Ask

Questions you can actually ask.

Say who you are and what is in front of you. You will get questions to take to a visit, a huddle, a pitch, or a kitchen table.

Who is asking?

What is in front of you?

You do not need a framework to have a stake. You need a way in that does not drown you.

For I want to understand this

I already use these tools

Opening

What am I trusting this with, and what would I need to know to keep using it with open eyes?

Take these

  1. 01

    What does this tool keep of me, and who else can see it?

  2. 02

    When it is fluent, how do I tell that from true?

  3. 03

    What would I refuse to let it decide, even if it is faster?

  4. 04

    If it were wrong in a way that mattered, who would I tell?

If you want the specialist shelf

Same questions, denser rooms. Go when you are ready — not as a test of seriousness.

Database of named risks

AI Risk Repository

MIT AI Risk Initiative

More than 1,700 risks drawn from dozens of existing frameworks. Two maps sit on top: a domain taxonomy (what kind of harm) and a causal taxonomy (who, on purpose, and when).

You are writing a policy, a board paper, or a curriculum and need the source taxonomy.

How to manage, not only name

NIST AI Risk Management Framework

U.S. National Institute of Standards and Technology

A voluntary framework for putting AI risk into an organisation's ordinary risk practice. Widely referenced; not a law.

You are past 'what can go wrong' and need a cycle: govern, map, measure, manage.