Introduction

Risk has always been part of human life. What has changed over time is how societies understand, manage and assign responsibility for it. From ancient beliefs about fate, through the emergence of insurance and probability theory, to modern organisational risk management, each era has shaped the way we respond to uncertainty.

Today, we are entering another turning point.

Artificial intelligence is rapidly becoming embedded in decision-making across businesses, governments and institutions. AI can analyse enormous datasets, identify patterns and support faster decisions than any human team. But as organisations increasingly rely on automated systems, a critical question emerges:

When AI-driven decisions lead to failure, who is responsible?

Understanding this question requires stepping back briefly to see how our relationship with risk has evolved.


From Fate to Probability

For most of human history, risk was interpreted through the lens of fate or divine will.

In agricultural societies, the success or failure of crops depended on unpredictable factors such as weather, disease and pests. Without scientific explanations, people often attributed these events to supernatural forces. This began to change as societies became more interconnected and trade expanded.

Maritime commerce forced merchants to confront risk in practical terms. Shipping goods across oceans involves enormous uncertainty; storms, piracy and navigation errors could easily destroy an entire investment.

In response, early forms of maritime insurance emerged in Mediterranean trading centres and later in London’s Lloyd’s coffee houses. You can read more about the history of maritime insurance and risk pooling here: https://www.lloyds.com/about-lloyds/history. These systems allowed merchants to pool risk collectively and protect themselves financially against loss. At the same time, mathematicians began developing probability theory, providing a foundation for modern risk analysis.

For the first time, risk could be quantified rather than feared.


Industrialisation and the Birth of Modern Risk Management

The Industrial Revolution transformed both the scale and consequences of risk.

Factories, railways, global supply chains and complex machinery created new hazards. Industrial accidents, fires and mechanical failures could have catastrophic consequences for businesses and communities.

In response, organisations began developing formal approaches to:

  • Safety management
  • Engineering controls
  • Insurance mechanisms
  • Statistical risk assessment

During this period, the foundations of modern insurance and risk management disciplines were established. The assumption of the industrial age was that with enough data and analysis, risk could be predicted and controlled.

Today, however, the risk landscape is far more interconnected.


The Modern Risk Landscape: Interconnected Systems

Modern organisations operate within deeply interconnected systems.

Technology infrastructure, cloud platforms, global supply chains and outsourced services mean that a disruption in one area can rapidly cascade across many others. Recent events have illustrated how fragile these systems can be.

In July 2024, a global IT outage linked to CrowdStrike software updates disrupted airlines, hospitals and financial institutions worldwide, grounding flights and affecting millions of users.

BBC coverage of the incident: https://www.bbc.com/news/articles/cp4wnrxqlewo

Reuters coverage: https://www.reuters.com/technology/cybersecurity/global-it-outage-caused-by-crowdstrike-update-2024-07-19/

Similarly, supply chain disruption during the COVID-19 pandemic demonstrated how failures in one region can quickly affect production and distribution globally.

Reuters overview: https://www.reuters.com/business/supply-chain-crisis-explained-2021-10-22/

These events highlight how traditional boundaries between risk categories, cyber, operational, geopolitical and environmental, are increasingly blurred.

Organisations today must think in terms of operational resilience, ensuring critical services can continue even during major disruption.


AI and the Accountability Problem

Artificial intelligence is now accelerating this transformation.

AI systems can analyse vast datasets, automate decision processes and detect patterns far faster than human analysts.

For risk professionals, this offers enormous potential in areas such as:

  • Predictive risk analysis
  • Fraud detection
  • Cyber threat monitoring
  • Supply chain risk analysis

However, the increasing use of AI also introduces new governance challenges.

AI systems rely on training data and algorithms, which means they can produce incorrect outputs or inherit biases from their datasets.

One widely discussed issue is AI hallucination, where systems generate confident but inaccurate information. A well-publicised case occurred in 2023 when lawyers in the United States submitted legal arguments generated by ChatGPT that cited non-existent court cases, leading to sanctions by the court.

BBC coverage: https://www.bbc.com/news/world-us-canada-65735769

Facial recognition systems have also raised concerns. Investigations have documented wrongful arrests resulting from inaccurate AI facial-recognition matches.

The Guardian report: https://www.theguardian.com/technology/2026/mar/19/essex-police-pause-facial-recognition-camera-use-study-racial-bias?CMP=share_btn_url

These examples highlight a critical issue:

Even when AI is involved, accountability cannot disappear.


Responsibility in an AI-Driven World

The growing use of AI raises fundamental questions for organisations:

  • Who is responsible when an automated system makes a flawed decision?
  • How should AI outputs be validated before influencing operational decisions?
  • What governance frameworks should be in place to manage algorithmic risk?

From a resilience perspective, these questions are critical.

Technology can enhance risk management, but it cannot replace human oversight, governance and accountability.

Organisations must ensure that:

  • AI-supported decisions remain subject to human review
  • Accountability for outcomes is clearly defined
  • Critical systems remain resilient to technology failures
  • Crisis management structures remain effective even when automated systems fail


What This Means for Organisational Resilience

For organisations today, the challenge is not simply adopting new technology, but integrating it responsibly into existing risk management frameworks.

At Horizonscan, much of our work with clients focuses on ensuring organisations are prepared for disruption in a world where risks are increasingly complex and interconnected.

That includes supporting businesses with:

  • Business continuity planning
  • Crisis management governance
  • Scenario exercising and stress testing
  • Operational resilience frameworks
  • Strategic risk and resilience advisory

AI will undoubtedly play a major role in the future of risk analysis and decision-making. But resilience ultimately depends on something more fundamental: clear accountability, strong governance and well-prepared people.


Conclusion

The way societies understand risk has evolved dramatically from divine fate to probability theory, from industrial safety to modern resilience frameworks.

Artificial intelligence represents the next stage in that evolution.

But while technology may change how risks are identified and analysed, one principle remains constant:

Responsibility cannot be automated.

In an increasingly complex and interconnected world, resilient organisations will be those that combine technological capability with strong governance, clear accountability and well-tested crisis management.

Because when disruption occurs, and it inevitably will, someone (A human) must still be responsible for the response.