Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

AI risk is not determined by a model alone. It emerges from the way a system is designed, the setting in which it is used, and the people and institutions that choose, operate, oversee, and respond to it. Managing that risk therefore requires technical work and clear human accountability throughout the system’s life.

Why is AI risk a human problem?

An AI system’s effects depend on more than its code or measured performance. NIST’s AI Risk Management Framework 1.0 (2023) describes AI systems as socio-technical: “AI systems are inherently socio-technical in nature, meaning they are influenced by societal dynamics and human behavior.” The people who select a system, configure it, act on its output, and decide how it will be monitored all shape its consequences.

Context matters. A tool used to support a decision may have different consequences from one whose output is treated as decisive. Risks can also change when the system interacts with other AI systems, when the people operating it have different capabilities or incentives, or when it is used in a social setting unlike the one anticipated during development. A technically sound result in one context does not, by itself, establish that use is appropriate in another.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

This does not mean the technology is irrelevant or that human involvement automatically makes an AI system safe. Technical properties and human decisions interact. Understanding risk requires examining both what the system can do and the conditions under which people put it to work.

What kinds of harm can arise?

The OECD’s overview of AI risks identifies categories that include bias and discrimination, polarization of opinions, privacy infringements, and security and safety issues. These are examples of potential harms, not a ranking of how often they occur. The sources do not establish that every AI system causes harm or quantify the frequency of these outcomes.

Concerns can overlap. A system that processes personal information may raise privacy questions as well as security concerns. A decision process may produce unequal effects, while the way an organization relies on its output can affect people’s rights and well-being. Evaluating one technical measure in isolation cannot answer all of these questions.

The wider stakes include human values, fairness, human determination, privacy, safety, and accountability. These were among the questions raised in the OECD’s 2019 report on AI in society. They are practical governance concerns: organizations need to consider who may be affected, what decisions are being supported or made, and how people can understand or challenge consequential outcomes.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Who is responsible when an AI system causes harm?

Responsibility is not located only with the people who built a model. It can involve the organizations that select, configure, deploy, operate, and rely on the system, as well as those responsible for monitoring its effects and responding when something goes wrong. The OECD describes deployer accountability as part of responsible AI and says risks need to be managed throughout the value chain.

That broad responsibility needs to become specific inside an organization. Someone must have authority to determine whether a use is suitable, assign people to assess impacts, approve deployment, monitor outcomes, and act on reports of harm. If these duties are split across teams, the handoffs and decision rights need to be explicit; otherwise, a framework or policy may exist without anyone being empowered to act.

Accountability also depends on incentives and organizational culture. NIST explains that effective risk management calls for mechanisms that establish roles and responsibilities, and that senior-level commitment may be needed. It cautions that using the framework alone will not create the organizational changes or incentives required to manage risk effectively. A checklist cannot substitute for authority, resources, or a willingness to pause a system when evidence warrants it.

What can organizations do to manage AI risk?

Risk management should continue from early planning through development, deployment, use, and evaluation. The work is not finished when a system passes a pre-deployment test: context can change, new uses can emerge, and observed outcomes can reveal problems that were not apparent earlier.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Before choosing or designing a system

  • Define the intended use and the decisions it may influence. Identify the people and communities affected, the setting of use, and the consequences of incorrect or inappropriate output.
  • Assess whether AI is suitable for the task and what alternatives or safeguards are needed. Establish who can approve the use and who can reject or stop it.
  • Consider the system’s trustworthiness characteristics, including validity and reliability, safety, security and resilience, accountability and transparency, explainability and interpretability, privacy enhancement, and fairness with harmful bias managed. NIST presents these as characteristics to consider across the lifecycle, not as a certification or guarantee.

During development and deployment

  • Test the system in conditions relevant to its intended setting, and examine possible effects on affected groups as well as overall performance.
  • Make operational responsibilities clear: who configures the system, decides how its output is used, communicates limitations, and handles exceptions or complaints.
  • Set expectations for human review that match the decision and its consequences. A reviewer needs appropriate information, time, authority, and a workable way to disagree with or override an output; the label “human in the loop” alone proves none of these.

After deployment

  • Monitor how the system is actually used and whether its outcomes or surrounding conditions change. Include ways to receive reports from operators and affected people.
  • Define escalation and response procedures before they are needed, including who investigates concerns and who can modify, restrict, or suspend use.
  • Reassess risk when the system, its purpose, its users, or the deployment context changes. Record decisions and communicate material limitations to people who rely on the system.

These steps are not evidence that any particular intervention will prevent harm. Their value depends on an organization’s ability to carry them out, learn from use, and act on what monitoring and evaluation reveal.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What does the NIST AI Risk Management Framework do—and not do?

NIST published AI Risk Management Framework 1.0 on January 26, 2023. NIST describes it as voluntary, rights-preserving, non-sector-specific, and use-case agnostic. It can help organizations structure consideration of trustworthiness and risk, but it does not make decisions for them or guarantee a safe outcome. NIST’s current framework overview says a revised version is in progress; consult the NIST AI RMF page for the latest status.

The framework can support a process, but the organization must supply the people, authority, capabilities, and incentives that make the process meaningful. Its development involved more than 240 contributing organizations, according to NIST; that figure describes contributors to framework development, not organizations implementing it.

A useful way to judge any risk-management approach is to ask whether it covers the lifecycle, assigns clear accountability, identifies affected people and context, requires monitoring and response, and matches the organization’s capacity and incentives. These are practical questions for evaluating implementation, not a ranking of frameworks or organizations.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.