Writing

A selective reading list on AI risk for boards, essays on risk, uncertainty and AI, and guidance and reports I wrote for the OECD and the Institute of Risk Management. Each essay opens here, with the full article on Substack.

AI Risk Reading

Frontier AI, cyber resilience and the exit plan nobody has tested

A short, selective list of new papers on AI risk that boards should know about, with a judgement on each and a question for the board.

Foundations

What every director should know about AI, from Turing to the EU AI Act

Where AI Risk Reading covers what is new, Foundations covers what lasts: ten documents, where to start with each, and why it matters to a board.

Ruminations on Risk

An antique-style world map with dragons in the margins and the words Here Be Dragons in the corners
AI-assisted illustration by Richard Anderson using Midjourney and ChatGPT

Here Be Dragons: Risk Appetite When the Risks Cannot Be Known

There are many flavours of risk. Some we understand perfectly well. Leave the ice cream out of the freezer overnight and we know what we will find in the morning. We teach our children to look both ways when they cross the road, even on a one-way street (dangers of Lime bikes!) Banks employ specialists to manage the mismatch between assets and liabilities, because they know exactly what happens when they don’t.

But sometimes we simply do not know. The old cartographers had an honesty about how they dealt with this. Where their knowledge ran out, they wrote “Here Be Dragons”. Gradually knowledge pushed the dragons off the map, and we learnt that we could sail around the world without meeting one (unless we went to Komodo).

Read the full article on Substack
The same antique-style world map, now with strange alien creatures in the margins, the words Here Be Aliens in the corners, and part of the ocean dissolving into a network pattern
AI-assisted illustration by Richard Anderson using Midjourney and ChatGPT

Here Be Aliens: Risk Appetite in the Age of AI

In an earlier article, I borrowed the warning sometimes attributed to old cartographers: “Here Be Dragons.” John Adams calls risks of this kind virtual: matters where knowledge is lacking, or experts cannot agree. The dragons did not need to exist for the uncertainty beyond the map to influence how people sailed.

Perhaps the modern map should say: “Here Be Aliens.” There is a small joke hiding in the word, but also a serious question. We cannot know everything AI will make possible, or what an organisation might become as it builds AI into its decisions. Like the dragons, our aliens give shape to something we do not yet understand.

Read the full article on Substack

The Straight Line Fallacy

A painted arrow on a road pointing towards a distant city, with a deep crack running across the road ahead
AI-assisted illustration by Richard Anderson using Midjourney

When Innovation Causes the Default

Bubble or bust is the AI question of the month. There is a comforting answer to it. Even if it overshoots, something valuable will be left behind, the way the railways survived the mania and the internet survived the crash. That answer assumes tomorrow’s AI will be a larger version of today’s, financed on a path that simply continues. I think the more dangerous assumption is the straight line itself. The assets securing much of today’s AI debt are GPUs and data centres financed on the premise that today’s giant models will still be the dominant architecture when the debt matures. If a cheaper, smaller, more specialised architecture wins instead, the technology succeeds and the collateral fails at the same moment. That is not a demand problem. It is a straight line drawn through a bend.

Read the full article on Substack

Monolithic Intelligence versus Governed Intelligence

The industry measures progress along a single line: bigger model, more knowledge, another benchmark passed, another straight extension of the same ladder. Every serious institution I have worked in knows that intelligence does not actually work that way. We do not hand one individual origination, risk judgement and final sign-off and call it efficient. We call it a control failure waiting to happen. Yet the dominant model of artificial intelligence asks one system to propose, reason, calculate and certify its own answer, and calls the final pass self-critique. I think the more interesting question is not how much a model knows. It is whether the architecture around it resembles a governed institution or an unaccountable one.

Read the full article on Substack

Guidance and reports

Reports and guidance I wrote or co-wrote for the OECD and the Institute of Risk Management. The IRM guidance is free to download, with a short executive summary for board members and a full document for practitioners.

Risk Management & Corporate Governance

Written for the OECD’s work on corporate governance and the financial crisis, covering banks in the UK, the United States and France. It argued that boards had become dependent on management for assurance, that part-time non-executive oversight was stretched, and that risk management had to reach beyond the organisation into its extended enterprise. The same pressures return today, as boards come to rely on AI they did not build and cannot easily inspect.

No longer on the OECD website. The OECD cites it in its 2014 review, Risk Management and Corporate Governance.

Extended Enterprise: Managing Risk in Complex 21st Century Organisations

On risk that sits outside an organisation’s direct control: in suppliers, outsourcing and networks of partners. Among its questions for boards is whether they understand their reliance on outsourced IT and cloud services. In 2014 that meant the cloud; today it also means AI.