AI risk management is the process by which a company identifies, assesses and reduces the risks associated with the use of artificial intelligence. It differs from ordinary information risk assessment in what is evaluated. Alongside availability, confidentiality and integrity, risks specific to AI are added: incorrect or fabricated output, bias against certain groups, the unexplainability of a decision, declining accuracy over time, dependence on the model provider, and the impact on the rights of the people the output concerns. For each risk, a measure, a responsible person, and a way of verifying effectiveness are determined. The risk register is reassessed with every new system, with every change of model, and at a regular interval, since the environment changes faster than with other technologies.
See also: AI management system, Fundamental rights impact assessment, AI system monitoring.