AI risk is being underestimated when organisations focus only on near-term usage and ignore how quickly adoption is expanding. Warning signs include weak governance, limited audit coverage, poor visibility into data lineage, and no clear process for reviewing model outputs or decisions. If teams cannot explain where AI is used or who approves it, the risk is already outpacing control.
What the planning process should expose before AI use becomes invisible
Underestimation usually shows up as a planning process that treats AI as a narrow tool choice instead of an expanding operational dependency. If the audit plan cannot identify where models are embedded, which business decisions they influence, and which datasets or prompts shape outputs, the organisation is already planning from an incomplete inventory. That is a control failure, not just a documentation gap.
Weak visibility also tends to correlate with poor governance over ownership, review, and change approval. A mature plan should force teams to explain where AI is used, who can approve it, and what evidence exists for testing output quality and decision impact. If those answers are vague, the audit scope is likely too small for the exposure.
One useful warning signal is the absence of lineage and exception tracking. Ultimate Guide to NHIs, Regulatory and Audit Perspectives is useful here because the same audit discipline that applies to governed identities also applies to AI-enabled processes: if you cannot trace inputs, approvals, and downstream use, you cannot credibly claim the control environment is understood.
Where underestimated AI risk shows up in audit coverage and control design
The clearest sign of underestimation is when the audit plan checks whether AI exists, but not whether it is being used in ways that change control risk. Limited coverage of model outputs, human review, exception handling, and fallback decisions means the plan is measuring adoption, not assurance. That misses the most material failure mode: AI influencing outcomes without a reliable review path.
Another sign is shallow testing of data and output quality. Audit teams should be looking for whether the organisation can explain training, retrieval, and decision inputs well enough to assess reliability, bias, and drift. If reviewers only ask whether a policy exists, rather than whether the operating process is producing evidence, the audit will understate the real control surface.
The most useful sign of maturity is whether the audit plan follows the process boundary, not the procurement boundary. A tool that began as a pilot can become embedded in reporting, customer support, code generation, or exception triage very quickly. 2026 Identity Security Trends & Predictions and Cloud Compliance Pulse 2025 both reinforce the practical point that governance needs to keep pace with operational adoption, not lag behind it.
Risk and Threat Considerations
AI risk is underestimated when the organisation assumes limited usage today means limited exposure tomorrow. In practice, fast adoption, opaque dependencies, and weak review processes can quickly turn an isolated AI pilot into a control gap that affects data handling, decision integrity, and accountability.
Failure mechanism: The audit plan scopes AI too narrowly, so it misses embedded use cases, unreviewed outputs, poor data lineage, and decision paths that no longer have meaningful human challenge or ownership.
Impact: The organisation may ship decisions it cannot explain, overlook biased or erroneous outputs, and fail to detect where AI has become material to business, compliance, or customer outcomes.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST AI RMF, NIST AI 600-1, NIST CSF 2.0 and CIS Controls v8 set the technical controls, while ISO/IEC 42001:2023 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST AI RMF | GOVERN — Govern | AI governance and accountability are central to audit planning. |
| Recommendation — Establish AI governance roles, risk ownership, and oversight for AI use in audit scope. | ||
| NIST AI 600-1 | GV.1 — Governance and Risk Management | The question is about underestimating AI risk in planning and assurance. |
| Recommendation — Align audit planning to AI governance, risk identification, and documented review expectations. | ||
| NIST CSF 2.0 | GV.RM-01 — Risk Management Strategy | Audit planning should reflect how AI risk is identified and prioritised across the organisation. |
| Recommendation — Use the risk strategy to decide which AI uses require deeper audit coverage. | ||
| ISO/IEC 42001:2023 | 4.1 — Understanding the organisation and its context | AI risk planning depends on understanding where AI is actually used and what context it affects. |
| Recommendation — Map AI use cases and their business context before finalising audit scope. | ||
| CIS Controls v8 | 6.1 — Establish and Maintain an Inventory of Enterprise Assets | AI underestimation often starts with incomplete visibility into deployed systems and tools. |
| Recommendation — Inventory AI-enabled systems and dependencies before deciding audit coverage. | ||
Practitioner Guidance
What to verify: Treat audit planning as a coverage exercise, not a policy exercise. Verify that the scope includes hidden or embedded AI use, named business owners, output review steps, escalation paths, and evidence of model or prompt change control.
Decision rule: If a team cannot explain where AI is used, what decisions it influences, and who signs off on exceptions, expand the audit scope immediately. If they can explain the use case but not the review evidence, prioritise control testing over further discovery.
What practitioners underestimate: The biggest gap is often not model sophistication, but the speed at which AI moves from “experimental” to operational without equivalent audit depth. DeepSeek breach is a useful reminder that AI-related exposure often becomes visible only when logs, keys, or operational traces reveal how much was reachable or exposed.
Practitioner takeaway: If the audit plan cannot trace AI use, ownership, and review evidence across the actual business process, it is already behind the risk, regardless of how small the current deployment looks.