“The Four Horsemen of Generative AI” are security vulnerabilities, third-party risk, privacy and copyright, and output quality. Suha Can, Grammarly’s chief information security officer, uses those four categories to organize risks facing organizations that adopt generative AI. They are a useful starting point, not a universally validated, ranked, or exhaustive taxonomy.
The larger megatrend is that generative AI is spreading across work and creative tasks while its costs, benefits, and consequences remain uncertain. Understanding Can’s four risks alongside the technology’s capabilities, business outlook, and societal effects helps organizations plan without treating either forecasts or hype as certainty.
What are the four horsemen of generative AI?
In an October 2023 article, Suha Can introduced her framework as “nightmare-level threats” and named four categories: security vulnerabilities, third-party risk, privacy and copyright, and output quality. The phrase is Can’s characterization, not an independent standard or a measure of which risk is most likely. Her article does not quantify comparative risk rates. Grammarly: The Four Horsemen of Generative AI
Security vulnerabilities
Generative AI changes the security landscape organizations must assess. Systems may involve models, interfaces, data flows, and connected services; security review should account for how these elements are used and tested. Can identifies this as a risk category but does not provide an incident rate or comparison with other threats.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
Third-party risk
Organizations may rely on outside model providers, platforms, and other suppliers. Those dependencies make supplier due diligence part of AI risk management: an organization needs to understand the external services in its system, rather than treating a model as a self-contained tool. Can names third-party risk, but her framework does not quantify its frequency.
Privacy and copyright
Privacy review should consider what information enters a system, how it is handled, and whether its use is appropriate. Copyright questions also arise around training data and generated material. The U.S. Government Accountability Office (GAO) notes that model training commonly uses large datasets, including publicly available internet material that may include copyrighted content. That observation does not determine whether a particular model or use is lawful. GAO: Generative AI
Output quality
Generated material can be inaccurate or unsuitable for its purpose. GAO identifies difficulty understanding and explaining model decisions, and its 2025 assessment includes inaccurate information among possible unsafe outputs. Organizations using generated content in consequential work therefore need appropriate verification and clear human accountability; this does not mean that every output is unreliable. GAO: Generative AI—Key Issues and Opportunities
Rank #2
What generative AI does—and what makes it possible
Generative AI produces text, images, audio, or video in response to prompts. Natural-language prompting is one feature that distinguishes these systems from many earlier forms of software. Their development has been enabled by large datasets, advances in deep-learning algorithms, and increased computing capacity, according to GAO. Models can nevertheless be difficult to interpret: it may not be clear how a system arrived at a particular result. GAO: Generative AI
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
GAO reports that training large models can take tens of thousands of processors running for months and may cost several hundred million dollars. That describes the resource demands of training large models, not the cost of every AI model or of each request to an already-trained system.
Why the four risks sit inside a wider megatrend
Can’s four categories describe organizational risks; they are not a complete map of generative AI’s economic, environmental, and social effects. IEEE uses “megatrends” for developments that affect multiple trends of worldwide importance and intertwine with economic, ecological, and social forces. That broader lens helps explain why the technology’s significance goes beyond any single list of security concerns. IEEE: Megatrends and the Future of Technology
GAO identifies potential applications in health care, education, software engineering, and business. It also flags possible disinformation, worker displacement, national-security concerns, and environmental risks. For many applications, the benefits and harms are not yet clear. GAO: Generative AI
How should organizations plan when the outlook is uncertain?
Planning frameworks can clarify assumptions, but neither scenarios nor maturity charts tell an organization exactly what will happen. Deloitte’s Center for Integrated Research developed four plausible enterprise futures through the end of 2027 using quantitative surveys, specialist interviews, and horizon scanning. The scenarios are intended to help organizations pressure-test strategy, not to predict the future or prescribe one response. Deloitte: Generative AI and the future of the enterprise
Gartner describes its Hype Cycle as a graphical representation of technology maturity, adoption metrics, and business impact. It can help technology leaders consider innovations in relation to risk appetite and potential reward. Gartner’s July 2026 article projects that at least 50% of GenAI projects will overrun budget through 2028 because of poor architectural choices and a lack of operational know-how. This is Gartner’s projection, not an observed rate across all projects. Gartner: Hype Cycle for Artificial Intelligence
Organizations can use these perspectives to test whether an initiative is ready for deployment and oversight, rather than asking only whether a model can perform a task. Relevant considerations include:
- Maturity and adoption: How established is the technology, and how widely is it being used?
- Business impact and risk tolerance: What benefit is expected, what could go wrong, and how much risk is acceptable?
- Architecture and operational readiness: Are systems designed and staffed to operate the application reliably?
- Data and suppliers: Are data handling and external dependencies understood and appropriately controlled?
- Output verification and oversight: Who checks results, and who remains accountable for decisions that rely on them?
- Alternative futures: Would the strategy still make sense under different plausible conditions, rather than only the most optimistic scenario?
What are the environmental and societal stakes?
GAO’s 2025 assessment says generative AI uses significant energy and water, while companies generally do not report detailed use. The International Energy Agency estimated that U.S. data centers used approximately 4% of U.S. electricity demand in 2022 and could use 6% in 2026, as cited by GAO in 2025. Those figures cover data centers overall, not generative AI’s isolated share; GAO says that share is unclear and that water-use estimates are limited. GAO: Generative AI—Key Issues and Opportunities
GAO also discusses governance approaches such as risk frameworks, independent review, and shared standards. Better reporting could help clarify environmental impacts, while independent review and common standards can support oversight. These approaches bring trade-offs: reporting and review take resources, transparency may be limited, and standards can be difficult to implement consistently. GAO: Generative AI—Key Issues and Opportunities
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Best Value
For readers concerned with European impacts, the European Commission Joint Research Centre’s 2025 outlook considers technical capabilities, economic and societal effects, the EU regulatory context, and sector-specific opportunities and challenges. It highlights possible benefits as well as concerns including misinformation, bias, labor disruption, privacy, and over-reliance. Specific legal obligations depend on current law and circumstances, so this overview should not be treated as a statement of the rules applicable to a particular system or use. European Commission Joint Research Centre: Generative AI outlook
How to interpret “the four horsemen”
Can’s list is useful as a prompt for an organizational review: examine security, suppliers, privacy and copyright, and the reliability of outputs. It should not be mistaken for a complete inventory of AI’s consequences or a ranking supported by comparative statistics. The wider picture includes opportunities, business uncertainty, effects on people and institutions, and resource demands—areas where current evidence and attribution can still be limited.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

