Over the next few articles, I’m going to try to quantify the risks that go with AI initiatives.
There’s a lot to scared about (or at least uncertain). At the 30,000-foot level, it’s difficult to tell which of the many ways AI will use to kill us all, take our jobs, crash the economy, and put our companies out of business. At 30,000 feet, weather is quite different from weather on the ground.
That’s a roundabout way of saying that worrying about existential threats is a poor use of time. From the clouds, you will be redundant, dead, broke, or redundant, broke, and dead. Meanwhile, the AI being built on the ground (and HR) can wreak havoc. Enjoy the highbrow philosophy discussion. That’s not where the real work of AI integration happens.
If you’re alive, you might as well be championing the effective containment of AI risk. That’s what governance is all about. You can’t hide from the end of the world. You can invest the time and resources needed to understand and manage the things that are likely to go wrong.
In the early going, this will be a conversation about what could go wrong. As usual, the road to hell is paved with good intentions. The early LLM era notion that everyone could/should build their own agents in their own departments took hold. The idealistic people who are always early adopters seized the opportunities.
The problem is that individual initiatives reinforce organizational silos without ever looking at the overall system. There is no future in which corporate agents run independently or silos that remain intact. They will increasingly be called on to be a part of the company’s intelligence. They will be encumbered with the testing, maintenance, validation, and integration overheads that allow well-orchestrated behavior.
The thing being described as ‘context’ really means ‘all of the data in the organization.’
The most resilient organizations will not be those with the fewest AI mistakes. They will be those that make it extraordinarily difficult for a small mistake to become an organizational fact. The greater the potential consequence, the greater the evidence, authority, observability, and reversibility required before an agent may proceed.
That means taking a deep look at anything that touches/manipulates existing data. Errors that happen in the acquisition and replacement of data cascade. That means they start small and get bigger over time. The largest risk is that HR’s core data gets corrupted in a non recoverable way.
Cascading failure is like a snowball rolling downhill. Ungoverned changes can move easily between systems.
The most dangerous errors in HR don’t look dangerous. They begin as one incorrect fact in one highly connected field. The damage comes later, as other systems quietly accept it as truth. Employee identity, employment status, reporting relationships, and job classification all fall into this category.
Imagine an employee is assigned to the wrong manager during a reorganization. One field changes in the HRIS. The value is valid. No alarms sound.
The next day, identity systems synchronize. The new manager gains approval authority for timecards, expenses, leave, and performance reviews. The former manager loses it. Everything appears to work exactly as designed.
A few days later, organizational charts update. Headcount shifts. Management reports change. Workforce planning now assumes the wrong manager has another employee.
Performance season arrives. The wrong manager writes the review. Coaching recommendations, development plans, and career guidance all reflect the new reporting relationship.
Then compensation planning begins. Salary budgets move with the employee. Merit increases are approved. Finance signs off because every report matches the HR system.
Months later, succession plans, leadership dashboards, and organizational analytics all reflect the same mistake. When the company reorganizes again, the AI uses that history to recommend the next structure. Yesterday’s error becomes tomorrow’s evidence.
The original mistake wasn’t assigning the wrong manager. The mistake was allowing every downstream system to assume that one field represented unquestioned truth.
By the time someone notices, changing the manager field doesn’t repair the damage. Approvals have been granted. Reviews have been written. Budgets have shifted. Plans have changed. The history itself has been rewritten.
That is how a small data error becomes systemic corruption.
Here are a few other examples:
Employment status changes from Active to Terminated
One status change starts an automated chain reaction. Pay stops. Benefits disappear. Access is removed. Every downstream system assumes the termination was intentional.Job classification changes from Exempt to Non-Exempt
One field changes the rules. Payroll, overtime, compliance, and labor reporting all recalculate from the same bad assumption. The error grows with every pay period.Employee identity is merged with another employee
Two people become one record. Histories, permissions, payroll, and performance are blended together. Untangling them later may be impossible.Organization code changes incorrectly
The employee moves on paper, not in reality. Budgets, headcount, reporting, and workforce plans follow the data instead of the work.Candidate identity is matched to the wrong person (Recruiting)
The wrong candidate becomes the official candidate. Assessments, background checks, interview notes, and eventually the employee record all belong to the wrong person.Job requisition is assigned the wrong job family or level (Recruiting)
The hiring process starts from the wrong premise. Recruiting attracts the wrong people, compensation is built on the wrong market, and every decision that follows looks reasonable because the data agree with themselves.Candidate is incorrectly marked as “Not Eligible for Rehire” (Recruiting)
One flag quietly closes every future door. Recruiters never see the candidate. Managers never know the person applied. Years can pass before anyone questions the decision.
Each of these scenarios come from not having a clear picture of who has authority to change what and under which circumstances.
What’s at risk is the integrity of the HR database as a whole. As the company begins to lose faith in the data, HR’s ability to execute diminishes until there’s nothing left.
The next article will cover the 15 types of risk that the HR Department should manage.
Photo by Fellipe Ditadi
Photo by Jonathan Ouimet




