OPERATIONALISING AI RISK BEFORE REGULATION FORCES ACTION

For the better part of three years, the use of artificial intelligence (AI) in an enterprise was treated as an innovation story. It lived in pilots, in the productivity wins of early adopters and in the language of the earnings call. Risk was a footnote, something for the legal team to worry about once the technology matured. However, that framing no longer holds. AI has moved out of the lab and into production systems where it makes decisions about credit, hiring, claims and security. The risk has followed it there. The question facing the chief risk officer, the general counsel and the head of compliance is no longer whether to use AI. It is whether they can show that the AI they have deployed is under control.

This is no longer theoretical. The EU Artificial Intelligence Act began applying its first obligations in 2024 and layers duties onto providers and deployers by risk tier. In the UK, the Financial Conduct Authority and the Bank of England have published joint work setting out where AI concentrates risk in financial services and what good governance looks like. The throughline across jurisdictions is consistent: accountability for an automated decision stays with the organisation that deployed it, not the vendor and not the model. A board that treats AI as a procurement category is treating a material risk as a line item.

Why AI risk behaves differently

Most risk disciplines assume a system with knowable logic. A credit policy can be read. A control can be tested. An outlier can be traced to a rule. Machine learning breaks that contract. The behaviour of a model is emergent, not written down.

Oct-Dec 2026 Issue

Great Gu