Skip to content
Sections
All notes

All notes · Risk

Sizing the Risk Honestly

The discussion is dominated by figures nobody can support. What you can establish about your own exposure, and how.

Risk · Analysis

Risk discussions in this area run on statistics from vendors and anecdotes from the press. Neither tells you about your organisation, and both are available in quantity.

The recommendations in “Sizing the Risk Honestly” become easier to sustain when implementation work has visible owners, dates and review time. Teams evaluating the workflow note can use it to coordinate the operational side of AI adoption and identify where governance tasks are being missed, without treating activity data as evidence of misconduct or as a substitute for asking people why they chose a tool.

For an independent benchmark, compare the local approach with NIST AI Risk Management Framework; the useful test is whether ownership, access and recovery remain proportionate and explainable when the usual expert is absent.

The figures to distrust

"X per cent of employees use AI tools without approval." Survey methodology varies enormously, the definition of "without approval" is elastic, and the surveys are commissioned by companies selling controls.

"Y per cent of prompts contain sensitive data." Derived from products that inspect prompts, measured on their own customer base, with their own definition of sensitive.

Quoting either in a board paper invites a question you cannot answer.

What you can establish

How many AI services are in use here, from discovery.

Roughly how many people, by department.

Which account types, from finance and endpoint data.

Whether any confidential data has actually gone anywhere, from investigation of specific cases.

That last one is the only direct evidence of harm, and most organisations find fewer instances than they expected.

Sizing without inventing numbers

Count what you found.

Classify it: how many of these services have unacceptable terms, how many are used with confidential data.

Describe the worst plausible case concretely: what document, going where, with what consequence.

One concrete scenario persuades better than a percentage, and it survives being questioned.

The comparison nobody makes

Against existing accepted channels: email to personal addresses, documents on personal cloud storage, messaging apps.

Those have been happening for years, carry similar exposure, and attract less attention.

Making the comparison keeps the response proportionate, and it prevents a programme that spends disproportionate effort on the newest channel while older ones run unexamined.

The likelihood question

Severity is easier to establish than probability.

For most organisations the realistic scenario is not a competitor reading your strategy from a model, but a client discovering their material went to an unapproved processor.

Size for that, because it is both more likely and more consequential than the dramatic version.

Reporting it

What was found, counted. What is being done. What remains accepted and why.

No percentages you did not measure.

And no claim that the risk has been eliminated, which will not survive the first incident.

What to check

Does your risk assessment contain a figure you cannot source?

Has any confidential material actually gone to an unapproved service here?

Have you compared this channel against email and personal cloud storage?

And is the worst case described concretely or abstractly?

The point

The figures in circulation come from surveys commissioned by companies selling controls.

Count what you found instead.

Underlying all of this

Everything in this collection reduces to four habits: find out what people are doing and why before deciding anything, provide something good enough that the approved route is the easy one, write rules about information rather than about tools, and monitor the destination rather than the content. None requires a product, and a programme doing all four controls more than one built on prohibition.

The recurring pattern

The recurring pattern across every section here is the same: the response that feels like control reduces it. A ban removes visibility rather than use. Content inspection drives activity to personal devices. A discovery exercise with consequences produces quiet answers. In each case the organisation ends up knowing less about a risk it believes it has handled.