Zum Hauptinhalt springen
Willkommen bei Deloitte

Sollten wir das falsche Erlebnis für Sie ausgewählt haben, ändern Sie es bitte oben.

AI Safety and Loss of Control

How organisations can strengthen governance, accountability, and oversight to address emerging AI safety risks and comply with evolving regulatory expectations

Artificial intelligence is increasingly embedded in core business processes and consequential decisions. As General-Purpose AI systems become more capable, organisations face a fundamental question: how can meaningful control be maintained over systems whose behavior is not always fully predictable, explainable or directly supervised? This paper explains why AI safety is a governance challenge and how organisations can detect and address loss-of-control risks early.

Key Takeaways

  • AI safety is not only a technical issue, but a governance and assurance challenge. 
  • Loss of control can emerge gradually through model drift, weakening oversight and reduced auditability, or suddenly through unexpected system behavior. 
  • The EU AI Act increases pressure on organisations to classify AI risk, maintain documentation, ensure human oversight, and report incidents. 
  • Deloitte recommends a five-pillar approach: risk and control assessment, governance framework, compliance readiness, incident and risk reporting, awareness, and training. 
  • AI control testing transforms technical test results into business-relevant, audit-ready evidence for deployment, monitoring, and regulatory readiness. 
AI Safety and Loss of Control

Download here 

Why organisations must prioritize AI safety now 

Artificial intelligence has moved from experimental use cases into the operational core of modern organisations. AI systems increasingly support decisions in finance, healthcare, public services, supply chains,  and risk management. These systems can create significant benefits in speed, scale, and analytical depth. At the same time, they challenge traditional governance models because their behavior can be probabilistic, adaptive, and difficult to fully explain. For organisations deploying General-Purpose AI and other advanced AI systems, the key question is no longer whether AI can be used productively, but whether it can be governed, monitored, and controlled with sufficient confidence. 

Understanding loss of control 

The paper focuses on loss of control as a central AI safety risk. Loss of control describes situations in which an organisation can no longer effectively explain, steer, audit or constrain the AI systems it deploys. This does not only refer to dramatic system failures. In practice, control can erode gradually: performance may drift, human monitoring may become less effective, escalation routines may weaken, and outputs may move outside intended boundaries without triggering immediate alarms. Sudden loss of control can also occur when systems behave unexpectedly because of new input distributions, complex component interactions or emergent capabilities. 

Risk dimensions and early-warning indicators 

Effective AI governance requires organisations to look beyond isolated technical errors. The paper outlines technical, operational, and societal dimensions of loss-of-control risk. Technical indicators include model drift, reduced robustness, unexpected model behavior, and a decline in explainability. Operational indicators include deferred human review, unclear ownership, weak escalation pathways and overreliance on automated outputs. Societal risks arise when AI systems affect stakeholder trust, infrastructure resilience or public outcomes beyond the immediate use case. Organisations should monitor early-warning signals such as anomalies, unexpected resource usage, weakening audit trails, reduced transparency, and widening gaps between system behavior and operator understanding. 

A structured five-pillar approach 

Deloitte recommends a structured approach to AI safety and control: 

  1. Organisations should conduct AI risk and control assessments that identify material risks, control objectives, and intervention points.
  2. They need governance frameworks that define decision rights, accountability and human oversight. 
  3. Compliance readiness should be embedded into daily workflows, especially considering EU AI Act requirements around classification, documentation, oversight, and incident reporting. 
  4. Incident and risk reporting mechanisms should make anomalies visible before they become material failures. 
  5. Awareness and training should equip technical teams, business users, compliance functions, and leadership with the practical capabilities needed to use AI responsibly. 
Deloitte’s recommendation for AI control testing 

Traditional static controls are often insufficient for AI systems that evolve over time. Deloitte’s AI control testing approach therefore treats assurance as a continuous discipline. It starts with clearly scoped AI use cases and translates them into concrete control objectives across areas such as loss of control, bias, reliability, compliance, and intended use. Technical testing results are not assessed in isolation. They are interpreted in the context of governance, business risk, and regulatory obligations. This creates traceable evidence that can support deployment decisions, ongoing monitoring, internal audit, board-level oversight, and regulatory review. 

What organisations should do next 

The strategic choice for organisations is clear: AI governance should not be treated as a secondary compliance burden. Organisations that build governance and control testing into their AI operating models are better positioned to deploy AI with confidence, respond effectively to regulatory expectations, and build trust with stakeholders. The goal is not to slow innovation, but to make AI adoption safer, more accountable, and more sustainable.

Download the full POV for detailed insights. 

“AI safety is not a speculative future issue. It is a practical governance challenge. Organisations need to demonstrate that AI systems remain within defined boundaries, supported by controls, evidence, and clear accountability.”

Martin Ritter | Partner | Enterprise Risk

Fanden Sie dies hilfreich?

Vielen Dank für Ihr Feedback