Identifying, measuring, and treating risks specific to AI systems: model risk, data risk, third-party model risk, prompt-injection and abuse risk, and reputatio
AI risk management quantifies and controls the new exposure class: hallucination harm, agentic action risk, model dependency, data leakage, and reputational blast radius, integrating AI into enterprise risk frameworks with metrics, owners, and tested responses.
Institutionalizing fast: boards expect AI in the risk framework, insurers probe it, and managers who handle probabilistic-system risk with rigor move into senior governance seats.
Speed and silence: agentic systems act at machine pace, and quality failures degrade silently rather than crashing loudly. Controls must detect statistical drift and bound autonomous blast radius: new muscles for classic ERM.
Frequency × exposure × consequence: measured error rates from evals, volume of affected decisions, and harm severity per error class. It turns 'the model is sometimes wrong' into a managed number.