Up to the previous chapters, we've introduced AI's convenience and how to use it. But to truly "master" AI, it's essential to properly understand the risks. Knowing the risks isn't about being scared of AI. Just like learning "how to use the brakes" when driving a car, it's the basic knowledge for using it safely.
Risks aren't things to "fear" but things to "know about"
Know the 5 major risks of AI
The risks to keep in mind when using AI can be organized into five. Each has a different character, so let's first grasp the big picture. We'll dig into each one below.
A phenomenon where it outputs plausible, confident-sounding information that isn't grounded in fact. AI's biggest risk.
A double issue of training data and generated output. Lawsuits are underway worldwide.
The data you enter may be used for training. Once entered, it can't be taken back.
Social biases contained in the training data are reflected directly in the output.
Indistinguishable fake media made by AI. Abused for fraud and impersonation.
Hallucination — AI lies with full confidence
Hallucination is the phenomenon where AI outputs information not grounded in fact as if it were true, and with full confidence. It's no exaggeration to call it the biggest risk of using AI.
Why it happens — understanding the mechanism
AI works by "predicting the word most likely to come next." In other words, it isn't outputting "what's correct" — it's merely outputting "what's plausible." AI doesn't judge truth or falsehood. It isn't consulting a dictionary; it's doing nothing more than pattern matching.
Hallucination rates differ greatly by model. A 2025 benchmark survey found that the best model (Gemini 2.0 Flash) was at 0.7%, while some models had results where nearly 30% were hallucinations[2]. Improvement is progressing, but it won't reach zero.
Real-world cases
- Fictional case law — a US lawyer submitted case law researched with ChatGPT to a court, only for the cited cases not to exist (2023)
- Fictional papers — plausibly generating non-existent paper titles and author names
- Wrong statistics — confidently asserting "the market size of X is Y billion," when the actual figure is wildly different
- Legal domain — a Stanford University study found cases where the hallucination rate on legal queries reached 69–88%[2]
Four defenses
You handle hallucination not by "making it zero" but with a "mechanism to catch it." Make these four steps a habit.
Ask back, "What's the source for that?" Be skeptical of claims it can't cite a source for.
Always confirm numbers, laws, and names against primary sources like official sites or the original text.
Put the same question to several AIs, and treat it as a warning sign if their answers diverge.
Research with search AIs that answer with source links, like Perplexity and Gemini.
The information to be especially wary of is these four: statistics and numbers, names and proper nouns, law and taxation, and breaking news. Always verify this information against primary sources.
💡 A practical tip: If you use AI tools that tie into web search, like Perplexity and Gemini, answers come back with source links. For important research tasks, it's a smart move to use these search-AI tools for the job. In businesses, adoption of AI guardrails — which structurally prevent AI's wrong answers — is also advancing.
Copyright — is it OK to use? Who owns what it makes?
The AI-and-copyright issue splits broadly into two: "is it OK to use copyrighted works for AI training?" and "does what AI makes have a copyright?"
Issue 1: AI training data and copyright
AI models are trained on huge amounts of content from the internet (text, images, code, and more). Lawsuits are being brought worldwide, arguing that works are being used without the copyright holders' permission.
| Lawsuit | Overview | Status (as of 2026) |
|---|---|---|
| NYT vs OpenAI | The New York Times sued over unauthorized training on its articles | In dispute |
| Getty vs Stability AI | Sued over unauthorized training on photos | In dispute |
| Artists' class action | Works used without permission to train image-generation AI | Multiple ongoing |
| Yomiuri, Asahi, Nikkei vs Perplexity | Unauthorized use of articles, seeking about ¥6.6 billion in total damages | Filed in 2025 |
Issue 2: Copyright of AI-generated output
Whether copyright is recognized for AI-generated content varies by country's judgment.
What AI generates autonomously has no copyright. However, if a human is creatively involved, it may be protected.
The Copyright Office's position is "no copyright for AI-alone output." With human creative control, it may be partially recognized.
Rule-making is underway regarding the copyright of AI-generated output.
What you should be careful about
- For commercial use, always check each service's terms
- Don't specify a particular artist's name in image generation ("in the style of X" invites copyright trouble)
- Check whether AI output resembles an existing copyrighted work
- Where necessary, state clearly that it's AI-generated
Privacy — what you may hand to AI
In 2023, an employee at Samsung Electronics entered internal confidential code into ChatGPT, which became major news. Prompted by this incident, many companies have come to establish policies on entering information into AI.
Data you enter into AI may be used to improve the service or train the model. Act on the premise that "information once entered can't be taken back." We explain what to enter and how in detail in Things to be careful about when entering data into AI.
- Company confidential information / unreleased source code
- Customers' and clients' personal information
- Passwords / API keys / credentials
- Unreleased financial or HR data
- Secret information entrusted to you by others
- Information that's already publicly available
- Data with personal and company names anonymized
- Text you wrote yourself and plan to publish
- Press releases and public materials
- Fictional or sample data
Concrete measures for data protection
| Measure | Explanation |
|---|---|
| Turn off chat history | Both ChatGPT and Claude let you stop training use of your conversation data in settings |
| Enterprise editions | Business plans guarantee your data isn't used for training |
| Anonymize information | Before entering, replace personal names with "Person A" and company names with "Company X" |
| Run locally | Run open-source models on your own PC with tools like Ollama |
💡 A criterion for when you're unsure: Ask yourself, "Would I mind if this information were made public on the internet?" If the answer is "yes, I'd mind," you shouldn't enter it into AI. If you're running it as an organization, it's safest to put your corporate AI usage guidelines in writing.
Bias and deepfakes
AI bias — biases in the training data show up in the output
AI bias is the phenomenon where social prejudices contained in the AI's training data are reflected directly in the output. AI isn't giving "the correct answer" — it tends to give "the answer that was in the majority within the training data."
- Gender bias — generate images of "nurses" and you get only women; "engineers," only men
- Cultural bias — a tendency to answer with values skewed toward English-speaking and Western perspectives
- Confirmation bias — over-reflecting majority opinions, so minority viewpoints drop out
Countermeasure: Don't take AI's answers at face value; get into the habit of instructing it to "consider other perspectives too" or "give the opposing view as well." For important decisions like hiring and HR evaluation, it's especially important not to make AI's judgment the sole basis.
Deepfakes — indistinguishable disinformation
As AI's technology for generating realistic images, video, and audio advances, the risk of deepfakes (fake media made by AI) is surging. Deepfakes on social media are estimated to have surged from 500,000 in 2023 to 8 million in 2025[3].
- Voice-cloning fraud — phone scams that imitate a family member's or boss's voice with AI. A clone can be made from a few seconds of audio
- Fake videos — manipulating public opinion or impersonating people with fake videos of celebrities and politicians
- Fake news — mass-spreading plausible AI-generated news articles
🛡️ Points for protecting yourself
- For urgent calls like "send money right away," verify the person's identity by another means
- Check the source of shocking images or videos you see on social media
- Keep a constant, healthy skepticism toward content that may have been AI-generated
As AI agents spread, new attacks — including this kind of abuse — are appearing. For the corporate-side perspective, Explaining AI agent security incidents is also a useful reference.
Regulatory trends worldwide — rule-making has begun
To address AI's risks, countries worldwide are rushing to build legal frameworks.
| Region | Regulation | Features |
|---|---|---|
| EU | AI Act (enacted 2024) | Risk-based regulation. Strict standards for high-risk AI (hiring, medicine, justice). Phased application began in 2025 |
| Japan | AI Promotion Act (enacted May 2025) | An "innovation-first" approach. Prioritizes promotion over regulation while also building safety standards |
| United States | Executive order on AI safety | No comprehensive federal law yet. Regulation advances state by state |
In December 2025, Japan adopted its "AI Basic Plan" by cabinet decision, planning AI-related investment on the scale of ¥1 trillion over five years[1]. A "Japanese-style" approach — not over-tightening regulation, but building safety standards while promoting innovation — is drawing attention.
A safety checklist for using AI
Having understood the risks, how should you actually act? We've compiled checklists from the standpoint of both individuals and organizations.
- Don't take output at face value — always verify important information against primary sources
- Don't enter confidential information — judge by "would I mind if this were public?"
- Verify numbers and proper nouns — the area most prone to hallucination
- Watch for bias — be aware of skew in AI's output
- Check copyright — always check the terms for commercial use
- Disclose AI use appropriately — disclose AI use in reports and articles
- Final responsibility is yours — responsibility for results using AI output lies with the user
- Establish and communicate an AI usage policy — put in writing what may be entered, and in which tasks
- Conduct employee training — educate on the correct use of AI and its risks
- A review flow for AI-generated output — build a mechanism for humans to check before publishing
- Consider enterprise editions — consider business plans with strong data-handling guarantees
- Prepare incident-response procedures — decide the response flow in advance for when problems arise
- AI's risks are not things to "fear" but things to "know about." We surveyed the 5 major risks at a glance.
- The basic hallucination defense is verification — the 4 steps of demanding a source, using primary sources, comparing multiple AIs, and using search AIs.
- The basic privacy measure is the "would I mind if this were public?" test. Don't enter secrets.
- Watch out for copyright, bias, and deepfakes too, and don't forget that final responsibility lies with the user.
- Regulation worldwide — the EU AI Act, Japan's AI Promotion Act, and more — is being built out at a rapid pace.
References
- "Japan adopts first AI basic plan." The Japan Times, December 23, 2025.
- Vectara. "Hallucination Leaderboard." GitHub, 2025. / Stanford RegLab. "Legal Hallucination Study." 2025.
- Deepstrike. "Deepfake Statistics 2025." deepstrike.io, 2025.
Related links:
- EU AI Act Explorer — the full text and explanation of the EU AI regulation
- MIC AI-related policy — an overview of Japan's AI policy
In the next chapter, we'll explain the latest trends in AI — multimodal AI, AI agents, and the trends of 2025–2026.