AI Risk Guide: Understanding Four Domains Organizations Must Govern
Summary
This article presents four AI risk domains that organizations should assess together: technical; societal and ethical; operational and organizational; and adversarial and security. Technical risks include hallucination, model drift, robustness failures, and unexplainability. The author argues that unexplainability deserves particular attention because high accuracy alone may not be defensible in regulated or high-stakes decisions. Societal and ethical risks include harmful bias, privacy violations, manipulation, and autonomy erosion, which can occur gradually as recommendation systems narrow the choices people see. Operational and organizational risks include third-party dependencies, unclear accountability, and over-reliance, especially when AI decisions span multiple teams or human judgment weakens through repeated automation. The article identifies prompt injection, data poisoning, exfiltration, and AI-enabled attacks as adversarial and security risks, and states that adversarial exploitation of AI grew eightfold from 2022 to 2025. It links the expanding attack surface to agentic systems that can access tools and take real-world actions, highlighting DevOps and SRE agents that can modify infrastructure, restart services, or roll back deployments. The author recommends using all four domains as a system-by-system audit checklist rather than assuming strength in one area covers the others.