5 AI Missteps Transportation Companies Should Watch For
Key Takeaways:
- Artificial intelligence (AI) can strengthen route planning, maintenance forecasting and customer service, but adoption often outpaces governance.
- AI risk is a business issue, not just an Information Technology (IT) issue, and works best when finance, legal, compliance and operations are involved early.
- Clear, practical guidelines for employee AI use can prevent sensitive company or customer data from ending up in public AI tools.
- Vendor-embedded AI features still need a security review. The vendor’s adoption of AI doesn’t automatically mean the risk has been addressed.
- AI output is a helpful input to a decision, not a substitute for professional judgment.
Artificial intelligence (AI) is quickly becoming a competitive advantage in the transportation industry. According to Penske’s 2025 Transportation Leaders Survey, 70% of transportation and logistics companies report adopting AI solutions, a 17-point increase from the previous year, highlighting how quickly AI is becoming embedded in industry operations.
Fleet operators are using it to predict maintenance needs before a truck breaks down. Logistics teams are using it to optimize routes and reduce fuel costs. Customer service teams are leveraging AI to respond to customer inquiries faster than ever before.
The potential benefits are great. However, many transportation companies are subject to making the same mistake we’ve seen with every major technology shift: adopting the technology faster than governing it.
Transportation companies should embrace AI. The real question is whether they’re doing it securely and responsibly. Here are five AI security missteps we see organizations making today.
1. Treating AI as a Technology Project Instead of a Business Risk
Many organizations assume AI is something the Information Technology (IT) department should manage. But in reality, AI impacts core business operations.
Consider a logistics company that uses AI to recommend delivery routes. If the model makes poor recommendations, the result could be missed delivery windows, increased fuel costs, customer dissatisfaction and operational disruption. The issue is no longer a technological risk; it’s a business risk.
That is why AI governance should include operational leaders, finance, compliance, legal and information security teams, not just IT.
Despite growing adoption, many organizations are still struggling to govern AI strategically. A 2025 Gartner survey found that only 23% of supply chain organizations have a formal AI strategy, suggesting many companies are implementing AI without a comprehensive governance framework.
The organizations achieving the most success with AI are treating it as an enterprise-wide risk management initiative rather than a standalone technology deployment.
2. Allowing Employees to Experiment Without Guardrails
Imagine a dispatcher trying to save time by asking ChatGPT to rewrite a customer communication regarding a delayed shipment. To provide context, the dispatcher pastes details about the customer shipment location and contract terms into the prompt.
While the dispatcher’s intentions were good, the problem is that sensitive business information may have been shared with the public AI platform without approval.
This is becoming increasingly common in organizations. In fact, a 2025 TELUS Digital survey of 1,000 U.S. enterprise employees found that 57% of generative AI users had entered sensitive information into public AI tools, while 68% accessed AI assistants through personal rather than company-approved accounts. These findings highlight how quickly “shadow AI” can develop when employees lack clear guidance and approved alternatives.
Whether drafting customer communications, analyzing spreadsheets, summarizing contracts or creating presentations employees are often adopting AI tools before formal policies are established.
Creating practical guidelines around approved tools, acceptable use and prohibited data is a more effective solution than banning AI outright. Employees generally want to do the right thing and just need clear direction.
3. Forgetting That Data is the Company’s Most Valuable Asset
Before deploying AI, organizations should ask themselves: “What data can this tool access, and is that OK?”
Transportation companies manage tremendous amounts of valuable information every day. This includes customer contracts, freight rates, driver information, maintenance records and supply chain information.
Imagine implementing a new AI platform that has broad access to the systems maintaining that data, without fully understanding what information the AI platform can see, store or share. Answering the questions above can help organizations identify risks that may not have been previously considered.
4. Trusting AI Features Embedded in Vendor Products
Vendor-provided transportation management systems, fleet management platforms and Enterprise Resource Planning systems (ERPs) are rapidly introducing AI-powered capabilities. And while these systems can create efficiencies, organizations may incorrectly assume that the vendor has already addressed the relevant security concerns.
For example, a vendor may introduce an AI-powered feature that automatically analyzes shipment trends or generates customer communication. Before enabling those capabilities, organizations should look to understand the following:
- What data is being shared with the AI engine?
- What security controls are in place to protect the data?
- How are outputs validated?
- Is customer information being used to train the AI model?
5. Believing AI is Always Correct
This may be one of the more challenging risks to catch because AI can be incredibly convincing, even when the information it’s presenting is not correct.
AI can help organizations make better decisions, but professional judgment should not be replaced. Human review is particularly important when AI can have an influence on customer communications, pricing decisions, operational planning, compliance activities and financial reporting.
Turning AI Governance Into a Business Advantage
Good governance around transformative technology can help organizations create a strong competitive advantage. Companies that adopt AI responsibly will be well positioned to leverage the potential that AI has to transform the transportation industry. The organizations that do this successfully will be able to innovate with confidence while maintaining the trust of customers, regulators and business partners.
AI adoption is moving quickly across the transportation industry, and the security and governance side often lags behind. Contact the Moore Colson Transportation team to talk through a practical, risk-aware approach to AI adoption for your business.
FAQ
What are the problems with AI in transportation?
The most common issues are governance gaps rather than the technology itself: AI decisions being treated as IT-only concerns, sensitive data ending up in public AI tools and vendor AI features going live without a security review.
How do I assess AI vendor risk?
Ask what data the AI feature can access, what security controls protect it, how outputs are validated and whether your data is used to train the vendor’s model. These questions apply even when the AI capability is bundled into a system you already trust.
What are best practices for AI governance?
Effective AI governance usually involves leaders from operations, finance, compliance, legal and information security, along with written guidelines for approved tools and prohibited data types, and a habit of human review before AI-informed decisions go into effect.
What is enterprise AI governance?
It’s the framework an organization uses to manage AI risk across the business, rather than leaving oversight to any single department.
About the Author
Journet Greene, CISA, is a Partner in Moore Colson’s Risk Advisory Practice Area with more than 20 years of accounting and advisory experience. She leads the firm’s System and Organization Controls (SOC) audits and IT risk assessment engagements.
Disclaimer: This content is provided for informational purposes only and reflects information available as of the date of publication. It does not constitute legal, tax, accounting, or other professional advice. Please consult a qualified professional before taking action based on this content.

