Knowledge Bundle: Public-Sector AI Readiness Concept ID: government:ai_risk_assessment Concept Type: Risk Management Status: Draft Audience: Public agencies, IT teams, legal counsel, privacy officers, program managers Steward: OKF Expert AI Use: Human-reviewed Last Reviewed: June 2026
An AI risk assessment is a structured review used to identify possible harms, failures, legal concerns, operational issues, and public-trust impacts before an agency adopts or expands an AI tool.
Its purpose is not to stop innovation. Its purpose is to help an agency understand where human judgment, safeguards, testing, documentation, and oversight are necessary.
| Risk Level | Description | Suggested Review |
|---|---|---|
| Low | Limited internal support use with no sensitive data and no effect on public decisions | Department review |
| Moderate | Public-facing or operational use with meaningful impact on staff workflows or service delivery | Department, IT, privacy, and legal review |
| High | Use affecting eligibility, enforcement, safety, benefits, employment, legal rights, or vulnerable populations | Executive, legal, privacy, security, and formal governance review |
Every AI risk assessment should result in a short written record that identifies: