AI risk management is the systematic process of identifying, assessing, and controlling risks that arise from developing and deploying AI systems. It extends traditional enterprise risk management to AI-specific risk categories, bias, hallucination, drift, opacity, adversarial attack, and a regulatory landscape that now makes parts of it legally mandatory.
AI Risk Management, the discipline of identifying, assessing, treating, monitoring, and reporting risks specific to artificial intelligence systems within an organisation's broader enterprise risk framework.
AI risk management extends standard ISO 31000 risk methodology to AI-specific characteristics: model behaviour that shifts over time, training data quality, vendor concentration, agent autonomy, emergent capabilities, and conduct exposure. ISO/IEC 23894 is the AI-specific companion to ISO 31000. The NIST AI RMF and ISO/IEC 42001 both organise around risk-management functions.
Source: ISO/IEC 23894:2023; NIST AI RMF
AI systems introduce risk characteristics that conventional technology risk frameworks were not designed to handle. They can fail without producing an error message, producing plausible but wrong outputs that are difficult to detect without domain expertise. They can exhibit bias that was not designed in and may not be immediately apparent. They are not fully explainable in the way conventional software is. And they can behave differently in production than in testing, because real-world data distributions differ from training data. NIST anchors this in seven trustworthiness characteristics: valid and reliable; safe; secure and resilient; accountable and transparent; explainable and interpretable; privacy-enhanced; and fair with harmful bias managed.
Synthesised from the NIST AI RMF trustworthiness characteristics, the 12 generative-AI risks in NIST AI 600-1, ISO/IEC 23894, and the EU AI Act risk tiers (sources at the end of this page):
Bias and discrimination
NIST identifies three bias categories to manage, systemic, computational/statistical, and human-cognitive, which can perpetuate discrimination at scale even without prejudicial intent.
Inaccuracy and hallucination
NIST treats "valid and reliable" as the foundational trustworthiness characteristic; its Generative AI Profile names "confabulation", confidently stated but false output, as a defining GenAI risk.
Model drift
An evolving operating environment means a system no longer meets the assumptions of its original design, degrading performance over time. Monitoring for drift sits in the NIST Measure function.
Opacity and explainability
NIST separates "explainable and interpretable" (how the system works and what outputs mean) from "accountable and transparent" (whether information about the system is available). Opaque systems block trust assessment.
Security and adversarial attack
Evasion, data poisoning, privacy attacks and model exfiltration, taxonomised authoritatively in NIST AI 100-2e2025, plus misuse attacks specific to generative AI.
Privacy and data leakage
AI can enable inference attacks that re-identify individuals; the GenAI Profile lists data privacy leakage as a distinct risk category.
Third-party and supply chain
Non-transparent integration of third-party data, pre-trained models and components across the AI value chain ("value chain and component integration" in NIST AI 600-1).
IP and copyright
Outputs or training practices may infringe copyright, trademark or other IP rights, or expose trade secrets.
Over-reliance and automation bias
The "human-AI configuration" risk: automation bias, over-reliance on outputs, and inappropriate trust in the system.
Environmental impact
Energy and resource consumption of training and operating large models, recognised as a risk category in the GenAI Profile.
Physical safety
NIST's "safe" characteristic: AI should not, under defined conditions, endanger human life, health, property or the environment.
The frameworks are complementary, not competing: the voluntary frameworks (NIST, ISO, national guidance) are the practical route to meeting the obligations that binding law (the EU AI Act) makes mandatory.
| Framework | Origin | Structure | Status and scope |
|---|---|---|---|
| NIST AI RMF 1.0 | United States (NIST) | Four functions: Govern (cross-cutting), Map, Measure, Manage; seven trustworthiness characteristics. Generative AI Profile (NIST AI 600-1, Jul 2024) adds 12 GenAI risks. | Voluntary; rights-preserving, non-sector-specific, use-case agnostic (NIST AI 100-1, Jan 2023) |
| ISO/IEC 42001:2023 | International (ISO/IEC) | Certifiable AI management system standard (Plan-Do-Check-Act); Annex A of 38 controls in 9 areas selected via a Statement of Applicability | Voluntary; independently certifiable for third-party assurance (published Dec 2023) |
| ISO/IEC 23894:2023 | International (ISO/IEC) | AI risk management guidance applying ISO 31000 principles to AI, with an annex of AI-specific risk sources | Voluntary guidance; complements ISO/IEC 42001 (published Feb 2023) |
| Guidance for AI Adoption (informally "AI6") | Australia (National AI Centre, Dept of Industry, Science and Resources) | Six essential practices, published 21 Oct 2025, condensing the earlier Voluntary AI Safety Standard's 10 guardrails; two tiers (Foundations; Implementation Practices) | Voluntary; Australia's current flagship business-facing AI governance guidance. Proposed mandatory high-risk guardrails were not proceeded with; feedback fed the National AI Plan (2 Dec 2025) |
| EU AI Act (Reg. (EU) 2024/1689) | European Union | Binding risk-tiered regulation: prohibited, high-risk (conformity assessment, Art. 43), transparency (Art. 50), minimal risk | Mandatory in phases: prohibitions + AI literacy live since 2 Feb 2025; GPAI since 2 Aug 2025; Art. 50 transparency from 2 Aug 2026; standalone high-risk postponed to 2 Dec 2027 by the Digital Omnibus |
The EU AI Act (Regulation (EU) 2024/1689) is the first binding, comprehensive AI law, and it phases in: prohibited practices and the AI-literacy duty have applied since 2 February 2025; general-purpose AI model obligations since 2 August 2025; the Article 50 transparency duties (chatbot disclosure, labelling AI-generated content) apply from 2 August 2026. The high-risk regime, mandatory risk management, conformity assessment and registration for Annex III systems, was postponed by the Digital Omnibus on AI, published in the Official Journal on 24 July 2026 and in force from 27 July 2026, to 2 December 2027 for standalone systems and 2 August 2028 for AI embedded in regulated products. The Act reaches organisations outside the EU whose AI output is used inside it. Australia, by contrast, remains voluntary: the Government confirmed it will not proceed with proposed mandatory high-risk guardrails at this time, with feedback folded into the National AI Plan (December 2025).
What is AI risk management?
AI risk management is the ongoing process of identifying, measuring, and mitigating the harms an AI system can cause across its lifecycle, from bias and inaccuracy to security, privacy, and safety risks. NIST's AI Risk Management Framework structures this into four functions (Govern, Map, Measure, Manage) applied continuously rather than once.
What is an AI risk management framework?
A structured, repeatable method for governing AI risk. The main reference frameworks are the NIST AI RMF (voluntary, characteristic-based), ISO/IEC 23894:2023 (AI risk-management guidance aligned to ISO 31000), ISO/IEC 42001:2023 (a certifiable AI management system), and the EU AI Act (binding, risk-tiered regulation). They are complementary: voluntary frameworks help you meet obligations that regulation makes mandatory.
What are the main categories of AI risk?
The commonly recognised AI-specific risk categories are bias and discrimination; inaccuracy and hallucination; model drift; opacity and lack of explainability; security and adversarial attacks; privacy and data leakage; third-party and supply chain; intellectual property and copyright; over-reliance and automation bias; environmental impact; and physical safety. These map onto NIST's seven trustworthiness characteristics plus the 12 generative-AI risks in NIST AI 600-1.
What is the difference between NIST AI RMF, ISO 42001, and ISO 23894?
NIST AI RMF is a voluntary framework organised around trustworthiness characteristics and four functions. ISO/IEC 23894:2023 is guidance specifically for managing AI risk, an AI-tailored application of ISO 31000. ISO/IEC 42001:2023 is a certifiable AI management system standard (Plan-Do-Check-Act) that an organisation can be independently audited against for third-party assurance.
Is an AI risk management framework legally required?
The frameworks themselves (NIST AI RMF, ISO standards) are voluntary. However, binding law such as the EU AI Act (Regulation (EU) 2024/1689) makes risk management mandatory for high-risk AI, including a conformity assessment before market placement, and it reaches non-EU providers whose output is used in the EU. Under the Digital Omnibus adopted in June 2026, standalone high-risk obligations apply from 2 December 2027. Adopting a voluntary framework is the practical route to demonstrating compliance.
What extra risks does generative AI add?
NIST AI 600-1 (the Generative AI Profile) identifies 12 risks unique to or amplified by generative AI, including confabulation (hallucination), intellectual-property infringement, value-chain opacity, over-reliance (human-AI configuration), degraded information integrity, information security, and environmental impact from model training and inference.
What are the 4 types of AI risk?
There is no single official "4 types" taxonomy, sources group AI risk differently. A common simplified grouping is technical risk (bias, inaccuracy, drift), legal and regulatory risk (privacy, discrimination, non-compliance), operational risk (vendor dependency, security, business continuity), and reputational risk. NIST's own taxonomy is broader: seven trustworthiness characteristics plus, for generative AI, the 12 named risks in NIST AI 600-1.
What are the 4 levels of AI risk?
This usually refers to the EU AI Act's four-tier risk classification: unacceptable risk (prohibited outright), high-risk (Annex III, subject to conformity assessment), limited risk (transparency obligations only, e.g. chatbot disclosure), and minimal risk (the majority of AI systems, no mandatory requirements).
What are the 4 main AI risk management frameworks?
The four most-referenced frameworks are the NIST AI RMF (US, voluntary, characteristic-based), ISO/IEC 23894:2023 (international guidance applying ISO 31000 to AI), ISO/IEC 42001:2023 (international, certifiable AI management system), and the EU AI Act (binding regulation for organisations in scope). They are complementary rather than competing, most organisations use a voluntary framework operationally and map it to binding law where it applies.
This page is general information about AI risk management, not legal, regulatory, or professional advice, and does not capture every nuance, exception, or recent development. Requirements vary by jurisdiction, sector, and organisation, and change frequently. Always verify against primary sources and your own qualified legal counsel before relying on it.
Not sure where your organisation stands?
The free AIRiskAware Health Check maps your sector, size, and AI use to the specific obligations that apply, in minutes, in-browser, with nothing stored. 66% of respondents find obligations they had not previously mapped.