IRM'S VIEW: On AI, human agency and the future of work

At a recent Institute of Risk Management roundtable with a delegation from the British Malaysian Chamber of Commerce, we discussed human capital and people risk, followed by cyber and AI. During the conversation, I suggested that, increasingly, these are not separate subjects at all. AI risk is people risk.

That may sound counterintuitive since the issues around AI are usually approached as a technology risk, but as AI moves from being a tool we occasionally consult to something that is embedded in everyday work and decision-making, it changes the conditions in which people are able to exercise judgement, accountability and control. Underlying this is the idea that people risk does not begin with people. In The Fundamentals of People Risk Management (Kogan Page, 2026), I argue that it begins with the conditions that shape how people think, decide and act. These are the pressures, incentives, hierarchies, information, capability and organisational norms that provide the context in which people operate. AI is rapidly becoming an important part of that human system.

Let’s consider automation bias, or our tendency to give disproportionate weight to the recommendation of an automated system. The more sophisticated and authoritative an AI output seems, the easier it is to substitute acceptance for critical judgement. If an AI system recommends an action and a human approves it, then who has really made the decision?

Putting a person in the loop is not enough to resolve this problem. If that person lacks the necessary expertise, confidence, information or authority to challenge the system’s output, we may create the appearance of human oversight whilst actually weakening it. This is why human agency matters. By this I mean the capacity to make informed, intentional and accountable choices. Used well, AI can strengthen agency, operating as a kind of cognitive exoskeleton that extends our ability to analyse information and identify underlying patterns while maintaining human judgement. Used badly, however, it can erode skills, narrow discretion and blur accountability.

Some organisations are starting to realise this. Moderna has brought talent and digital technology together under a chief people and digital technology officer, explicitly recognising the profound impact of AI and digital platforms. Gartner now predicts that by 2029, 30% of firms will form blended HR/IT teams to accelerate AI adoption, arguing that decisions about work design, skills, technology, human-AI performance and decision rights increasingly cannot be owned by either alone.

The question is therefore shifting from “where and how can we deploy AI?” to “how should work be designed?”. This means addressing questions about what, uniquely, humans should do, such as where human judgement must remain, who can challenge an automated decision, and who is accountable when things go wrong. The challenge for risk professionals and boards is not simply to govern the technology, but to understand the human system being created around it.

AI may transform how organisations work. Our task is to ensure that as machines become more capable, the people working alongside them become more capable too.



Share Story:

YOU MIGHT ALSO LIKE


Resilience Rooted in Reality
In this podcast, CIR speaks to CLDigital’s Tejas Katwala about why organisations must move beyond checklist compliance to build living, data driven resilience. He explains how rethinking governance, risk and compliance, breaking down silos and focusing on value streams can create sustainable, real time resilience that is rooted in the way businesses actually operate today.

Building cyber resilience in a complex threat landscape
Cyber threats are evolving faster than ever. This episode explores how organisations can strengthen defences, embed resilience, and navigate regulatory and human challenges in an increasingly complex digital environment.