Frontier AI, cyber resilience and the exit plan nobody has tested
A short, selective list of new papers on AI risk that boards should know about, with a judgement on each and a question for the board.
A selective reading list on AI risk for boards, essays on risk, uncertainty and AI, and guidance and reports I wrote for the OECD and the Institute of Risk Management. Each essay opens here, with the full article on Substack.
A short, selective list of new papers on AI risk that boards should know about, with a judgement on each and a question for the board.
Where AI Risk Reading covers what is new, Foundations covers what lasts: ten documents, where to start with each, and why it matters to a board.
There are many flavours of risk. Some we understand perfectly well. Leave the ice cream out of the freezer overnight and we know what we will find in the morning. We teach our children to look both ways when they cross the road, even on a one-way street (dangers of Lime bikes!) Banks employ specialists to manage the mismatch between assets and liabilities, because they know exactly what happens when they don’t.
But sometimes we simply do not know. The old cartographers had an honesty about how they dealt with this. Where their knowledge ran out, they wrote “Here Be Dragons”. Gradually knowledge pushed the dragons off the map, and we learnt that we could sail around the world without meeting one (unless we went to Komodo).
Read the full article on Substack
In an earlier article, I borrowed the warning sometimes attributed to old cartographers: “Here Be Dragons.” John Adams calls risks of this kind virtual: matters where knowledge is lacking, or experts cannot agree. The dragons did not need to exist for the uncertainty beyond the map to influence how people sailed.
Perhaps the modern map should say: “Here Be Aliens.” There is a small joke hiding in the word, but also a serious question. We cannot know everything AI will make possible, or what an organisation might become as it builds AI into its decisions. Like the dragons, our aliens give shape to something we do not yet understand.
Read the full article on Substack
Bubble or bust is the AI question of the month. There is a comforting answer to it. Even if it overshoots, something valuable will be left behind, the way the railways survived the mania and the internet survived the crash. That answer assumes tomorrow’s AI will be a larger version of today’s, financed on a path that simply continues. I think the more dangerous assumption is the straight line itself. The assets securing much of today’s AI debt are GPUs and data centres financed on the premise that today’s giant models will still be the dominant architecture when the debt matures. If a cheaper, smaller, more specialised architecture wins instead, the technology succeeds and the collateral fails at the same moment. That is not a demand problem. It is a straight line drawn through a bend.
Read the full article on SubstackThe industry measures progress along a single line: bigger model, more knowledge, another benchmark passed, another straight extension of the same ladder. Every serious institution I have worked in knows that intelligence does not actually work that way. We do not hand one individual origination, risk judgement and final sign-off and call it efficient. We call it a control failure waiting to happen. Yet the dominant model of artificial intelligence asks one system to propose, reason, calculate and certify its own answer, and calls the final pass self-critique. I think the more interesting question is not how much a model knows. It is whether the architecture around it resembles a governed institution or an unaccountable one.
Read the full article on SubstackReports and guidance I wrote or co-wrote for the OECD and the Institute of Risk Management. The IRM guidance is free to download, with a short executive summary for board members and a full document for practitioners.
Written for the OECD’s work on corporate governance and the financial crisis, covering banks in the UK, the United States and France. It argued that boards had become dependent on management for assurance, that part-time non-executive oversight was stretched, and that risk management had to reach beyond the organisation into its extended enterprise. The same pressures return today, as boards come to rely on AI they did not build and cannot easily inspect.
No longer on the OECD website. The OECD cites it in its 2014 review, Risk Management and Corporate Governance.
Written as the UK Corporate Governance Code first asked boards to determine the nature and extent of the risks they are willing to take. Its questions for the boardroom, and its use of John Adams’s categories of risk, including virtual risk, apply directly to decisions about AI today.
On risk that sits outside an organisation’s direct control: in suppliers, outsourcing and networks of partners. Among its questions for boards is whether they understand their reliance on outsourced IT and cloud services. In 2014 that meant the cloud; today it also means AI.