CM-06: The Risks of Generative AI, Cybersecurity, and Responsible Use (Governance & Ethics)
Core Theme: An AI tool is like a confident intern. It works with remarkable skill; but it can also tell outright lies without the slightest hesitation. Final accountability lives with the human who signs, who submits the answer, who makes the decision. Reading is the only wall that keeps the human in control.
1. A Systematic Taxonomy of Generative AI's 7 Principal Risks (Taxonomy of AI Risks)
The most fundamental truth anyone using artificial intelligence must grasp is this: an LLM is not an information store or a database. It is an engine that predicts the most plausible next word on statistical probability (P(w_t | w_<t)). When information is missing, or when asked something it does not know, the model does not fall silent and say "I don't know." Instead, it fabricates false information and presents it in supremely confident, official-sounding form.
From the school student to the chief executive, all of us face these seven principal risk dimensions. (Each risk below carries a concrete worked example drawn from the public service — the same pattern applies directly to your school, your business, or your home):
Figure 8.1: Risks of Generative AI — Hallucination, Bias, Privacy, Legal liability, Misuse, Over-reliance, and Token Cost.
Figure: A Systematic Taxonomy of Generative AI's 7 Principal Risks — Idasara Academy.
The Deep Anatomy of the 7 Risk Dimensions:
-
Hallucination: * Technical nature: When the model meets a contextual gap or uncertainty, it produces facts that are linguistically beautiful — and physically nonexistent. * Public-sector impact: Administrative circular numbers that exist nowhere in the real world, imaginary Supreme Court judgments, or fake demographic statistics slipping into official documents. If a Ministry Secretary or a Divisional Secretary signs such a document, it becomes a legal and administrative catastrophe.
-
Bias & Inequity: * Technical nature: The social, economic, cultural, and linguistic imbalances in the historical internet data used to train the model directly shape its decisions. * Public-sector impact: In assessing welfare entitlements such as Aswesuma or Samurdhi — Sri Lanka's national welfare-benefit programs — or in shortlisting public-service recruits, marginal communities, women-headed households, or people from remote provinces can be disadvantaged automatically. This is exactly why the EU AI Act (Regulation 2024/1689) classifies public welfare and public-service decisions as "High-Risk AI."
-
Confidentiality & Privacy Leakage: * Technical nature: Data entered into public consumer AI tools may be stored by the model's parent company for retraining its next generation of models. * Public-sector impact: Citizens' National Identity Card (NIC) numbers, land deed details, medical records, or confidential cabinet memoranda entered into open AI systems. Under Sri Lanka's Personal Data Protection Act, No. 9 of 2022 (PDPA), protecting citizen data is the absolute legal obligation of the state Data Controller.
-
Legal & Regulatory Liability: * Technical nature: Unauthorized reproduction of commercially or intellectually protected documents — and the fact that AI-generated output itself attracts no copyright. * Public-sector impact: Intellectual-property violations in tender documents, policy drafts, or curricula. Under administrative law, a state decision must rest on a specific human reasoned determination; a black-box AI decision can be unlawful before a court.
-
Misuse & Deepfakes: * Technical nature: Multimodal AI tools can instantly produce voice cloning, fake videos (deepfakes), and automated social-engineering attacks. * Public-sector impact: Forging the voice of a District Secretary or Ministry Secretary to phone in an order to release funds; generating counterfeit official documents at speed. Meanwhile, cybercriminals weaponize AI to automatically discover and break software vulnerabilities in frameworks such as MOSIP (Modular Open Source Identity Platform) or in aging state web portals.
-
Over-reliance & Deskilling: * Technical nature: Seduced by the ease of automation, the human quietly surrenders deep thinking, analysis, and critical intelligence to the tool. * Public-sector impact: Just as mental arithmetic withered after the calculator arrived, the public officer stops reading the complex acts and circulars and starts depending solely on AI summaries. The intellectual level of the entire service collapses.
-
Cost & Token Economics: * Technical nature: The heavy token consumption of commercial-grade API inference, context-window caching, and agentic loops. * Public-sector impact: Systems run without proper architecture and budget control create monthly operating expenses (OPEX) no public institution can bear.
2. Deloitte's $440,000 Lesson
The world's best example of how AI hallucinations dragged even a giant international consultancy into humiliation and legal penalty comes from the Australian government's experience:
Figure 8.2: Deloitte's AI Fallout Explained — The $440,000 Report That Backfired (the fate of an official report to the Australian federal government).
Figure: Deloitte's AI Fallout Explained — The $440,000 Report Anatomy — Idasara Academy.
The Background and the Systemic Breakdown:
In late 2025, Deloitte — one of the world's premier management consultancies — produced a policy research report for the Australian government's Department of Employment and Workplace Relations under a contract worth AUD 440,000 (more than 130 million Sri Lankan rupees) (Deloitte's AI Fallout Explained: The $440,000 Report That Backfired).
The consulting team had used generative AI for the literature review and for summarizing economic data. But once the report reached a Senate committee of the Australian Parliament, the truth surfaced:
- Many of the academic papers, author names, and institutional survey reports cited in the report were entirely hallucinated — imaginary sources that had never been published anywhere in the real world.
- Not one of the firm's senior consultants had checked whether those sources actually existed.
- In the end, Deloitte had to refund part of its consulting fee to the government and apologize publicly before Parliament. The Australian government then legislated strict AI-use and human-accountability clauses into all future public consulting contracts.
Important
The lesson for all of us in Sri Lanka: However scientific and authoritative the English in which AI writes your report, from the moment you sign it, full responsibility for every word is yours. "The AI made a mistake" is not a valid defense before an examination board, an employer, the Public Service Commission, or a court of law.
3. Reading Is the Only Interface That Keeps the Human in Control
In an article I authored, this is the core cognitive principle I insisted upon:
Figure 8.3: In the Age of Generative AI, Reading Is What Keeps the Human in the Loop — reading is not a passive act but the human interface that governs intelligence (Samisa Abeysinghe).
"Machines can write hundreds of pages in seconds. The speed of writing is intoxicating. But the only wall that prevents our intellectual surrender before these automatic creations is deep, deliberate, and discerning reading. The day you stop reading is the day you become the machine's servant."
Figure: In the Age of Generative AI, Reading Is What Keeps the Human in the Loop — Idasara Academy.
The Difference Between Two Modes:
- Idle skimming / scrolling (the failure mode): Glancing over a 10-page AI-written report, deciding the language is beautiful, and signing it. This is precisely how Deloitte walked into disaster.
- Deep discerning reading (the true defensive wall): 1. Logical Trace: Do premises A and B actually establish conclusion C — or has the AI built a false bridge? 2. Constraint Compliance: Did the model obey, one hundred percent, the negative constraints and legal conditions you placed in the prompt? 3. Empathetic Alignment: Does the report's language honor the real citizen's pain and the dignity of the institution — judged with professional discernment?
4. Understanding and Preventing AI Bias
Another grave danger of artificial intelligence is its ability to regenerate society's existing prejudices in a supremely credible, seemingly neutral form.
Figure 8.4: Understanding & Preventing AI Bias — the 3 causes of bias (historical prejudices, algorithmic amplification, human design bias) and the 3 steps of prevention.
Figure: The Data Law — Data Diversity and Output Fairness — Idasara Academy.
Figure 8.5: The Data Law — narrow data yields biased outputs, while diversified data yields a fair model.
1. What Is AI Bias?
A model systematically generating unequal decisions that prejudice a social group, an ethnicity, a gender, or a region. * The example in the figure: With identical qualifications, the female applicant "Sarah Chen" is rejected while the male applicant "David Smith" is selected.
2. Why Does It Happen?
- Historical Prejudices in the training data: When a model is trained on data carrying yesterday's gender pay gaps or social inequalities, it learns those old wrongs as legitimate permanent rules.
- Algorithmic Amplification: Even a slight bias in the data, when statistically optimized, is magnified by the model into extreme decisions.
- Human Cognitive Bias in Design: The engineers who design the software select features according to the biases in their own subconscious — and place profit above fairness.
3. How to Prevent It?
- Diversify & Audit Data: Pre-audit the institution's datasets to confirm they represent all social segments.
- Regular Algorithmic Auditing: Continuously test the model's decisions against fairness metrics.
- Inclusive Team Design: Build technical teams from professionals of varied social backgrounds, fields, and sensibilities.
5. The Deep Architecture of Preventing AI Hallucinations
Figure 8.6: Understanding & Preventing AI Hallucinations — the 3 causes of fabricated information (Garbage In, Garbage Out / Model Limitations / Confusing Prompts) and the 3 remedies.
The Triple Fault Matrix of Hallucination — and Its Solutions:
| Root of the Fault | Technical Background | The Real Risk in Practice | The Engineering Remedy |
|---|---|---|---|
| Garbage In, Garbage Out | Low-quality, biased, or outdated training data. | Calculating compensation from a 1985 land circular while ignoring the 2024 gazette. | Better Training & RAG: Use only up-to-date official documents instead of the model's open memory. |
| Model Limitations | Misreading patterns and guessing on probability ("All fruit is red!" — and so rejecting the green apple). | Asked for 10 legal precedents, the model welds real judges' names onto fake case numbers. | Human-in-the-Loop: Before any official document is issued, a human compares it against the source records. |
| Confusing Prompts | Vague queries with no constraints, role, or context ("Tell me about the thing?"). | Asked about a relief payment, the model recommends an imaginary amount without consulting the specific circular. | Clear Constraints: Set the role, the context, and the negative constraint: "If you do not know, say 'I do not know.'" |
6. The 3-Tier Verification Workflow
In sessions, people often ask me: "Samisa, how do you personally prevent these hallucinations and use AI reliably in production-grade systems?"
This is the 3-Tier Verification Pipeline I use in my own engineering life:
Figure: The 3-Tier Verification Pipeline — Idasara Academy.
- Tier 1 (Google Search AI Mode — live source retrieval): I first check the true facts of the topic — the latest gazettes and official web data — through Google Search's AI Mode, obtaining a summary with verified links.
- Tier 2 (Google Gemini — research and prompt engineering): I hand that summary to Gemini and broaden it with Sri Lankan context and Sinhala-language accuracy. Then I have Gemini itself write the next instrument: "Based on these verified facts, write the optimal prompt — with negative constraints — that should be given to the Claude model to draft this legal document."
- Tier 3 (Anthropic Claude — logical drafting): I carry that engineered prompt to Claude for the final deep logical analysis and the structured draft.
- Tier 4 (Human control and signature): Finally, I read the document line by line, confirm its accuracy, and sign.
This tiered method prevents hallucinations from slipping through with 99.9% effectiveness.
7. Shadow AI: The Secret Reality Already Unfolding Inside Offices
There is something we must discuss honestly: public officers, teachers, accountants — employees of every institution — are already sending official files to the free ChatGPT on their personal phones.
- It is not done from bad intent: The file load is crushing, and the tool genuinely helps.
- Banning cannot stop it: When an institution bans AI, usage does not stop — it becomes an uncontrolled secret with no safeguards at all (Shadow AI).
- Provide a sanctioned route: The institution should approve one secure, paid tool (an enterprise zero-data-retention tier) and give staff a clear list of what data may and may not be entered.
- Make disclosure safe: The employee who openly states, "I prepared this first draft with AI assistance; I then reviewed and corrected it," must never be punished for the disclosure.
- The real risk: Not that people use AI — but that data leaks out in secret, without institutional control, regulation, or human verification.
In the final module, we chart the road through these risks into the coming decade — the evolution from the chatbot era to autonomous AI Agents, the Avukana standard, Japan's three faces and a Kalutara mother's heartbreaking discovery, and the 5 universal golden rules of AI mastery.