Top News

If Nobody Owns the AI Risk, Your Company Does Not Have an AI Strategy

0
Share

The Tumbler Ridge lawsuits expose the weakness in treating artificial intelligence as a tool without assigning human accountability.

Companies love to say they have an AI strategy. Usually they mean they have licenses, pilots, integrations and a slide deck about productivity.

That is not a strategy if nobody owns the downside.

The new wave of lawsuits against OpenAI tied to the Tumbler Ridge mass shooting should make executives uncomfortable for a reason that has little to do with predicting the legal outcome. The cases expose the gap between deploying an AI system and building a management system around it.

Thirty additional lawsuits reportedly bring the number of Tumbler Ridge cases against OpenAI and CEO Sam Altman to 37. The allegations are disputed and unproven. The court may reject some or many of them.

That uncertainty does not rescue companies from the obvious management question: when your AI detects or creates a serious problem, who has the authority to act?

The most dangerous AI policy is nobody knew who owned it

Organizations do not tolerate that answer in other high-risk areas.

If a payment system flags fraud, somebody owns the alert. If malware is detected, somebody can isolate a device. If a worker reports harassment, there is supposed to be an escalation path. If a factory safety control fails, responsibility is not left to whichever employee happens to be online.

Yet many companies deploy AI with no equivalent operating discipline.

They rely on vendor terms, default settings and a vague instruction to use good judgment.

That is not governance. It is hope.

What is actually established in Tumbler Ridge

The February 10 attack in Tumbler Ridge, British Columbia, killed eight victims. RCMP says the shooter also died and two additional victims were seriously injured.

OpenAI has acknowledged that an account associated with the shooter was banned in June 2025 after activity violated company rules. The company considered contacting law enforcement but decided the case did not meet its referral threshold at the time.

CEO Sam Altman later apologized for not notifying authorities.

The plaintiffs allege far more. An April complaint states that multiple safety reviewers recommended contacting the RCMP and that company leadership overruled that recommendation. It includes claims for negligence, product liability and aiding and abetting.

That aiding-and-abetting theory is not new to the September filings, despite some recent coverage saying otherwise. It appears in the April complaint.

OpenAI disputes claims about how the decision was made and denies that politics or public relations drove it. None of those disputed allegations should be treated as findings of fact.

The management failure companies should fear is ambiguity

The most important part of the story for business leaders is not the specific legal theory. It is the anatomy of an escalation dispute.

A system flags something. Human specialists review it. They form a recommendation. Leadership has authority. A decision is made. Later, the decision becomes the centre of a lawsuit.

Every company using AI should be able to map its own version of that chain.

Who sees the alert? What threshold moves it to a human? Who makes the final call? Can that person override specialists? What record explains the override? Who can disable the service? When is legal counsel involved?

If you cannot draw that flow on one page, your AI program is less mature than you think.

Stop hiding behind the vendor

Another weak excuse is the vendor handles safety.

Maybe the vendor handles model-level safeguards. That does not mean it understands your customer, your employee, your industry or the consequences of a failure in your workflow.

A bank using AI for customer interactions has different obligations from a retail store using AI to draft product descriptions. A school technology provider dealing with minors has a different risk profile from an internal coding assistant.

NIST’s AI Risk Management Framework is useful precisely because it does not pretend risk belongs only to model developers. It is designed to help organizations manage AI in design, development, deployment and use.

Translation: if you chose the use case, you own part of the risk.

An AI strategy needs a kill switch and a phone tree

Executives often want sophisticated principles. Start with something more useful.

  • Every production AI system needs a named owner.
  • Every high-impact use case needs a defined human-review point.
  • Every serious incident needs an escalation contact.
  • Every critical vendor needs a real support route, not just a generic help form.
  • Every customer-facing AI system needs a practical way to be disabled or restricted.
  • Every important decision needs enough logging to explain what happened.

That is not glamorous. It is what makes a system governable.

A company that can launch an AI agent in a day but cannot shut it down in an hour does not have agility. It has exposure.

Privacy is where lazy safety thinking gets exposed

Some leaders will respond to AI risk by saying monitor everything.

That is not a mature answer either.

The Office of the Privacy Commissioner of Canada says organizations using generative AI remain subject to applicable privacy law and should consider necessity, proportionality, transparency and safeguards.

If you collect every prompt, retain it indefinitely and make it broadly available to managers, you may solve one hypothetical problem by creating a real privacy problem.

Good governance defines what is monitored, why it is monitored, who can see it and when it is deleted.

Regulators are already asking for evidence

The Federal Trade Commission’s inquiry into AI companion chatbots asks companies about testing, monitoring, negative impacts, rule enforcement and data practices.

Notice what is missing from that list: inspirational speeches about the future of AI.

Regulators want to know what you tested and what you do when the product misbehaves.

Customers, insurers, boards and plaintiffs’ lawyers will ask versions of the same questions.

Boards should stop approving AI as a category

Another bad habit is approving AI in the abstract.

There is no meaningful risk rating for AI as a category. There are use cases.

An employee using AI to rewrite a meeting note is not the same as an AI agent that sends messages to customers, changes account settings or makes recommendations about people.

Boards and executives should demand a use-case inventory, not a slogan.

Classify the systems by impact. Put serious controls around the serious ones. Keep the low-risk ones lightweight. That is how you move fast without pretending all risks are equal.

The court case may change. The accountability gap will not

The Tumbler Ridge litigation could look very different a year from now. Some allegations may fail. Some legal claims may be dismissed. Discovery may support or contradict what has been alleged.

Businesses should not copy policy from a complaint.

They should recognize the management problem the complaint makes visible.

If a company deploys AI into consequential interactions and nobody has clear authority to investigate, escalate, override, preserve records or shut the system down, then nobody really owns the risk.

And if nobody owns the AI risk, the company does not have an AI strategy. It has a feature rollout.

Related Posts