Versatile AI Risk Assessment

AI threat catalogueReliability and Responsible UseProduction

Overreliance

People tend to accept convincing-sounding AI outputs without checking them (automation bias). When employees or downstream systems rely uncritically on AI for important decisions, errors go undetected and cause real-world harm.

As of: July 2026 · Catalogue version 2026.07.17.3 · 5 mitigations · 11 verified sources

Description

AI systems phrase their answers fluently and confidently even when the content is wrong. This is exactly what fuels automation bias: the human tendency to trust the results of an automated system more than one's own judgement. This threat does not come from attackers; it arises in everyday work, for example under time pressure or when knowledge about the limits of AI is missing. It becomes especially critical when AI outputs feed into follow-up decisions or other systems without human review: a single undetected error then propagates and compounds. A decline in model quality also stays invisible for as long as nobody questions the results.

Possible impact

Poor decisions based on unchecked AI outputs first hit the people affected, such as applicants, customers, or patients, and then fall back on the company. Financial losses, liability questions, and reputational damage follow. The EU AI Act requires effective human oversight for high-risk systems, and the GDPR places strict limits on fully automated individual decisions.

Example

An HR department has incoming applications pre-ranked by an AI system and adopts the ranking as it is. Only months later does it emerge that the system systematically screened out suitable candidates and that nobody had ever spot-checked its recommendations.

Recommended mitigations (5)

Every mitigation states its control type, effect, implementation level and the reason for the classification.

Framework mappings

Verified locations in OWASP, NIST AI RMF, MITRE ATLAS, the EU AI Act and further frameworks. The mappings are taxonomic, not evidence of compliance.

OWASP LLM Top 10 LLM09:2025NIST AI RMF Section 2.2 · Section 2.7 · GOVERN 3.2EU AI Act Article 13(1), 13(3)(b)(ii), (iv), (v) · Article 14(4)(b) · Article 4BSI R8BIML BIML-LLM LLMtop10:9 · BIML-LLM output:12 · BIML78 system:2

Verified references (11)

Every reference states the framework, the exact location and the publishing organisation.

More entries from the topic group Reliability and Responsible Use.

Assess this threat in your own system

The live demo contains all 52 threats of this catalogue, including the EU AI Act and GDPR assessment. The free single modules cover AI risk, the EU AI Act and GDPR. No sign-up; the assessment runs locally in your browser.

Cite this entry

For reports, policies or internal documents; the link leads directly to this entry.

“Overreliance”. Versatile AI Risk Assessment, AI threat catalogue, as of July 2026.
https://www.versatile-ai-risk-assessment.com/en/wissensbasis/threats/overreliance/

← Back to the full catalogue