top of page

BEFORE THE INSIDER THREAT Human Risk During AI Transformation

The Pathways to Insider Risk
The Pathways to Insider Risk

.........................................

Before Reading: Please note, this piece is not an evidence base. It is a set of human pathways worth testing; not a set of findings. It stems from a wider body of work examining external human stressors forming insider threats.

.........................................



Most discussions I follow tend to focus on how AI will transform how business is conducted, and what it will replace. What I do not see is discussion on the "anticipation of change" and what this next industrial revolution will mean to workers currently occupying these roles.


But despite the multiple discussions, I suspect the actual transformation, human to AI, regardless of scale, will take many months, or even years to fully implement. Some roles will see gradual changes and savvy HR leaders will likely not want to cut headcounts just yet, which could explain the absence of public discourse.


Employees however, who are farther away from the decision makers, will be trying to understand what their futures look like. And it is within this period of uncertainty that unforeseen risk might arise; and may require closer examination.


The risk may begin before the event

Insider-risk programmes traditionally focus on behaviours and circumstances that may precede harmful activity: financial difficulties, workplace grievances, disciplinary problems, substance misuse, unusual access to information, or significant changes in behaviour.


None of these issues, on their own, makes someone an insider threat. Indeed, most people experiencing financial pressure, workplace dissatisfaction or personal difficulties will never become one.


So instead of focusing on changing personal characteristics, perhaps we should look at changing relationships - the relationships that exist between the employee and the organisation.


What could the consequences look like if an existing human vulnerability were confronted with a significant change in the worker organisation relationship, when AI is that change?


Consider an employee; at any level, who believes they are likely to be replaced with AI, even if talk of redundancies has not even been considered. Another employee may feel their own skills and earning potential are about to be vaporised. Yet another may determine it is unhealthy to simply wait around stressing about what might happen



I am considering 4 potential pathways

I must stress, I do not present these as facts or definitive modeling. They are simply observations I wish to test with others working across HR, Security, Risk Teams, and Leaders.


  1. They stay with the company — but they become vulnerable as time progresses:  The employee remains in place whilst the atmosphere and meeting rooms are filled with AI-Speak. The uncertainty builds, and gradually the perception of unfairness develops leading to an erosion of trust. There is nothing malicious at this stage, but the employee employer relationship is changing.

  2. They stay with the company — but become dependent: 

    In this pathway, the employee remains in place, but finds themselves conducting fewer tasks than before as AI is now performing tasks that had required their human judgement. As they become more dependent on AI, the organsiation, despite retaining its workers, begins to lose capabilities those humans were originally employed to provide. You may not consider this an insider threat, but it might qualify as a resilience / accountability issue.


  3. They resign — on a voluntarily basis: An more confident employee might decide they do not want the torment of waiting around - they deduce life is difficult enough and the company is not talking to them and saying what they need to hear.


    But as they exit the building for the last time, they carry with them more than their job title. They have acquired inside knowledge of the operation, client & competitor relationships, and judgement. In some instances they will market that expertise back into the industry, either as a consultant, or on behalf of a competitor.


  4. They resign — involuntarily: This is the pathway we expect to hear of when considering insider risk. Transformation leads to redundancy or termination. In this situation, it is the end of this risk period (although they could revert to Pathway 3), but it began when uncertainty crept in, possibly a considerable period before it came to the attention of HR / Security.

This is why we should consider looking for relationship change, and not just personal characteristics


When looking at insider risk potential, we might ask, "if the employee is showing any indicators?" Increased alcohol consumption is often included here, but of course, on its own is not an indicator of vindictive risk.


Perhaps a more useful question would be, "what has changed in the employee's relationship, (now or future potential relationship), with the organisation?"


It would be a grave error to treat any of these findings or changes as evidence of malicious intent. But where a considerable change, especially when combined with other (personal) circumstances, we should at least consider a paradigm shift.


This again causes us to depart from traditional insider human risk assessments, which often focus on incidents. What we should be looking at with this AI implementation is the direction of human organisation relationship travel.


Who is the owner?

It also exposes a potential ownership gap which relates to perception based upon one's corporate role. Is this a HR problem, or a Security problem?


  • HR might interpret events as: uncertainty / disengagement / attrition.

  • The Security Department may see: uncertainty / behavioural change / potential vulnerability.

  • The Risk Team may see: uncertainty / capability loss / operational exposure.

  • Leadership may see: AI transformation / improved efficiency.


These differing perspectives should not be viewed as different challenges - they are simply alternative visions of the same human response to organisational changes brought upon them.


Identifying such alternate views would also present an opportunity to merge them.


A question, not a conclusion

I make no suggestion that the incoming AI transformation is about to wreak insider threat havoc across organisations implementing the technology - that would be an indefensible claim.


What I am outlining is the potential for a period of human uncertaintly that should become integrated into the organisation's risk mapping in order that any arising vulnerability can be mitigated, and certainly before critical workers decide to leave.


So I leave you with an alternative thought; Ask not what AI will do for our company, but what will our workforce do whilst awaiting to discover what AI will do either for, or to, them?


To be clear, this is a strategic think, not an evidence base. Testing these pathways requires something I do not have on my own; the visibility into what is actually happening inside organisations going through this transformation right now.


If you are inside an AI transformation, or have led one, I would be genuinely interested to hear what you are seeing. Which pathway looks most familiar. Which one I've missed.


The risk picture, if there is one, will be built from those conversations — not from a single article.


Thank You


Anthony Hegarty MSc (Criminal Psychology & Criminology)


DSRM Risk



 
 
 

Comments

Rated 0 out of 5 stars.
No ratings yet

Add a rating
© Copyright

© 2026 by DSRM

  • Linkedin
  • Facebook
bottom of page