1. Drafting and summarising
Documents, emails, meeting notes, first-pass reports. The fastest value and the widest use. It brings output nobody checked and business information pasted somewhere new.
Everyone lists the uses. Few list the cost.
The five things businesses use AI for, what each is good at, and the entry it puts on your risk register. Free, no form.
An AI use case is a specific job a business hands to AI: draft this, answer that, score these, act on those. Most AI in the workplace falls into one of five families. Most published lists of AI applications in business sort them by department and stop there. The useful sort is by what each one changes about your exposure, because a drafting tool and an agent with system access are not the same decision, even when the same team asks for both.
Documents, emails, meeting notes, first-pass reports. The fastest value and the widest use. It brings output nobody checked and business information pasted somewhere new.
Support chat, sales questions, self-service. It brings a promise your business has to honour, because what the AI tells a customer is what the business said.
Code, queries, configuration. Fast, and it brings dependence on model vendors you never contracted, as the September outages showed.
Triage, credit, prioritisation, shortlisting. It brings the accountability question: who owns the answer when it is wrong, and can anyone explain how it was reached.
Systems that take steps, not just suggest them. The largest gain and the widest exposure. Guardrails and safeguards are the entry here.
How to read one
Search for AI use cases, or generative AI use cases, and you get a department-by-department menu. Marketing does content, finance does forecasting, HR does screening. It is accurate and it is only the upside column.
The half that decides whether a use case is worth it is what it changes about your exposure: the data it touches, the decision it influences, the customer it speaks to, the supplier it depends on.
The pairing
Every family above ships with its entry. Write both down at the same time and the register stays current by default. Write only the use case and the register goes stale the day the tool goes live.
Agents make the gap widest. EY found 26% of large US companies using agentic AI cannot detect unauthorised agents running inside their own organisation.
Choosing
Not the one with the best demo. The one attached to an objective you are already trying to move, where you can name the measure and live with the risk column.
The sequence for putting it in place is on the adoption page. The risks other people have already found are in the AI risk series, including the ones nobody chose, like shadow AI.
FAQs
Five families cover most of it: drafting and summarising, customer-facing answers, technical and coding work, decisions and scoring, and agents that act.
The one attached to an objective you are already trying to move, where you can name the measure and accept the risk it brings.
Each family has its own: unchecked output and data exposure for drafting, promises made to customers for chat, vendor dependence for technical work, accountability for decisions, and unwatched action for agents.
The risks under each objective, scored, with a safeguard drafted for every one. Free.
AI strategy and AI risk
An AI strategy that starts from your objectives
The series hub: five steps, a one-page template, and one decision per objective.
AI adoption without inheriting the risk
The five steps in order, and the risk each one introduces.
AI maturity: where you actually are
Five levels of governance maturity and four questions to place your business.
Shadow AI: the risk your register does not have
The use cases nobody approved, and what to do about them.
Guardrails, safeguards, controls
What AI needs around it, in plain words.
The AI risk register
What every entry carries, with worked examples.
The real risks of AI for a business
The AI risk series hub.