Use cases / Risk, legal and compliance
AI Risk
Know which AI is running, at what risk, under which controls.
01
Problem
AI systems appear faster than the risk register. Risk reviews are point-in-time and disconnected from what agents actually do.
02
AI capability
Classify systems, link risk level to required controls, watch runtime signals and escalate breaches of risk boundaries.
03
Data
The agent works from the context you connect, not from the open internet by default.
- AI system inventory
- Trust Profiles
- Runtime policy events
- Incident records
04
Agent
Risk Agent
Tracks risk posture across the AI estate and escalates boundary breaches.
05
Workflow
- 1. Register system
- 2. Assign risk level
- 3. Apply required controls
- 4. Monitor events
- 5. Escalate breach
- 6. Review and re-rate
06
Governance
Governance runs inside the agent at runtime: policy changes what it can actually do.
Can
- Read inventory and policy events
- Propose risk ratings
- Open risk escalations
- Report on posture
Cannot
- Lower a risk rating without an owner
- Disable a control
- Suspend systems unattended
- Edit incident history
Requires approval
- Changing a risk level
- Pausing a production agent
- Accepting a residual risk
Records
Agent identity, Data accessed, Model used, Output, Tools called, Policy applied, Decision, Approval, Action, Outcome.
Suggested starting autonomy: L1 Assist
Start at L1: it recommends ratings and escalations; accountable risk decisions stay with owners.
07
Outcome
What you measure, so the agent earns more autonomy on evidence:
- Share of AI systems with a current risk level
- Time from breach to escalation
- Controls matched to risk level
- Overdue risk reviews
Questions
How is risk linked to autonomy?
Higher risk levels cap the autonomy level an agent may hold and raise the approval and audit requirements.
Where does the risk level live?
In the system Trust Profile, next to its approved models, data classification and policy set.