====== AI Risk Assessment ====== **Knowledge Bundle:** Public-Sector AI Readiness **Concept ID:** government:ai_risk_assessment **Concept Type:** Risk Management **Status:** Draft **Audience:** Public agencies, IT teams, legal counsel, privacy officers, program managers **Steward:** OKF Expert **AI Use:** Human-reviewed **Last Reviewed:** June 2026 ===== Definition ===== An AI risk assessment is a structured review used to identify possible harms, failures, legal concerns, operational issues, and public-trust impacts before an agency adopts or expands an AI tool. Its purpose is not to stop innovation. Its purpose is to help an agency understand where human judgment, safeguards, testing, documentation, and oversight are necessary. ===== Common Risk Areas ===== * Inaccurate or misleading outputs * Biased or inequitable outcomes * Exposure of confidential or sensitive data * Lack of transparency about how AI is being used * Overreliance on AI-generated recommendations * Public-records and retention concerns * Cybersecurity vulnerabilities * Vendor lock-in * Unclear ownership or accountability * Reputational damage or loss of public trust ===== Suggested Risk Assessment Questions ===== * What decision, service, or workflow will this AI tool support? * Who could be affected by an inaccurate answer or recommendation? * Could the tool create unfair, discriminatory, or inconsistent results? * What data will be entered into the system? * Is any confidential, personal, financial, health, legal, or protected information involved? * Will a human review outputs before they affect a resident, employee, vendor, or policy decision? * Can the agency explain how the tool is being used? * What records must be retained? * What happens if the AI tool fails or produces harmful output? * Who is responsible for monitoring the tool after deployment? ===== Basic Risk Levels ===== ^ Risk Level ^ Description ^ Suggested Review ^ | Low | Limited internal support use with no sensitive data and no effect on public decisions | Department review | | Moderate | Public-facing or operational use with meaningful impact on staff workflows or service delivery | Department, IT, privacy, and legal review | | High | Use affecting eligibility, enforcement, safety, benefits, employment, legal rights, or vulnerable populations | Executive, legal, privacy, security, and formal governance review | ===== Recommended Output ===== Every AI risk assessment should result in a short written record that identifies: * The proposed use case * The responsible owner * The data involved * The identified risks * Required safeguards * Approval status * Review date * Conditions for continued use ===== Related Concepts ===== * [[government:ai_governance|AI Governance]] * [[government:approved_ai_use_cases|Approved AI Use Cases]] * [[government:ai_procurement|AI Procurement]] * [[government:public_records|Public Records and AI]] * [[government:ai_readiness|Return to Public-Sector AI Readiness]]