Trust, Security & Regulation
AI Risks and Limitations: What You Need to Know and How to Mitigate Them
The Four Main Risk Areas of AI at a Glance
AI risks fall into four categories: content errors (hallucination), systematic distortion (bias), human misalignment (over-reliance and automation bias), and technical and legal risk (security, data protection, liability). None of these is a bug that the next update will fix. They follow from how today's models work: they learn statistical patterns from data rather than understanding truth or causality.
- Hallucination: the AI produces false but convincingly worded content.
- Bias: societal and data-driven distortions are reproduced.
- Over-reliance: people accept AI output uncritically.
- Security and data protection: new attack surfaces and legal obligations.
Hallucination: When AI Is Confidently Wrong
Large language models generate text by predicting the statistically most likely next word. They have no internal model of facts and no concept of truth, so they state falsehoods with the same fluency as correct information: fabricated studies, non-existent court rulings, false quotes, plausible but wrong figures. This is especially dangerous in law, medicine and finance, where a single error is costly and fluent language creates a false impression of reliability.
- Mitigate: ground answers in verified sources (retrieval-augmented generation) and require citations.
- Always verify facts, figures, names and quotes independently; never accept them unchecked.
- Use AI for drafts, summaries and ideas, not as a final source of truth.
- Note: no prompt or update removes hallucination entirely; it becomes rarer, not zero.
Bias and Distortion: Prejudice From the Data
Models learn from vast amounts of text that carry societal stereotypes, historical inequalities and gaps. They reproduce these patterns, for example when screening job applications, in credit-scoring logic, in image descriptions, or in quality for smaller languages. Relevant for Switzerland: models are usually trained heavily on English, while Swiss German, Romansh and local legal and administrative contexts are underrepresented, leading to subtly wrong or ill-fitting results.
- For decisions about people (HR, credit, insurance), the EU AI Act treats such applications as high-risk.
- The Swiss revFADP gives individuals rights regarding automated individual decisions, including information and human review.
- Test and document outputs across different groups instead of assuming fairness.
- Sovereign, multilingual efforts such as the open Swiss model Apertus (ETH Zurich, EPFL) address language and context gaps.
Over-Reliance: The Risk of Blind Trust
Automation bias is the human tendency to accept AI suggestions uncritically, precisely because they sound competent and fluent. The effects creep in: expertise atrophies (de-skilling), errors go undetected, and accountability blurs when no one can say who actually made the decision. Paradoxically, the more convincing and convenient a system feels, the greater the risk that its errors flow unchecked into real decisions.
- Assign final human accountability: AI proposes, a human decides and is responsible.
- Actively maintain skills so teams can still judge and correct AI output.
- For high stakes, build in deliberate friction: second opinion, four-eyes principle, required justification.
Security and Data Protection: New Attack Surfaces
AI creates its own security risks. In prompt injection, attackers hide instructions inside web pages, documents or emails that an AI assistant then executes as commands, for example to exfiltrate data or trigger actions. Add to this data leakage through inputs to cloud models, jailbreaks, insecure agents with tool access, and poisoned training data. On data protection: entering personal data or trade secrets into an external model can breach the Swiss revFADP without a proper legal basis.
- Never enter sensitive personal or business data into consumer chatbots; use business tiers with a data-processing agreement.
- Clarify data location, retention and whether your inputs are used for training; use opt-outs.
- Design agents and integrations on least-privilege principles and constrain outbound actions.
- Run a data protection impact assessment for risky use cases; the FDPIC is the Swiss supervisory authority.
Limits of AI: What Language Models Fundamentally Cannot Do
Beyond risks, AI models have hard, by-design limits. They do not understand causality but detect correlations; they know the world only up to a knowledge cut-off and, without connected tools, no real-time events; they do not calculate reliably; and they are non-deterministic, so the same question can yield different answers. Crucially, a model cannot reliably gauge its own uncertainty and rarely warns you when it hits a boundary.
- No genuine understanding or causality, only pattern continuation.
- Knowledge cut-off and limited context window: long or current context is lost.
- Unreliable at mathematics, exact logic and reproducible results.
- No reliable self-assessment of its own reliability or sources.
Mitigate Responsibly: A Governance Roadmap
Mitigating risk does not mean abandoning AI, but deploying it with judgement and controls. A workable framework classifies each use case by risk, defines human oversight, and documents decisions so they remain auditable. The EU AI Act (extraterritorial, reaching Swiss providers with EU ties) and the revFADP set the legal frame; programmes such as Innosuisse and Swiss research provide trustworthy building blocks.
- Classify each use case by risk and rule out unsuitable uses (e.g. autonomous high-risk decisions).
- Embed human-in-the-loop, source grounding and fact-checking as standard.
- Label AI use transparently and train staff on limits and risks.
- Establish a data protection impact assessment, logging, monitoring and regular review (including red-teaming).
- Vet vendors and models: data location, security, traceability and exit options.
Frequently asked questions
What is an AI hallucination?
A hallucination is a false but convincingly worded statement from an AI model, such as a fabricated source, a wrong quote or a non-existent figure. It arises because language models generate likely word sequences and have no concept of truth. Always verify factual claims independently.
Can AI risks be eliminated completely?
No. Hallucination, bias and uncertainty follow from how today's models work and can be reduced but not brought to zero. Responsible use means managing risk: human oversight, source grounding, clear boundaries, data protection and monitoring, rather than expecting an error-free system.
What are the legal rules in Switzerland for AI risks?
For personal data the Swiss revFADP applies, with rights around automated decisions; the supervisory authority is the FDPIC. Additionally, the EU AI Act applies extraterritorially and affects Swiss providers with EU ties, with stricter duties for high-risk uses. Do not use the term GDPR for Swiss matters.
What does over-reliance or automation bias mean?
It is the tendency to accept AI output uncritically because it sounds competent. Consequences include undetected errors, loss of skills and blurred accountability. Remedies: a human final decision, deliberate checks for high-stakes cases and maintaining your own expertise.
How do I protect company data when using AI?
Do not enter sensitive personal or business data into consumer chatbots. Use business tiers with a data-processing agreement, clarify data location, retention and training opt-out, limit agent permissions, and run a data protection impact assessment for risky cases. Also watch for prompt injection via external content.
What can AI fundamentally not do?
Language models do not understand causality, know the world only up to a knowledge cut-off, do not calculate reliably, do not always give reproducible answers and cannot reliably judge their own uncertainty. For exact, current or legally binding tasks they need connected tools and human review.
Key terms in the glossary
Practical AI for your business
From idea to implementation – we show you what is concretely possible in your case.
Request a demo