Table of Contents

AI Risk Assessment

Knowledge Bundle: Public-Sector AI Readiness Concept ID: government:ai_risk_assessment Concept Type: Risk Management Status: Draft Audience: Public agencies, IT teams, legal counsel, privacy officers, program managers Steward: OKF Expert AI Use: Human-reviewed Last Reviewed: June 2026

Definition

An AI risk assessment is a structured review used to identify possible harms, failures, legal concerns, operational issues, and public-trust impacts before an agency adopts or expands an AI tool.

Its purpose is not to stop innovation. Its purpose is to help an agency understand where human judgment, safeguards, testing, documentation, and oversight are necessary.

Common Risk Areas

Suggested Risk Assessment Questions

Basic Risk Levels

Risk Level Description Suggested Review
Low Limited internal support use with no sensitive data and no effect on public decisions Department review
Moderate Public-facing or operational use with meaningful impact on staff workflows or service delivery Department, IT, privacy, and legal review
High Use affecting eligibility, enforcement, safety, benefits, employment, legal rights, or vulnerable populations Executive, legal, privacy, security, and formal governance review

Every AI risk assessment should result in a short written record that identifies: