This page was originally written in Indonesian. This English version was translated automatically using machine translation (AI/Google engine) and may contain contextual inaccuracies. View the original Indonesian version.

Fluent Doesn't Mean Correct: The Safe Limits of AI for Business

Ilustrasi manusia mengawasi dan memverifikasi output AI sebagai pagar kepatuhan bisnis
A companion PDF guide is available for this article

Mid-size to large companies, both private and state-owned, are increasingly relying on artificial intelligence to handle high-value analytical work. Employees use AI to research capital markets, draft risk assessments, formulate business plans, and even write official reports. Unfortunately, the pace of adoption has sprinted far ahead of the compliance guardrails that should already be in place.

The risk of falling behind here isn't just about employee productivity. There is a very real material threat. Market data born from machine hallucination can drive flawed investment decisions. An unverified risk assessment can end in a credibility disaster. A report that reads fluently but is substantively wrong can destroy a company's reputation in front of investors, auditors, and regulators. Companies that set safe limits for AI use now will be far better prepared for what's ahead than those who wait for an incident to happen before scrambling for a fix.

The EY Canada Case: When an AI Report Destroyed Its Own Reputation

As an early warning, consider the real case that hit EY Canada. The firm was forced to pull and delete its own cybersecurity report, titled "Points of Attack," after a detection tool uncovered a startling fact. Of the 27 citation sources in the 44-page report, 16 turned out to be fake, misquoted, or linked to dead pages. The AI even fabricated a fictitious McKinsey reference and presented two conflicting valuation figures of US$200 billion each.

This wasn't some throwaway document put together by an intern. The report was published by a Big Four accounting firm to market its own cybersecurity services. If a firm the size of EY could slip up without adequate quality control, we should ask how resilient our own internal teams really are when drafting risk assessments or feasibility studies without an equivalent layer of verification.

Why This Kind of Analytical Work Is So Vulnerable to AI Error

This kind of analytical work is vulnerable not because the AI technology itself is bad, but because the nature of the task runs directly against AI's structural weaknesses. The work demands a high degree of factual accuracy in figures, citations, and dates. AI, meanwhile, has an inherent tendency to hallucinate. These business documents are also used as the basis for high-value decisions that will be audited by the board of directors, commissioners, lending banks, and the Financial Services Authority (OJK). The biggest temptation for employees is that AI can write with tremendous confidence. But fluent prose is no guarantee of factual accuracy.

This pattern of overtrusting AI's capabilities isn't just about documents, it's also about the human resource decisions that sit above them. Orgvue data shows that 39 percent of business leaders cut positions lured by AI's promise, yet 55 percent of them later admitted that decision was a mistake. Robert Half's findings even show that 32 percent of managers in the United States were forced to rehire staff after those roles had been replaced by AI. These two data points are about staffing decisions, not the accuracy of figures in a document. But both point to the same symptom: organizations routinely overestimate what AI can actually do, whether deciding who to keep on staff or trusting what it writes.

Four Risk Patterns Management Must Watch For

There are four specific risk patterns in analytical work that management should watch closely.

The first is market research. AI can produce a string of numbers that sound entirely plausible but can't be traced back to their original source. This exact same pattern of deception occurred in the EY case, where figures with different underlying definitions were forced to look consistent. Using this raw data as the basis for an investment is a dangerous gamble.

The second concerns risk assessments. These intelligent machines are very good at detecting patterns from historical data, but very weak when facing unexpected events or local context absent from their training data. This creates a false sense of confidence. An assessment can look thoroughly comprehensive, while its entire structure rests on assumptions that human judgment never actually verified.

The third concerns drafting business plans or feasibility studies. AI can easily produce financial projections that look neat and mathematically logical. As a Chartered Accountant who regularly dissects the structure of financial feasibility (a topic I explore further in AI at the Corporate Table), I often find a fundamental weakness here. Base assumptions such as market growth, commodity price swings, and absorption rates often go unvalidated against conditions on the ground. It's extremely risky when this pro forma document is handed over as-is as the basis for a bank loan application.

The fourth is drafting the final report. AI tends to smooth out language to the point of losing the sharp precision of the numbers. Another risk is that the machine assembles structure from other sources without the document's author realizing it, which ultimately raises issues of intellectual honesty and data ownership.

The Regulatory Gap and a Middle Path for Adoption

On the regulatory front, this governance space isn't actually a complete void. OJK has issued the Indonesian Banking Artificial Intelligence Governance framework along with the technical regulation on Information Technology Administration by Commercial Banks that took effect in early 2026. However, those rules specifically bind only the banking industry. Non-bank companies and state-owned enterprises in energy, infrastructure, and various other sectors don't yet have local guidance at that level. Waiting for sector regulators to step in will take time. Proactive boards of directors can certainly adopt already-established global standards, such as NIST's AI risk management framework (a US government technology standards body) or the ISO 42001 certification standard (the first international standard specifically for AI system governance), as a direction for internal policy.

Of course, holding back from AI entirely isn't a realistic option. Companies that adopt this technology too slowly risk losing ground to competitors who have already cut down their research and analysis time. Precisely because that competitive pressure is real, the pace of adoption needs to be balanced with control, not avoided altogether.

Ilustrasi batas aman penggunaan AI untuk riset pasar dan laporan bisnis
A visual recap: the adoption-compliance gap, the four analytical risk patterns, and the guardrails to close it.

Building Practical Operational Guardrails

To protect the company, management needs to build guardrails that are practical yet firm. Absolute verification must be mandatory for every number, citation, and source produced by AI before it goes into an official draft. This needs to be a standing company protocol, not something left to an employee's discretion. Document approval also needs to be tiered according to the level of risk. The larger the investment value in a feasibility study, or the more strategic a risk assessment, the higher the level of official required to give final validation.

Equally important is transparency about AI use. Employees need to document how much of a role the virtual assistant played in producing a document. I apply this same principle of openness to every piece I publish on mulyagusdin.com, where I attach an AI level label from zero to three to show how much the machine intervened in the creative process. If this transparency standard can be applied consistently to a personal opinion piece, the same should certainly be required for corporate documents worth billions of rupiah.

A companion practical guide is available

Operational procedures and a verification checklist for the safe limits of AI use in the corporate setting, ready to use.

Read & download the Practical Guide to Safe AI Limits in the Corporation

Management also needs to set a hard rule against submitting raw AI output without a clear audit trail. Every use needs to include information about what instructions were used and for what purpose the query was made. All of these procedures then need to be formalized through explicit clauses in the company's internal policy.

Building these guardrails is a crucial step in protecting the quality and integrity of work at the corporate level. Companies that dare to write their own rules starting today will earn far more respect and trust from stakeholders than those who only wake up after getting caught in a reputational crisis caused by a machine they trusted blindly.

Instinct and Leadership That AI Cannot Replace

The Orgvue and Robert Half data mentioned at the start of this piece actually hold a deeper lesson than just a budgeting miscalculation. When 39 percent of business leaders cut positions lured by AI's promise, and more than half of them later admitted that decision was wrong, what actually happened is they lost faith in human dynamism and pragmatism first, before it was ever properly tested whether AI could really replace it. There are two capabilities that often get left out of that calculation: instinct in the face of crisis, and the ability to bring many different minds together into a single direction.

I felt the first of these during a hike to a rocky beach at the far edge of Aceh with two companions. The weather changed drastically and a carefully laid plan had to be abandoned on the spot, within minutes, with no time to systematically recalculate. What saved that trip wasn't a navigation device or weather data, but trained instinct and the trust between team members that had already been built long before the storm arrived.

Tim pendakian mengambil keputusan cepat di tengah cuaca ekstrem, insting yang tidak bisa digantikan AI
Decisions were born from instinct and team trust, not machine calculation.

I experienced the second form on an even larger scale, when I had just taken over leadership of a regional state-owned enterprise whose way of working wasn't yet organized or pointed in a single direction. I gathered everyone, from management down to the office boys, security guards, and drivers, to sit together in one room for two days to rethink the company's direction and way of working. No algorithm could sit in that room, listen to everyone's objections, weigh conflicting interests, and then convince everyone to move in the same direction. What came out of those two days wasn't just a new policy document, but the trust that made that policy actually get carried out.

Rapat kerja lintas jabatan menyatukan arah kerja perusahaan, sesuatu yang tidak bisa dilakukan AI
Two days sitting together, from management down to the office boys and drivers, to unite the company's direction.

Instinct in a crisis and the ability to unite a vision across ranks both come from experience and empathy, not data calculation. This is what often gets missed when efficiency decisions are made too quickly, on the assumption that AI can replace the full range of judgment needed to lead.

Sources and References

Leave a Reply

See Also

Loading related articles...

Discover more from Mulyagusdin

Subscribe now to keep reading and get access to the full archive.

Continue reading