Executive summary
Artificial intelligence can create real competitive advantage, but the greatest risk to most AI transformation programmes is not the technology — it is the advice. This article sets out how boards and executives can recognise AI charlatans, ask the right questions before approving investment, and select partners who understand governance, risk and delivery as well as AI.
Artificial intelligence is transforming industries at an unprecedented pace. Organisations across every sector are investing heavily in AI to improve efficiency, reduce cost, strengthen decision-making and unlock new opportunities. Yet despite the excitement, many AI initiatives fail to deliver the expected value.
The problem is often not the technology. The problem is the people leading the transformation.
As demand for AI expertise has increased, so has the number of individuals and firms claiming to be AI specialists. Some possess deep technical and business expertise. Others rely on impressive demonstrations, fashionable terminology and unrealistic promises, without the governance, implementation experience or strategic thinking required to deliver sustainable change. These AI charlatans may be one of the greatest risks facing organisations today.
AI is not the objective
AI is not a business strategy. It is an enabler. Organisations create value only when AI supports:
- Business strategy
- Governance
- Risk management
- Regulatory compliance
- Operational excellence
- Change management
Organisations that begin with technology instead of business problems frequently discover that expensive AI investments generate very little measurable value. That is why AI strategy belongs inside a wider business transformation advisory agenda rather than alongside it, and why digital transformation advisory work should start with outcomes rather than platforms.
Five warning signs of an AI charlatan
1. They sell technology before understanding your business
Transformation should begin with business objectives, not AI tools. An advisor who cannot describe your operating model, your regulatory environment and your value drivers before recommending a platform is selling, not advising.
2. They promise instant transformation
Successful AI adoption requires governance, experimentation, process redesign, change management and continuous improvement. Transformation is never instant.
3. Governance is missing
Responsible AI requires:
- Accountability
- Human oversight
- Model governance
- Cybersecurity
- Data governance
- Explainability
- Ethical principles
If governance is absent, risk increases significantly. Boards that treat AI oversight as part of their existing governance, risk and controls advisory framework tend to move faster, because the control questions are answered once rather than re-litigated at every stage gate.
4. They ignore regulatory requirements
Many regulated industries cannot simply upload confidential information into public AI platforms. Organisations must consider:
- Cross-border data transfer restrictions
- Central bank regulations
- Banking secrecy
- Customer confidentiality
- Privacy laws
- Data minimisation
- Local hosting requirements where applicable
Innovation should never come at the expense of compliance.
5. Everything is about AI
Experienced advisors understand that AI is not always the answer. Sometimes process redesign, automation, governance improvements or stronger controls create more value than AI itself. AI should solve business problems, not create new ones.
Questions every board should ask
Before approving major AI initiatives, boards should ask:
- What business problem are we solving?
- How will success be measured?
- What new risks are introduced?
- Who owns AI governance?
- How is regulatory compliance maintained?
- What controls exist over models and data?
- How are third-party AI providers assessed?
- What happens if the AI solution fails?
Where a board lacks the confidence to press on these points, independent board advisory support is usually a faster route to good judgement than another vendor presentation.
Internal audit has a critical role
Internal audit should not simply audit AI after implementation. It should provide assurance over:
- AI governance
- Model risk
- Data governance
- Cybersecurity
- Third-party providers
- Regulatory compliance
- Continuous monitoring
Our internal audit advisory services set out how this assurance is planned and delivered in practice. For the audit approach itself, see how internal audit should audit AI. Modern internal audit can also use AI to improve planning, analytics, testing and reporting while fully respecting applicable regulatory requirements, a theme explored in the future of internal audit in the age of AI.
Choose transformation partners, not technology vendors
Successful organisations rarely begin by asking which AI platform they should buy. They ask how they can improve the business. Technology is only one part of successful transformation. Leadership, governance and execution remain the true competitive differentiators.
Conclusion
Artificial intelligence represents one of the greatest business opportunities of our generation. It also represents one of the greatest opportunities for poor advice. Selecting the wrong transformation partner can delay strategic initiatives, weaken governance, expose organisations to regulatory risk and destroy stakeholder confidence.
Choose advisors who understand governance as well as technology, risk as well as innovation, and sustainable business value as well as AI. Successful transformation has never been about technology. It has always been about delivering better business outcomes.
Frequently asked questions
What is an AI charlatan?
An AI charlatan is an individual or firm that presents itself as an AI specialist without the governance, delivery or domain expertise required to make AI work. The pattern is recognisable: polished demonstrations, heavy jargon, aggressive timelines, and no credible answer on risk, controls, data protection or measurable business outcomes.
How can organisations choose the right AI advisory partner?
Test whether the advisor starts with your business problem rather than their technology. Ask for evidence of delivered outcomes, for their approach to AI governance and model risk, for how they handle regulated data, and for the circumstances in which they would advise against AI. A credible AI advisory partner will describe trade-offs, not certainties.
Why is AI governance important?
AI governance establishes accountability, human oversight, model and data controls, explainability and ethical boundaries. Without it, organisations cannot demonstrate how automated decisions are made, cannot evidence compliance to regulators, and cannot detect model drift or misuse before it causes harm. Responsible AI is what makes AI adoption sustainable at scale.
What role should internal audit play in AI transformation?
Internal audit should provide independent assurance across AI governance, model risk, data governance, cybersecurity, third-party AI providers, regulatory compliance and ongoing monitoring, engaging early rather than after go-live. It should also advise the audit committee on whether AI risk is being managed within the board's stated appetite.
Can AI be implemented while complying with regulatory requirements?
Yes. Compliant AI implementation depends on design choices: appropriate hosting and data residency, data minimisation, restrictions on confidential information entering public models, documented model governance, and clear human accountability for decisions. Regulated organisations routinely deploy AI successfully when compliance requirements are treated as design inputs rather than obstacles.
Key takeaways
- AI is an enabler, not a strategy — value comes from the business problem it solves
- Charlatans sell tools first, promise instant results and have no answer on governance
- Regulated organisations must treat data residency, confidentiality and privacy as design inputs
- Boards should agree measurement, ownership and failure scenarios before approving AI investment
- Internal audit should assure AI governance, model risk and third parties before go-live, not after
Written by
DisInnova Advisory Team
DisInnova's insights are prepared by a senior practitioner-led advisory firm with credentials across internal audit, IT audit, governance, risk management, controls, fraud examination, strategy, corporate governance and financial services, including CIA, CISA, CFE, CRMA, CRISC and related professional certifications.
This article is general advisory information and does not constitute legal, regulatory, audit, tax, investment or professional assurance advice.