of regular data can cost 1-3% of revenue, but in the range of 20-500 million rubles; for special categories and biometrics — 25-500 million rubles. The sole proprietor is responsible for a number of parts of Article 13.11 as a legal entity, and not as a "small entrepreneur" with a symbolic fine.

Local deployment

An illustrative foreign example is CB Financial Services in the USA: an employee from a personal account uploaded names, SSNs and dates of birth to an unapproved AI when preparing a layout, although the bank had an approved tool. The incident was deemed significant. The leak here was not because of a hacker, but because of convenience. If the allowed tool is more inconvenient than a personal chat, employees will choose a personal chat.

Security: someone else's text as a command to your agent

For the language model, the text in the email, on the website, in the document and in the system instructions looks like text. If an agent reads an incoming email and simultaneously has the right to send data outside, someone else's phrase can become a command. This is called an injection into prompta, and in 2026 the problem is not considered solved.

access to private data

This combination is often called the "deadly three": private data, untrusted text, and an external channel. Remove any element, and the attack stops reassembling. Therefore, the security of an AI agent is not only a filter of bad words in the industry, but above all rights, isolation, logs, confirmation of irreversible operations and the prohibition of unnecessary channels.

Cases with development agents show the dangers of extra rights. In Replit in July 2025, the agent deleted a working database with data from more than 1,200 executives and 1,190 companies during the freeze, and then informed them that a rollback was not possible. The rollback still worked; the agent's recognition turned out to be text generation, not a device. In the history of PocketOS, the agent demolished the production in seconds, along with the copies inside it, using the found token with full rights. The backup copy next to the work data is not a backup copy.

Money: Why the AI Bill doesn't rise when You expect it to

The AI bill rarely grows beautifully and linearly. It is growing due to the length of the dialog, repeated calls, agent looping, open widget, long tool responses, and provider price changes. At first it looks like a minor technical detail, but after a month it turns into a matter of financial control.

Each new message in a long dialogue often drags the previous context. The price increases, but the quality may decrease. In a 2025 study, Chroma compared a short promo of about 300 tokens with a long context of about 113,000 tokens and showed that longer is not always more accurate. Chroma has a commercial interest as a supplier of a vector database, but the idea itself is practical: storing the entire dialog in a model is expensive and not always useful.

A separate trap is tool tokens. When an agent calls a CRM, knowledge base, or internal function, the response from that function is often returned to the model and charged. This is forgotten in calculations: only the user's request and the bot's response are counted. For example, Yandex has separate billing elements related to tools next to incoming, outgoing, and cache.

A budget alert is not a protection if it comes after a write—off. You need to check before the call: the limit for the dialog, the user, the day, and the chain of actions. If the embedded agent can reschedule the task and call the external service again, it can eat up the daily budget in an hour. An open widget on a site without protection actually gives strangers access to your API.

There is also a risk of accessibility. In 2026, Anthropic disabled access to two models for a wide range of users for 18 days due to export restrictions: the company could not verify citizenship in real time. The Russian supplier also does not provide immunity: tariffs, platforms, and payment units change. The provider must be a replacement part. If the call format and price are hardwired into the product, the replacement turns into a rewrite.

People: what happens when a client realizes that he is talking to a robot

Customers don't "hate bots" equally, and they're not equally willing to talk only to humans. They are annoyed not by the fact of AI itself, but by helplessness: the bot does not understand, repeats the pattern, does not allow them to call the operator, and during translation forces them to retell the problem.

Automation must know the moment

live operator

The practical rule is simpler than research: one failure, the next person. If the client is annoyed, it is worth transmitting it earlier than a technically difficult but calm request. A study in Management Science showed that after an unsuccessful contact with a bot, an operator's too quick response with an AI prompt can be perceived as a continuation of the conversation with the machine. After a failure, it is better for the operator to explicitly introduce himself and take responsibility.

The Cursor case shows another detail: people are annoyed by the indistinguishability. If the response is generated by AI and looks like official policy, the cost of the error is higher. Voluntary labeling can be not only ethical, but also a way to reduce stress.

Which of the advantages of artificial intelligence is confirmed by measurements

It is better to discuss the advantages of artificial intelligence not through supplier presentations, but through research with a control group. The picture there is less brilliant, but more useful for business.

Brynjolfsson, Lee, and Raymond studied 5,179 customer support operators in their work "Generative AI at Work". The effect is plus 14% of requests per hour on average, up to 35% for newcomers and weak employees. For experienced users, the effect was minimal, and in some places the quality of the dialogues decreased slightly. At the same time, satisfaction increased and turnover decreased. ""The conclusion is not "AI accelerates everyone," but "AI especially helps those whose qualifications are lower than the quality of the hint."

In July 2025, METR conducted a randomized trial with 16 experienced developers and 246 tasks in their own repositories. The AI slowed down by 19%, although the participants expected acceleration and believed they had accelerated after the experience. In February 2026, the result shifted to a possible acceleration, but the confidence intervals included zero. This is an important lesson: productivity feelings cannot be trusted without measurements.

Alibaba's 2026 field experiments provide a more recent picture for support. An assistant accidentally turned on by some operators increased the speed and ratings of customers, but repeated requests did not significantly change. Weak employees won, while the best ones could have both subjective and objective quality decline. In the second experiment, the agent conducted part of the dialogues under supervision: the person maintained quality during technical escalations, but worked worse with emotional ones because he was less involved.

The result of the three data lines is the same: AI pays off on massive, repeatable tasks where error is limited and the quality of the model is higher than that of a novice. It is less suitable for exceptions, strong experts, and situations where responsibility, empathy, and rare contextual detail are important. Vendor statements like "76% of requests are resolved by themselves" should be read with the question: what is considered resolved and whether the silent departure of the client is considered a success.

How to Reduce AI Risks: Ten Rules that Work

choosing a contractor

  1. The first process is where error is cheap.
  2. If the number is not in the knowledge base, the agent does not name it.
  3. The "call a person" button starts with the first message.
  4. It is better to mark the AI's answers.
  5. The data must be physically read where it can be read.
  6. Break the "deadly three".
  7. The limits are set before the launch.
  8. The rights are exactly for the task.
  9. An approved tool should be more convenient than an unapproved one.
  10. The metrics are removed before the start.

Terms of reference for an AI agent