Deception that scales
Fraud that used to need skill now needs a subscription. Voice clones, convincing invoices, phishing without the tells people were trained to spot, and identity checks that assumed forgery was hard.
Not the ones in the headlines. The ones already on your register.
Most writing about the risks of artificial intelligence is about artificial intelligence. This hub is about your business: which of the risks you already carry AI is making worse, which it is quietly making possible, and how to tell the difference.
Two different questions get filed under this heading, and confusing them is why so many AI risk exercises stall.
The first is risk from the AI you have adopted: the tools your teams use, what they do with your data, whether their output can be trusted. That is a real and bounded question, and frameworks like the NIST AI Risk Management Framework exist to answer it.
The second is risk from AI in the world, whether or not you have adopted anything: your competitors moving faster, fraud against you becoming cheaper to run, your suppliers automating decisions that affect you, your customers arriving with new expectations. This is the larger of the two, it is the one most registers miss, and it is what this hub is about.
Put plainly: AI is not a new line on your risk register. It is changing the lines already there.
The shape of it
The instinct when AI arrives is to add a row: AI risk, rated medium, owner TBC. It is tidy and it teaches you nothing, because AI is not one risk. It is a force acting on the risks you already carry.
Take a supplier concentration risk you have held for years, scored amber, reviewed annually. Nothing about the supplier has changed. But the effort required to impersonate their finance team convincingly has collapsed, so the same risk now has a materially higher likelihood. The entry did not move. The world underneath it did.
That is why the useful exercise is not an inventory of AI tools. It is a re-reading of your existing register with one question applied to every line: has AI changed the likelihood, the impact, or the safeguard that was supposed to hold this?
Fraud that used to need skill now needs a subscription. Voice clones, convincing invoices, phishing without the tells people were trained to spot, and identity checks that assumed forgery was hard.
Confident, fluent, wrong. Systems that generate plausible answers create work that looks finished, reaches customers and regulators, and carries no signal that it was never checked.
Competitors repricing, responding and shipping on cycles your approval process was never designed to match. Not a failure of judgement, a mismatch of clock speed.
Your people pasting things into tools nobody approved, and your suppliers automating decisions that reach you. Most of this sits outside anything you have adopted.
Both directions
Risk work has a bias toward downside, and with AI that bias produces a register that is both frightening and useless. The same force making fraud cheaper is making things possible that were not possible eighteen months ago.
An objective you quietly dropped because it needed headcount you could not justify may now be reachable. That is not a separate conversation from risk. It is the same conversation: what has changed underneath the plan, in both directions.
A picture that scores only what has become more dangerous will get you funding for defence and nothing else. Score both, and you have something a leadership team can actually decide from.
Practical
Start from your business objectives rather than from a list of tools. For each objective, ask what could stop you achieving it, and then how much of that is now AI driving. That ordering matters: it keeps the exercise about your business rather than about technology, and it produces entries an owner can act on.
Two pages here take it further. How to run an AI risk assessment compares the three ways of doing the work and walks the five steps. The AI risk register gives you the structure the results live in, with worked entries.
Regulators are publishing their own guidance as this develops, including the UK NCSC and the Australian Cyber Security Centre. None of it requires you to wait before starting.
The ones that actually reach a board pack are deception that scales (fraud, voice cloning, convincing phishing), information nobody can verify, competitors moving faster than your process, and exposure through your own people and suppliers. Existential scenarios get the headlines; these get the losses.
Almost always an existing one, moving. AI rarely creates a category of risk you have never held. It changes the likelihood, the impact, or whether the safeguard you rely on still works. That is why adding a single AI row to a register teaches you very little.
Yes, and this is the part most registers miss. Fraud against you, your competitors' speed, your suppliers' automation and your customers' expectations all change regardless of what you have adopted. Adoption is one source of AI risk, not the only one.
The main one, held against your objectives. A standalone AI register tends to become a silo nobody owns and nobody reads, and it separates AI from the risks it is actually driving.
No. Frameworks are useful when a customer or regulator asks you to map to one, and they are worth knowing about. But starting is more valuable than mapping, and none of the work on this hub requires a framework to be useful.
More often than an annual cycle allows. The underlying capability changes on a scale of months, so a score set a year ago is describing a world that no longer exists. Quarterly is a reasonable floor for the risks AI is driving hardest.
The risks AI is driving against your objectives, scored for your business, with a safeguard drafted for each. Free.