AI is not a standalone risk. I repeat. AI is not a standalone risk.
A recent chat with someone who has been looking at AI governance for a while reminded me of it. He was telling me about how a senior advisor had been pushing for AI to be a standalone risk area. And a centralized risk management unit responsible for all AI risks. And after some pushback, landing on a compromise - that even if AI risk was not fully standalone, there might be merit in treating it that way for specific use cases.
I told him that this makes zero sense. And that it will almost certainly lead to issues on both the innovation and risk side.
Why I think so. AI is not a separate thing. Try drawing a clear line between what is AI and what is not these days. For the recent incidents where LLMs from OpenAI, Anthropic and others hacked external organizations despite being sandboxed, would you view it as technology risk, or some special AI risk? If we let a separate unit own all AI risk including third party AI, what is the existing third party risk unit left with? You get the idea.
AI shows up inside the risks you already have. An AI credit model is credit risk. Nobody invented a new risk called “spreadsheet risk” when Excel arrived, or “internet risk” when the web did.
Have a central function to set the standard and coordinate, fine. But owning all the risk is a different thing, and illogical for a few reasons.
First, no levers. The unit is accountable for all AI risk, but the things that actually manage it - the data, the models, the deployment decisions, the vendor contracts, the security testing etc. - live in the functions it does not have control over. Responsible for everything, able to change nothing.
Second, gaps. You cannot cleanly cut AI out of the risks it lives inside. Every intersection between the new unit and the old ones becomes a gap where each side assumes the other should do it. That is where things fall through.
And the compromise - standalone treatment just for specific use cases - is worse. It is like standing up a brand new risk unit every time you launch a new product. One for the new savings account. Another for the new app. Another for the latest structured product. And every separate unit reinvents the wheel - for innovation, transformation or risk. Totally unscalable.
This is the spirit of a primer I wrote recently - A Primer on AI Risk Management from First Principles. AI risk management is a system whose parts hold each other up, and the controls only work when they interlock with what you already run. Build a silo for AI and you are in the worst of all worlds.
It is deliberately boring. Tell me where I am wrong.
Excerpts below, the primer can be found here, free for now. The fuller course comes later this year.
#AIRiskManagement #AIGovernance #AIRG





