The AI Risk Register — front cover
The AI Risk Register — back cover

No. 55 · Manuscript complete · AI & agents · RISK

The AI Risk Register

Build a Living Register That Names, Owns, and Tests Every AI Risk Before It Names You

The AI Risk Register: Build a Living Register That Names, Owns, and Tests Every AI Risk Before It Names You.

RISK gives teams a living register for AI failure modes: named risks, accountable owners, tests, mitigations, escalation paths, and review cadence. Build a Living Register That Names, Owns, and Tests Every AI Risk Before It Names You. The framework: RISK.

pages
224
chapters
14
hours of reading
± 3
editions
EN · NL

The editions

Kindle and Paperback

Production shots of the editions. Not for sale yet — this page is the public working version.

  • The AI Risk Register, kindle

    Kindle

    The digital edition, ready in any Kindle app.

  • The AI Risk Register, paperback

    Paperback

    The working copy. Mark it up. Take it into the meeting.

The book

Build a Living Register That Names, Owns, and Tests Every AI Risk Before It Names You

The board meeting ends on time. Seventeen items, all green or yellow, and everyone walks out relieved to have "done the risk thing." Two weeks later a model update in the customer-success agent starts misclassifying tickets, the errors feed three other agents, and churn is climbing before anyone notices. None of the seventeen items mentioned it. The post-mortem ends the way every serious AI failure does: "This risk was not on the register."

The reflex is to add more items and schedule another review. That scales the document, not the protection. A longer list is a snapshot of what you already knew to name, not a map of what breaks you.

The AI Risk Register introduces the RISK framework: Register what matters, Inspect with evidence, Scenario-plan the unlikely, Kill-switch before deployment. Four moves turn a static compliance artifact into a living decision system that changes what your team ships. RISK is an operating heuristic, not a validated instrument: a lens you test against your register.

What you learn

What this book puts in your hands

  • Register what matters: give every material risk one owner, a first evidence date, and an update trigger.
  • Inspect with evidence, replacing "we talked about it" with a measured condition and a last-inspected date.
  • Scenario-plan the unlikely with cards that trace the second-order path and name the tail condition before it cascades.
  • Build tested kill-switches before deployment, so you stop a system on purpose.
  • Wire the register into how the team sets risk appetite, escalates, and reports.
The AI Risk Register, printed page: Practice: risk surface audit 11
Practice: risk surface audit 11

From the book

Practice: risk surface audit 11

The AI Risk Register, printed page: Practice: risk surface audit 11

Inspect more pages

The contents

Chapter by chapter

14 chapters

Every chapter of The AI Risk Register with its printed epigraph, what you can do afterwards, and the moment it is built for.

  1. Introduction

    The Invisible Risk Surface

    Risk registers document what the team already knows how to name. Material exposure can remain in the paths no one wrote down.

    What you can do afterwards

    You will see why your current risk list is a snapshot of yesterday's knowns. You will learn the four quadrants of the actual risk surface and run a field test that shows exactly where your register has no language.

    Use this chapter when

    You have a slide deck or spreadsheet labeled "risk register" that the board nods at, yet near-misses and surprises keep arriving from directions the list never mentioned.

  2. Chapter 1

    Register What Matters

    A risk is registered only when it is named, owned, and updated with evidence. Unregistered risks remain real; the problem is that no operating control can find them.

    What you can do afterwards

    You will leave with a prioritised starter register in which every material risk has a specific name and one accountable human owner. Every row carries a status, an evidence date, and a living update trigger.

    Use this chapter when

    You have inherited or created a risk list in which many items are known to the team yet never assigned, never inspected, and never acted upon.

  3. Chapter 2

    Inspect with Evidence

    Demos, vendor claims, and "it passed internal testing" do not establish that a named risk is managed. Inspection requires evidence at the granularity of the decision.

    What you can do afterwards

    You will replace trust with inspection. You will leave with four inspection designs matched to the four evidence classes, an independence rule, a cadence tied to change velocity, and a fifteen-minute falsification protocol.

    Use this chapter when

    A model or agent "seems fine" in demo or internal test, yet you have no protocol for what evidence would support a bounded production claim.

  4. Chapter 3

    Scenario Planning for the Unlikely

    "That will never happen" can end inquiry precisely where consequence demands it. Scenario planning gives an unlikely but material path a trigger and a pre-committed response.

    What you can do afterwards

    You will run a ninety-minute session that produces scenario cards for your highest-impact tails. You will write signposts that pass the observable-cheap-leading test, and rehearse one card before reality runs it for you.

    Use this chapter when

    The register contains only first-order items and the team still says "that tail will never matter to us."

  5. Chapter 4

    Kill-Switches Before Deployment

    A material-risk system needs a tested path to a defined safe state before deployment. The path, authority, and maximum response time depend on the harm it is meant to contain.

    What you can do afterwards

    You will design a kill-switch around four principles and audit everything it is entangled with. Then you build the containment ladder and verify the control path with a timed test.

    Use this chapter when

    You are shipping agents or models into production where a bad output at scale would be expensive, irreversible, or reputationally damaging.

  6. Chapter 5

    The Living Register

    A static quarterly document records a point in time. A living register carries triggers, owners, evidence, and version history into the decisions between reviews.

    What you can do afterwards

    You will leave with a register design that runs on triggers, pruning rules, and an operating calendar measured in minutes. You will also start the one metric that proves the register is alive: the decision that changed.

    Use this chapter when

    Your risk register is updated the week before the board meeting and then sits untouched until the next quarter.

  7. Chapter 6

    Ownership and Escalation

    Diffuse ownership is how risk registers become theater; every risk must have a single named human owner with a clear escalation path or it is not a managed risk.

    What you can do afterwards

    You will assign a single accountable owner and derive an escalation clock for every top risk. The chapter uses 24/48/72 hours as one worked clock for slow-moving operational drift, then shows when a much shorter safety, legal, or customer-harm clock overrides it.

    Use this chapter when

    Risks have "the team" or "engineering" as owner and no one can say whose calendar actually changes when the risk moves.

  8. Chapter 7

    Second-Order and Tail Risks

    A first-order row can miss consequential paths through customers, systems, suppliers, and institutions. Mapping those paths widens the register without pretending to measure their prevalence.

    What you can do afterwards

    You will build a second-order map for three material first-order risks using a repeatable tracing protocol. You will learn where to pause, when to continue, and how to promote one consequential, actionable link into the register.

    Use this chapter when

    Your register contains only the risks that are easy to name and the team still believes the expensive surprises will be first-order.

  9. Chapter 8

    Risk Appetite and Trade-offs

    Risk appetite governs only the exposure an organization is permitted to choose. Law, safety, rights, contracts, and professional duties set non-waivable floors; explicit trade-offs operate above them.

    What you can do afterwards

    You will write a one-page appetite statement with testable boundaries per risk category, build a trade-off table with three worked rows, and pressure-test both against your last three deployment decisions.

    Use this chapter when

    The board says "zero tolerance for compliance risk" while the team is paralyzed, or a competitor ships the segment you could have taken.

  10. Chapter 9

    Integrating Risk into Decision Making

    A risk register that does not change go/no-go decisions, feature prioritization, or deployment timing is not a register; it is a compliance artifact.

    What you can do afterwards

    You will wire the register into the four rooms where decisions actually happen, using four copyable artifacts that each cost minutes, and start a decision log that records whether the register changed an outcome.

    Use this chapter when

    Risk review happens the week before launch and the launch still happens because "we're already late."

  11. Chapter 10

    Regulatory and External Risk

    Treating regulatory requirements as a separate compliance track is how companies get surprised by rules that were visible for years; the register must include the external map or it is incomplete by design.

    What you can do afterwards

    You will add regulatory rows to the register as first-class entries with classification, triggers, owners, and obligation dates. A thirty-minute monthly monitoring loop will surface rule changes before they arrive as surprises.

    Use this chapter when

    The team treats the EU AI Act or sector rules as "legal will handle it" while the register has no regulatory row.

  12. Chapter 11

    Risk Communication

    A register that is buried in slides or written in compliance language is not a register; how it is communicated determines whether anyone will use it when it matters.

    What you can do afterwards

    You will build a versioned communication protocol for five audience views, create one engineer brief, and test whether a cold reader can retrieve its signal, action, and owner under a worked ninety-second constraint.

    Use this chapter when

    The risk register is structurally sound but the engineer who needed its trigger and response had never seen the relevant page.

  13. Chapter 12

    Building Your Risk Protocol

    "We have a document" is the starting point, not the achievement; a living risk protocol that the leadership team runs as an operating system is what turns dread into proportionate, calm capability.

    What you can do afterwards

    You will assemble twelve chapter artifacts into one protocol page, derive the operating cadence from your risks and capacity, and leave with a thirty-day installation sequence, completion evidence, and explicit stop conditions.

    Use this chapter when

    The team has a beautiful risk register but still made three major deployment decisions last quarter without consulting it.

  14. Conclusion

    Calm Capability

    A living register does not eliminate uncertainty or harm. It gives operators a prepared way to recognize a material condition, inspect the evidence, contain what they can, and escalate what they cannot accept.

    What you can do afterwards

    You will see every chapter contribute to one composite eleven-minute decision, then create a dated commitment to register, inspect, scenario-test, and contain one real risk under your control.

    Use this chapter when

    The team has installed the protocol and needs to test whether the parts meet in one decision rather than living as separate artifacts.

Who it is for

Who this book was written for

The result is a one-page living register with named owners, tested kill-switches, and scenario cards that trace what a static list never sees. It turns vague dread about AI into proportionate capability.

If you run material AI in production and refuse to meet your exposure in the post-mortem, start with the register you have and the effect it never named.

The reader it was written for

Risk leads, COOs, heads of product or engineering, founders, and board risk or audit members at organizations with material AI deployments. They have seen the gap between a risk list and a risk system that changes decisions. They are systems-oriented, skeptical of risk theater, and willing to maintain a small set of useful artifacts.

Probably not for you if

  • Specialists seeking a technical model-risk textbook.
  • Organizations with no material AI exposure.
  • Readers seeking a one-time compliance checklist or a substitute for legal,

Editions

Editions and specifications

Edition Formats Chapters Pages Reading time ISBN (paperback)
English The AI Risk Register In production 14 224 ± 3 hours —
Dutch Het AI-risicoregister In production 14 100 ± 3 hours —

Both editions are written natively. The Dutch text is not a machine translation of the English. · Trim size: 6x9″

Frequently asked

What readers usually want to know

What is The AI Risk Register about?

RISK gives teams a living register for AI failure modes: named risks, accountable owners, tests, mitigations, escalation paths, and review cadence. The subtitle is: Build a Living Register That Names, Owns, and Tests Every AI Risk Before It Names You.

Is there a Dutch edition?

Yes. The Dutch edition is Het AI-risicoregister, written as a native edition rather than a machine translation. It moves through the same production line.

How long is The AI Risk Register?

This edition runs 14 chapters, 224 pages in print and roughly 3 hours of reading.

Who is The AI Risk Register for?

If you run material AI in production and refuse to meet your exposure in the post-mortem, start with the register you have and the effect it never named.

The production system

How this book was made

Every title moves through the same gated production line: sourced research, a claim-level evidence ledger, structural review, fact-checking, red-team critique, and a bilingual final edit. AI agents do specialist work inside those gates; judgment, voice, and accountability stay human.

  • Claims enter an evidence ledger with a source and a confidence grade before they reach the page
  • English and Dutch are two native editions, not a translation of one another
  • Every chapter clears readability, rhythm, and style gates before it is typeset
Read the system in The Agentic Author
Markdown for LLMs