Enterprise risk management as a discipline was largely codified in the late 1990s and 2000s. The frameworks that most organisations use today, whether derivatives of COSO ERM, ISO 31000, or internally developed equivalents, were built around a world of identifiable, categorisable, and to a significant degree, historical risks. The risks they manage well are those that have happened before.

Artificial intelligence, as an operational technology deployed at enterprise scale, introduces risk categories that most existing frameworks were not designed to assess. These are not hypothetical future risks. They are materialising in organisations that have deployed AI in consequential processes today. Boards and Chief Risk Officers that have not updated their frameworks to include them are operating with incomplete risk visibility.

The seven AI-era risk dimensions

1. Model risk at scale

Financial services organisations have managed model risk for decades. What is new is the scale, the speed, and the opacity. AI models deployed in customer-facing processes, operational workflows, and strategic decision support are making consequential determinations at a speed and volume that makes traditional model validation approaches inadequate. The error rates that would be acceptable in a human-mediated process become significant risk exposures when multiplied across millions of model-assisted decisions.

2. Algorithmic bias as a regulatory risk

Regulatory frameworks in India, the EU, and increasingly across Asia Pacific are beginning to address algorithmic bias as a compliance issue. Organisations that deploy AI in credit decisions, hiring, pricing, or customer service without adequate bias assessment and monitoring are accumulating a regulatory risk that is not yet fully visible but is growing rapidly. The DPDP Act’s provisions on automated decision-making are the leading edge of a broader regulatory trend.

3. Third-party AI dependency risk

Most enterprise AI deployments rely on foundational models and infrastructure provided by a small number of hyperscale technology providers. The concentration of AI capability in a handful of providers creates a third-party dependency risk that most organisations have not adequately assessed. The failure, policy change, or pricing change of a key AI provider could disrupt AI-dependent processes with limited warning.

4. AI-enhanced cyber threats

AI is as available to attackers as to defenders. The sophistication of AI-enhanced phishing, social engineering, and vulnerability exploitation has increased dramatically in the past 24 months. Organisations whose cybersecurity posture was calibrated against pre-AI threat levels are likely to be underprotected. The threat surface has expanded faster than most enterprise security programmes have adapted.

5. Intellectual property and training data exposure

The use of enterprise data to fine-tune or otherwise inform AI models creates intellectual property and confidentiality risks that most organisations have not fully assessed. Where employees are using third-party generative AI tools in their work, there is a real risk of sensitive information being incorporated into training data that is accessible to others. Data governance policies have not kept pace with the rate at which employees are adopting AI tools in their daily work.

6. Accountability diffusion

When an AI system makes a consequential error, the question of who is accountable is frequently unclear. The organisation that deployed the system, the provider that built the model, the team that configured the system, or the individual who acted on its output? This diffusion of accountability is not merely a legal and ethical issue. It is an operational risk issue. In the absence of clear accountability, the incentives to maintain adequate oversight of AI systems are weakened.

7. Reputational risk from AI failures

AI failures have a reputational dimension that differs from conventional operational failures. When an AI system produces a biased, incorrect, or harmful output, the reputational impact can be disproportionate to the direct harm caused, because it raises questions about the organisation’s judgment, values, and oversight capability. Managing this reputational dimension requires a proactive communications and governance approach that most organisations have not yet developed.

The organisations that will manage AI era risk most effectively are those that update their frameworks proactively, not reactively. By the time an AI risk materialises into a significant incident, the cost of inadequate preparation is already sunk.

About the Author

Daipayan Das

Founder and CEO of Strategy TheFuture and Cechoes Technology. 26 years of Big 4 consulting across PwC, KPMG, and Protiviti. IIM Calcutta. B.E. Electronics and Communications, Nagpur University.

Full profile