Craig Stanley
Home / Risk / Start here

Most AI risk registers list the model, not the decision

Why AI risk registers full of generic model risks don't help, and how to rebuild them around the decisions models feed.

10 October 2026 · 2 min read · Craig Stanley
In short, explained

Instead of worrying about what the computer helper might get wrong in general, look at each job it does and ask what would happen if it got that job wrong.

Most AI risk lists say things like "the model might make things up." That's true but doesn't tell you what to do. It's more useful to list each decision the AI helps with and ask what happens if it's wrong there.

Generic model risks (hallucination, bias, leakage) don't prioritise action. Rebuild the register with one row per decision the model influences: impact if wrong, reversibility, reliance, detection time, owner, control and nudge. Model-level risks become inputs to each row.

The usual register

Open most AI risk registers and you'll find the same rows: hallucination, bias, data leakage, prompt injection, over-reliance. Each has a rating and a mitigation like "user training" or "human in the loop".

None of these are wrong. The trouble is that they're the same for every organisation and every use, so they don't help anyone decide what to do first.

Start from the decision

The same model can be low-risk in one place and high-risk in another. Summarising a meeting and approving a refund carry very different stakes, even if the model behind them is identical.

So rebuild the register around decisions. One row per decision that a model influences, with these columns:

ColumnQuestion
DecisionWhat choice does the model affect?
Impact if wrongWhat does a wrong answer cost, and who bears it?
Reversible?Can it be undone, and how quickly?
RelianceDoes anyone check the output before acting?
Time to detectHow long before a problem would be noticed?
OwnerWho is accountable?
ControlWhat stops or catches a bad answer?
NudgeWhat alert reaches the owner when something moves?

Where model risks go

Hallucination, bias and leakage don't disappear. They become inputs to each row. For a refund decision, ask what a hallucinated policy reference would cost there. That's a question someone can answer.

A quick test

Pick any row in your current register and ask: who would do something different on Monday because of this? If the answer is nobody, rewrite it around a decision.

Read next

A question to take awayWho gets told, and how fast, when a decision model starts drifting?

About me

Craig Stanley

Microsoft AI consultant and technical architect, based in Whitley Bay. Over the last few years I've delivered Microsoft 365 Copilot, Copilot Studio agents, Azure AI Foundry work and governance for UK public sector and financial services organisations.

What interests me is the decision underneath the tool: what it costs, what it risks, and whether a small, transparent model can make it better. I write the methods up here and on Substack so anyone can use them.

Find me