Also in: සිංහල · தமிழ்

08. Risks of Generative AI, Cybersecurity, and Responsible Use

Core Theme: An AI tool is like a confident intern. It works with dazzling skill; but it can also tell you flat, brazen lies without a flicker of hesitation. The final legal accountability rests with the public officer who signs the document. Reading is the only rampart by which the human retains control.


1. A Systematic Taxonomy of the 7 Principal Risks of Generative AI

The most fundamental truth a public officer must grasp before using artificial intelligence inside public administration is this: an LLM is not an information vault or a database. It is simply an engine that predicts the statistically most probable next word (P(w_t | w_<t)). When it lacks information, or is asked something it does not know, the model does not fall silent and say "I don't know." Instead, it fabricates false information — and presents it in supremely confident, official-sounding prose.

The seven principal risk dimensions facing officers in the public service can be systematically identified as follows:

Risks of Generative AI Figure 8.1: Risks of Generative AI — Hallucination, Bias, Privacy, Legal accountability, Misuse, Over-reliance, and Token Cost.

A Deep Anatomy of the 7 Risk Dimensions:

  1. Hallucination (Fabricated Information): * Technical nature: When the model encounters a contextual gap or uncertainty, it manufactures facts that are linguistically elegant yet physically non-existent. * Public-sector impact: Administrative circular numbers that exist nowhere in the real world, imaginary Supreme Court judgments, or fake demographic statistics finding their way into official documents. If a ministry secretary or a Divisional Secretary signs such a document, it becomes a legal and administrative catastrophe.

  2. Bias & Inequity: * Technical nature: The social, economic, cultural, and linguistic imbalances embedded in the historical internet data used to train the model directly shape the model's decisions. * Public-sector impact: When assessing eligibility for welfare benefits such as Aswesuma or Samurdhi (Sri Lanka's national welfare programs), or shortlisting public-service recruitments, marginalized communities, female-headed households, or people from remote provinces can be automatically and systematically disadvantaged. This is precisely why the European Union's AI Act (Regulation 2024/1689) classifies public welfare and citizen-service decisions as "High-Risk AI."

  3. Confidentiality & Privacy Leakage: * Technical nature: Data entered into public consumer AI tools may be stored by the model's parent company and used to retrain its next generation of models. * Public-sector impact: Entering citizens' National Identity Card (NIC) numbers, land deed details, medical records, or confidential Cabinet memoranda into open AI systems. Under Sri Lanka's Personal Data Protection Act, No. 9 of 2022 (PDPA), protecting citizen data is the absolute legal responsibility of the state Data Controller.

  4. Legal, Copyright & Regulatory Liability: * Technical nature: Unauthorized reproduction of commercially or intellectually protected documents, and the absence of copyright protection over AI-generated output. * Public-sector impact: Intellectual-property violations when drafting tender documents, policy papers, or curricula. Under administrative law, a state decision must rest on a specific human reasoned determination — and a black-box AI decision can be found unlawful before the courts.

  5. Misuse & Deepfakes: * Technical nature: The ability to instantly produce voice cloning, fake videos (deepfakes), and automated social-engineering attacks using multimodal AI tools. * Public-sector impact: Forging the voice of a District Secretary or a ministry secretary to place phone calls ordering the release of funds; instantly generating counterfeit official documents. Equally, cybercriminals can weaponize AI to automatically discover and exploit software vulnerabilities in frameworks such as MOSIP (Modular Open Source Identity Platform) or in aging government web portals.

  6. Over-reliance & Deskilling: * Technical nature: The convenience of automation lulls the human into surrendering deep thinking, analysis, and critical intelligence to the tool. * Public-sector impact: Just as mental arithmetic withered after the calculator arrived, the public officer stops reading complex Acts and circulars and begins to depend solely on AI summaries. The intellectual standard of the entire public service collapses.

  7. Cost & Token Economics: * Technical nature: The heavy token consumption incurred when running commercial-grade API inference, context-window caching, and agentic loops. * Public-sector impact: Without a proper architectural plan and budget controls, a state institution can generate monthly operating expenses (OPEX) it simply cannot bear.


2. Deloitte's $440,000 Lesson

The world's best example of how AI hallucinations dragged even a giant international consulting firm into severe embarrassment and legal penalty comes from the Australian government's experience:

Deloitte's AI crisis Figure 8.2: Deloitte's AI Fallout Explained — The $440,000 Report That Backfired (the fate of an official report to the Australian federal government).

The Background and the Systemic Failure:

In late 2025, Deloitte — one of the world's foremost management consulting firms — prepared a policy research report for the Australian government's Department of Employment and Workplace Relations under a contract worth AUD 440,000 (over 130 million Sri Lankan rupees) (Deloitte's AI Fallout Explained: The $440,000 Report That Backfired).

The consulting team that compiled the report had used generative AI for the literature review and for summarizing economic data. But once the report was tabled before a Senate committee of the Australian Parliament, it emerged that: * Many of the academic papers, author names, and institutional survey reports cited in the report were entirely hallucinated by AI — imaginary sources that had never been published anywhere in the real world! * Not one of the firm's senior consultants had checked whether those sources actually existed. * In the end, Deloitte was compelled to refund part of its consulting fee to the government and to apologize publicly before Parliament. The Australian government then legislated strict AI-use and human-accountability clauses into all future state consulting contracts.

Important

The lesson for the Sri Lankan public officer:
However scientific and authoritative the English in which AI writes your report, from the moment you sign it, the complete legal and administrative responsibility for every word in it is yours. "The AI made a mistake" is not a valid defense before the Public Service Commission or a court of law!


3. Reading Is the Only Interface That Keeps the Human in Control

In an article I authored, this is the core cognitive principle I insisted upon:

Reading and human control Figure 8.3: In the Age of Generative AI, Reading Is What Keeps the Human in the Loop — reading is not a passive act but the human interface that governs intelligence (Samisa Abeysinghe).

"Machines can write hundreds of pages in seconds. The speed of writing is intoxicating. But the only rampart that prevents our intellectual surrender before these automated creations is deep, deliberate, and discerning reading. The day you stop reading is the day you become the machine's servant."

The Difference Between Two Modes:

  • Idle skimming / scrolling — the failure mode: Glancing over a 10-page AI-written report, thinking the language is beautiful, and signing it. This is exactly how Deloitte walked into disaster.
  • Deep discerning reading — the real defensive rampart: 1. Logical trace: Do premises A and B truly establish conclusion C — or has the AI built a false bridge? 2. Constraint compliance: Has the model obeyed 100% of the negative constraints and legal conditions you placed in the prompt? 3. Empathetic alignment: Does the language of the report match the real pain of the citizen and the dignity of the public service, judged with administrative discernment?

4. Understanding and Preventing AI Bias

Another grave danger of artificial intelligence is its ability to reproduce society's existing prejudices in a supremely credible, seemingly impartial form.

Preventing AI bias Figure 8.4: Understanding & Preventing AI Bias — the 3 causes of bias (historical prejudice, algorithmic amplification, human design bias) and the 3 preventive measures.

Narrow Data vs Broaden Data Figure 8.5: The Data Law — narrow data produces biased outputs, while diversified data produces a fair model.

1. What Is AI Bias?

It is a model systematically generating unequal decisions that prejudice a particular social group, ethnicity, gender, or region. * The example in the figure: An equally qualified female applicant named "Sarah Chen" is Rejected, while the male applicant "David Smith" is Selected.

2. Why Does It Happen?

  1. Historical prejudices in the training data: When the model is trained on data carrying past gender pay gaps or social inequalities, it internalizes those historical wrongs as legitimate, permanent rules.
  2. Algorithmic amplification: Even a slight bias in the data gets statistically magnified during optimization, hardening into extreme decisions.
  3. Human cognitive bias in design: The engineers who design the software select features according to the unconscious biases in their own minds, and place profit above fairness.

3. How to Prevent It?

  • Diversify & audit data: Pre-audit the institution's datasets to ensure they represent diverse social groups.
  • Regular algorithmic auditing: Continuously test the model's decisions against fairness metrics.
  • Inclusive team design: Include professionals of diverse social backgrounds, disciplines, and sensibilities within the technical team.

5. The Deep Architecture of Preventing AI Hallucinations

Preventing AI hallucinations Figure 8.6: Understanding & Preventing AI Hallucinations — the 3 causes of fabricated information (Garbage In, Garbage Out / Model Limitations / Confusing Prompts) and their 3 remedies.

The Triple Fault and the Solution Matrix:

Root of the fault Technical background The real public-sector risk The engineering remedy
Garbage In, Garbage Out Low-quality, biased, or outdated training data. Calculating compensation based on a 1985 land circular while ignoring the 2024 gazette. Better training & RAG: Use only up-to-date official documents instead of the model's open memory.
Model Limitations Misreading patterns and guessing on probability ("All fruit is red!" — and so rejecting green apples). Asked for 10 legal precedents, the model fuses real judges' names with fake case numbers. Human-in-the-Loop: Before any official document is issued, an officer compares it against the source documents.
Confusing Prompts Vague, generic queries with no constraints, role, or context ("Tell me about the thing?"). Asked about a relief payment, the model recommends an imaginary amount without consulting the specific circular. Clear Constraints: Impose a role, context, and the negative constraint "If you do not know, say 'I do not know.'"

6. The 3-Tier Verification Workflow

In my sessions, people often ask me: "Samisa, how do you personally prevent these hallucinations and use AI dependably inside production-grade systems?"

The 3-Tier Verification Pipeline I use in my own engineering life is this:

  1. Tier 1 (Google Search AI Mode — real-time source retrieval): I first sweep the topic through Google Search's AI Mode — the true facts, the latest gazettes, official web data — and obtain a summary with verified links.
  2. Tier 2 (Google Gemini — research and prompt engineering): I hand that summary to Gemini and expand it further for Sri Lankan context and Sinhala-language accuracy. Then I ask Gemini itself: "Based on these verified facts, write me the optimal prompt — with negative constraints — that I should give the Claude model to prepare a legal draft."
  3. Tier 3 (Anthropic Claude — rigorous drafting): I carry that superior prompt, crafted by Gemini, over to Claude for the final deep logical analysis and the structured draft.
  4. Tier 4 (Human control and the signature): Finally, I read the document line by line, confirm its accuracy, and sign.

This tiered method lets you prevent the probability of hallucinations entering your work by 99.9%.


7. Shadow AI: The Covert Reality Already Unfolding Inside Offices

There is something we must discuss honestly: public officers are already sending official files to the free ChatGPT on their personal phones.

  • It is not done with bad intent: it happens because the file load is crushing, and because the tool genuinely helps.
  • Banning will not stop it: when an institution bans AI, usage does not end — it becomes an uncontrolled, unprotected secret (Shadow AI).
  • Provide a sanctioned route: the institution should approve one secure, paid tool (an Enterprise ZDR tier) and hand officers a clear list of what data may and may not be entered into it.
  • Make disclosure safe: an officer who openly declares, "I prepared this first draft with AI assistance; I then reviewed and corrected it," must never be punished for saying so.
  • The real danger is not officers using AI; it is data leaving the building in secret, with no institutional control, no regulation, and no human verification.

In the next chapter, we will manage these risks while exploring how to elevate citizen services — through the Avukana sculptor's model (the Baranastha principle), the three Japanese faces and a moving experience from the Kalutara DS office, AI Agents, and the systems of the future.