Is AI dangerous?

Published

Last verified: August 2026

Yes, but not primarily in the way the debate suggests. The documented harms in 2026 are mundane and immediate: fabricated information presented confidently, non-consensual deepfakes, unreliable detection tools producing false accusations, and unresolved questions about who owns AI-generated work. Existential risk is contested. These are not.

We build AI systems for UK businesses, which means we spend more time on the failure modes than the capabilities. This article covers the risks that actually generate legal exposure and reputational damage, and the current UK legal position on each — including two developments from the last twelve months that most published articles on this topic still get wrong.

The immediate risks, ranked by how often they bite

Confident fabrication. A language model generates the most probable text, not the true text. It will produce plausible citations to papers that do not exist, statutes that were never passed, and case law it has invented. In a business context this is the most frequent harm by a wide margin — and it is invisible, because fabricated output looks exactly like correct output.

Non-consensual synthetic imagery. Overwhelmingly targeting women, now criminal in the UK in both creation and distribution.

False accusation via detection tools. Students and employees accused of AI use on the basis of tools that do not work reliably, with a documented bias against non-native English writers.

Unclear ownership. Businesses commissioning AI-generated assets without knowing whether they own anything.

Data leakage. Staff pasting client or personal data into consumer AI tools. A UK GDPR problem, and the most common compliance failure we encounter in audits.

Existential risk from advanced AI is a genuine research field with serious people on both sides, and it is not resolved. It is also not what will land a UK SME in front of the ICO this year.

Can AI be detected? The honest answer

No, not reliably. AI text detectors work by measuring statistical properties of writing — how predictable each word is given the previous ones — and assuming machine-generated text is more predictable than human text. That assumption fails often enough that no current detector is safe to use as evidence of misconduct.

The strongest evidence comes from OpenAI itself. It launched an AI Text Classifier in January 2023 and withdrew it on 20 July 2023, stating plainly: "the AI classifier is no longer available due to its low rate of accuracy." The company with the most training data, the most capable models and the strongest commercial incentive to solve detection tried, failed, and said so publicly.

Worse, the failures are not random. A Stanford study — Liang, Yuksekgonul, Mao, Wu and Zou, GPT detectors are biased against non-native English writers, published in Patterns in July 2023 — found that detectors consistently misclassified writing by non-native English speakers as AI-generated, while classifying native-speaker writing correctly. The mechanism is straightforward and damning: non-native writers tend to use more common vocabulary and simpler constructions, which is exactly what these tools score as machine-like. The authors explicitly cautioned against use in evaluative settings.

The practical consequences for a UK organisation:

  • Do not use an AI plagiarism checker score as the basis of a disciplinary or academic misconduct finding. It is not evidence, and a percentage figure creates a false impression of precision.
  • If your institution or business uses detection tooling, it is producing discriminatory outcomes against non-native English speakers by design. Under the Equality Act 2010 that is worth taking seriously.
  • Where AI use genuinely matters, address it through process — supervised work, drafts, oral examination, version history — not through detection software.

Watermarking and provenance standards are more promising than detection, because they attach a signal at generation rather than guessing after the fact. But they only work where the generating tool cooperates, which means they will never cover the cases you most want covered.

Deepfake risks and the UK law that changed in 2026

This is the section where most articles are out of date, and the error is significant.

Two separate offences now exist, created by two different pieces of legislation.

Sharing intimate images without consent is covered by the Online Safety Act 2023, section 188, which inserted sections 66B–66D into the Sexual Offences Act 2003. This covers sharing without consent, sharing with intent to cause alarm or distress, sharing for sexual gratification, and threatening to share — including where no image actually exists. Penalties run from summary conviction to two years on indictment.

Creation is a newer and separate offence. The Data (Use and Access) Act 2025, section 138 inserted sections 66E–66F into the Sexual Offences Act 2003, criminalising intentionally creating a purported intimate image without consent, and requesting its creation. There is a "reasonable excuse" defence and the offences are summary-only.

Two details that matter. The creation offence came into force on 6 February 2026, not at Royal Assent — so anything written before that date describing creation as lawful was correct at the time and is wrong now. And it was not the Criminal Justice Bill, which fell at the 2024 dissolution; a great deal of commentary still attributes these provisions to that bill incorrectly.

Beyond intimate imagery, deepfakes touch fraud (voice cloning for authorised push payment fraud is now a routine vector), defamation, and the Fraud Act 2006. Voice cloning specifically is worth naming for businesses: a cloned voice of a director instructing a payment is a live and currently under-defended attack. Verification procedures that do not rely on recognising a voice are no longer optional — the kind of process failure our work with accountants and recruitment agencies is designed to close.

Who owns AI art? The UK position

Under UK law, computer-generated works can have an author. Section 9(3) of the Copyright, Designs and Patents Act 1988 states that for a computer-generated literary, dramatic, musical or artistic work, "the author shall be taken to be the person by whom the arrangements necessary for the creation of the work are undertaken." This makes the UK unusual — most jurisdictions, including the US, require human authorship.

Section 9(3) predates generative AI by decades and was drafted with a different technology in mind. Who counts as making "the arrangements necessary" for an image produced from a text prompt has not been settled by a UK court. Plausible candidates include the prompter, the platform, and the model developer. Platform terms of service typically assign output rights to the user, which is contractual and does not resolve the underlying copyright question.

The contrast with the US is stark. The US Copyright Office requires human authorship: purely AI-generated output is not copyrightable, though human-authored contributions within a work can be protected. Its position is set out across a multi-part report — Digital Replicas (July 2024), Copyrightability (January 2025) and Generative AI Training (pre-publication, May 2025) — and applied in registration decisions including Zarya of the Dawn and Théâtre D'Opéra Spatial.

The case law, corrected

Getty Images v Stability AI [2025] EWHC 2863 (Ch), 4 November 2025 — decided. This is the correction that matters most, because most articles still describe it as pending.

Mrs Justice Joanna Smith handed down judgment. Getty withdrew its training and development claim, having been unable to establish that training occurred in the UK, and withdrew its output claim after Stability blocked the relevant prompts. The secondary infringement claim failed: the court held that the model weights would not have infringed had their making occurred in the UK, and so were not infringing copies. Getty succeeded only on trade mark infringement, and narrowly — relating to historic watermark generation.

Read plainly: a substantial loss for Getty on the copyright questions that mattered, with a limited trade mark win. Anyone citing this case as authority that AI training infringes UK copyright has it backwards. Related consequential orders followed in December 2025.

Thaler v Comptroller-General of Patents [2023] UKSC 49, 20 December 2023. The UK Supreme Court held that an AI system cannot be named as an inventor — the Patents Act 1977 requires a natural person — and that Thaler was not entitled to the patents merely by owning the machine. Patents, not copyright, but it establishes the direction of judicial thinking on machine authorship.

Andersen v Stability AI (N.D. Cal.) remains ongoing in the US as far as we can establish. Its status should be checked before being relied on.

Where UK policy actually stands

The government's Copyright and Artificial Intelligence consultation ran from 17 December 2024 to 25 February 2025 and is closed. DSIT published a report and impact assessment on the use of copyright works in AI development on 19 March 2026. No formal consultation outcome has been published.

There is no text-and-data-mining exception in UK law. A TDM exception with rights reservation and transparency requirements was the consultation's preferred option — a proposal, not legislation. Statutory reporting duties do exist, under sections 135–137 of the Data (Use and Access) Act 2025.

What this means commercially. If you are commissioning AI-generated assets, do not assume you own them and do not assume they are clean. Practical steps: get contractual warranties from whoever supplies AI-generated work; keep records of prompts and human editing, since human contribution is where protection is most defensible; for anything load-bearing — a logo, a brand asset — use human-authored work where ownership is unambiguous.

Comparing the risks

AI risks compared by likelihood, legal exposure and mitigation for a UK SME.
RiskLikelihood for a UK SMELegal exposureMitigation
Fabricated output reaching a customerHighMisrepresentation, regulated-advice breaches, reputationalGround answers in retrieved documents; define "I don't know"; human review on anything consequential
Staff pasting personal data into consumer AIHighUK GDPR — unlawful processing, transfersWritten AI use policy; business tiers with data-processing agreements; training
False AI-use accusation via detectorModerateEquality Act, unfair dismissal, academic appealDo not treat detector scores as evidence; use process-based assurance
Voice-clone or deepfake fraudModerate and risingFinancial loss; Fraud ActOut-of-band payment verification that never relies on voice recognition
Owning nothing you commissionedModerateUnenforceable rights in brand assetsWarranties in contract; human authorship for critical assets; retain prompt records
Automated decisions affecting individualsLow but severeUK GDPR Article 22 obligationsKeep a human in the loop; document the basis; provide explanation routes
Existential riskNot actionable at SME levelNone currentlyNot a business planning input

What responsible deployment looks like

Six things, none of them technically difficult, all of them routinely skipped.

Ground it. Any system giving factual answers must retrieve real source documents and answer from them, with citations. This single design choice removes most fabrication risk.

Let it refuse. A defined "I don't know, here is a human" path is the most valuable feature in any customer-facing AI system, and the one clients most often want removed because it feels like a weakness. It is not — as we explain when scoping an AI receptionist for a client.

Disclose it. Tell people they are talking to an AI. It is required in some regulated contexts, expected in most others, and the reputational cost of concealment landing badly vastly exceeds any benefit.

Keep a human on consequential decisions. Anything affecting someone's money, health, employment or legal position gets a named accountable person. This is both a legal position and an operational one — something we build into deployments for dental practices and trades businesses alike.

Write the policy. Which tools are approved, what data may never be entered, who to ask. Most data leakage we find is well-intentioned staff with no guidance.

Log everything. Inputs, outputs, decisions, model versions. When something goes wrong — and it will — the difference between a contained incident and an unbounded one is whether you can reconstruct what happened.

So, is AI dangerous?

The technology is not dangerous in the way a chemical is dangerous. It is dangerous in the way an unaudited process is dangerous: it does what it was set up to do, at scale, including when what it was set up to do is wrong.

The businesses that get hurt are not the ones using AI. They are the ones using it without knowing what it does when it fails, without a human accountable for its output, and without having asked whether the process underneath it made sense in the first place. The problem is structural, not behavioural — and you cannot train your way out of a structural problem. It is also why platform choice matters, as we cover in our Zapier vs n8n comparison.

Start with the audit, not the software

Most AI risk in a small business is not exotic. It is an unclear process, an undocumented decision and nobody named as accountable. That is diagnosable in an afternoon.

Thirty minutes on a call, no pitch. We map how work moves through your business, show you where the risk and the wasted time actually sit, and tell you what is worth building — and what is not. You keep the roadmap either way. See our pricing for what happens next.

Is AI dangerous? FAQ

Is AI dangerous?

Yes, but not primarily in the way the debate suggests. The documented harms in 2026 are mundane and immediate: fabricated information presented confidently, non-consensual deepfakes, unreliable detection tools producing false accusations, and unresolved questions about who owns AI-generated work. Existential risk is contested. These are not.

Can AI writing be detected?

No, not reliably. AI text detectors work by measuring statistical properties of writing — how predictable each word is given the previous ones — and assuming machine-generated text is more predictable than human text. That assumption fails often enough that no current detector is safe to use as evidence of misconduct.

Are deepfakes illegal in the UK?

Yes. Sharing intimate images without consent is covered by the Online Safety Act 2023, section 188, which inserted sections 66B–66D into the Sexual Offences Act 2003. Creation is a separate, newer offence: the Data (Use and Access) Act 2025, section 138, inserted sections 66E–66F into the Sexual Offences Act 2003, criminalising intentionally creating a purported intimate image without consent. The creation offence came into force on 6 February 2026.

Who owns AI-generated art in the UK?

Under UK law, computer-generated works can have an author. Section 9(3) of the Copyright, Designs and Patents Act 1988 states that for a computer-generated literary, dramatic, musical or artistic work, "the author shall be taken to be the person by whom the arrangements necessary for the creation of the work are undertaken." Who counts as making those arrangements for an AI image has not been settled by a UK court.

Sources and links

Start with the audit, not the software.

Thirty minutes on a call. We map how work moves through your business, show you where the time is going, and tell you what is worth building. You keep the roadmap either way.