Skip to main content
AI Risk
Board Briefing

AI Risk

The AI risks that bite are seldom on the register, and the bill for sovereignty shocks, readiness gaps, verification costs, and model risk arrives later.

11 articles 6 audio Updated 26 July 2026

Start here

Two short reads before you go deeper: what AI risk actually is and where its costs hide, then the order to take this briefing in.

Start with this

The Bill That Has Not Yet Been Presented

Registers tend to price the visible costs of AI. The exposures that matter are the ones whose bill arrives later.

2 minute read · Read →

Then read this

From Dated Event to Deliberate Choice

Take the core reading in order, from the capability that vanished overnight to the discipline of choosing a model, then the mechanisms and the questions.

2 minute read · Read →

Core reading

The core sequence runs from a capability withdrawn overnight to the discipline of choosing a model deliberately, with the further reading tracing where the exposures concentrate.

  1. The AI Sovereignty Trilemma: When a Frontier Model Vanishes and Reality Bites

    The visible cost of sovereignty deters Boards. The hidden cost of the convenient alternative was never shown, and that is the cost 12 June presented.

    10 minute read · 14 June 2026

    Read the article →or listen to the podcast version → 11 minute listen

  2. The AI Maturity Mirage: Diagnosing the Gap Between Investment and Readiness

    Boards overestimate AI maturity by counting tools and pilots rather than capability. Three patterns create the illusion, and each can be diagnosed before it misleads.

    11 minute read · 7 December 2025

    Read the article →or listen to the podcast version → 16 minute listen

  3. The Verification Premium: What Classical Training Reveals About AI Coding Costs

    AI coding tools amplify the expertise gap rather than closing it: senior developers capture twice the gains. The verification premium is the cost nobody budgets.

    13 minute read · 25 January 2026

    Read the article →or listen to the podcast version → 18 minute listen

  4. Selecting your enterprise LLM: Moving beyond the hype to make the right choice

    With well over a hundred language models available, choosing one is a question of fit, not headlines: match the model to the task.

    10 minute read · 3 January 2025

Further reading

Remake

The mechanisms beneath the thinking: the model, diagnostic, methodology, and principle from the Remake Library that turn this briefing into apparatus a Board can use.

Questions

The questions I would put to any Board seeking assurance that its AI risk is understood, owned, and priced.

Could a provider withdraw the models we depend on overnight?

It already happened to organisations that were never the target. On 12 June 2026 a national-security directive forced a provider to switch off two deployed frontier models for every customer, and those cut off lost the capability as collateral of someone else’s compliance. Model availability is a third-party continuity risk that belongs on the risk register with a named owner, and the test is one line: if this model disappeared tomorrow morning, what would stop working by lunchtime? I set out the full argument in the Trilemma made real.

We have AI tools deployed in every function. Why does that not count as maturity?

Because visible activity bears little correlation to capability. 89% of enterprises have adopted AI tools, yet only 23% can measure the return on that investment (Larridin 2025), and the gap is produced by three reinforcing patterns: counting tools as capability, mistaking pilot wins for systemic readiness, and hype-driven metrics that reward short-term ROI over capability. The AI Maturity Mirage sets out a diagnostic for finding the organisation’s true position before further investment widens the gap.

Can AI coding tools reduce our dependence on expensive engineering talent?

The evidence suggests the opposite. Senior developers capture roughly twice the productivity gains of juniors (McKinsey 2023), and a randomised controlled trial found experienced developers were actually 19% slower with AI tools once verification and correction costs landed (METR 2025). Expertise is not what AI coding replaces; it is what determines whether AI-generated code creates value or debt. The Board question is not whether AI can write code cheaper but whether the organisation holds the verification capability to know. I explore this in The Verification Premium.

Is the most capable frontier model the safest choice?

Not necessarily. The safest model is the one that fits the work, judged across strategic value, risk, organisational readiness, and operational sustainability, and different use cases will justify different models. The choice is made per deployment, not once for the organisation, and it now carries a jurisdictional dimension: two providers in the same jurisdiction, subject to the same directive, are one exposure wearing two names. Start with Selecting Your Enterprise LLM and read it alongside the Trilemma made real.

Our people are using AI tools we never approved. Should we shut that down?

Enforcement fails on the numbers: 54% of employees say they would use AI tools even if unauthorised (BCG 2025), and 57% conceal their usage (Gigster 2025), so prohibition simply drives the risk underground. A time-limited AI amnesty converts the blind spot into governance visibility and captures the innovation employees have already validated. And the approved estate deserves the same scrutiny: many Boards have signed off automated decision systems that cannot yet deliver the safeguards UK law now requires, the exposure I call the Reasoning Gap.

Which of our critical processes depend on a single model or jurisdiction?

In my experience few Boards can answer this from the chair, because the dependency was assembled by default, through procurement choices each defensible on its own and never examined together as a position. The credible answer is a per-deployment map: which processes rely on one model, which of those are customer-facing or regulated, and whether the fallback would survive the specific event. The map is only honest if it counts jurisdiction as well as vendor, since a second provider under the same directive is no fallback at all. The AI Sovereignty Trilemma model frames the trade, and the Trilemma made real shows the bill once it is presented.

Who owns model availability on our risk register?

Often nobody, because model availability has been filed under IT as an operational setting rather than carried as a third-party continuity risk with a named owner. Continuity planning was built for outages, degradation, cyber incidents, and supplier failure, events the provider is working to reverse. A compelled withdrawal sits outside all of them: the provider stays up, the infrastructure stays up, and the capability goes anyway. The Board’s task is not to choose the vendor or the architecture but to require that the exposure is known, owned, and priced, which is the Minimum Lovable Governance principle applied where it matters. The Trilemma made real sets out the argument.

Does our AI business case price the oversight labour it assumes?

Almost never, in my experience. Business cases count the hours AI saves and seldom the hours it adds: the reviewing, correcting, and supervising that outputs demand before anyone can rely on them. That labour lands on existing people on top of existing jobs. A survey of 1,488 US workers found 14% of those using AI reporting mental fatigue, the strain attaching to oversight load rather than to AI use itself (BCG Henderson Institute 2026). A control asserted but not resourced exists on paper only, so every proposal should state who performs the oversight, what share of their capacity it consumes, and what that costs fully loaded. The Balancing Item prices the line the business case left out.

References

The external research and primary sources these articles draw on, for directors who want the evidence at first hand.

METR

Measuring the Impact of Early-2025 AI on Experienced Open-Source Developer Productivity

Randomised controlled trial finding experienced developers 19% slower with AI coding tools, the clearest measurement yet of the verification premium.

GitClear

AI Copilot Code Quality: 2025 Data Suggests 4x Growth in Code Clones

Analysis of 211 million changed lines of code showing an eightfold rise in duplicated blocks in AI-assisted codebases.

Google Cloud

Announcing the 2024 DORA report

The 2024 DORA report, finding a 25% increase in AI adoption correlates with a 7.2% decrease in delivery stability.

MIT Sloan Management Review

The Hidden Costs of Coding With Generative AI

Economic modelling of how technical debt from AI-generated code quickly eclipses the short-term productivity gains.

J.P. Morgan

Vibe Coding: A Guide for Startups and Founders

Investor due-diligence questions on AI-generated code, from verification process to technical debt profile.

Gartner

Gartner Survey Finds 45% of Organizations With High AI Maturity Keep AI Projects Operational for at Least Three Years

Survey evidence that high-maturity organisations sustain AI value for three years or more and earn markedly higher stakeholder trust.

McKinsey & Company

The State of AI

The State of AI research identifying leadership alignment, not technology capability, as the bottleneck in enterprise AI value.

BCG

AI at Work 2025: Momentum Builds, but Gaps Remain

AI at Work 2025, finding 54% of employees would use AI tools even if unauthorised, the workforce reality beneath shadow AI.

legislation.gov.uk

Data (Use and Access) Act 2025

The Data (Use and Access) Act 2025, the statute behind the four safeguards now required for solely automated decisions.

Institute of Directors

AI Governance in the Boardroom

The IoD business paper on AI governance in a sector-led UK regulatory environment, with the ICO as a central actor.

Harvard Business Review

When Using AI Leads to “Brain Fry”

BCG Henderson Institute research in HBR: a survey of 1,488 full-time US workers identifying mental fatigue that attaches to heavy AI oversight loads, with replacement-pattern AI use associated with lower burnout.

Anthropic

Statement on the US government directive to suspend access to Fable 5 and Mythos 5

The 12 June 2026 provider statement on the US directive that suspended two frontier models for every customer: the continuity risk that opens this briefing.

Larridin

The State of Enterprise AI in 2025: From Experimentation to Accountability

The 2025 enterprise survey behind the 89% adoption against 23% measurable return figure, the gap the maturity mirage describes.

McKinsey & Company

The economic potential of generative AI: The next productivity frontier

McKinsey’s 2023 analysis of generative AI’s economic potential, the source of the finding that senior developers capture roughly twice the productivity gains of juniors.

Concepts

The ideas beneath this briefing

Ideas I’ve named and matured writing about AI Risk: what each one means, and where it started.

Sovereign Control

The ability to keep an AI capability running on terms the organisation sets, rather than terms a distant provider, or a government, can revise without consultation; more than data residency.

Read the article →

AI Maturity Mirage

Mistaking visible tool deployments and isolated pilot wins for genuine organisational capability, a systematic overestimation that derails transformation strategies. For a Board, correcting it means diagnosing actual capability against AISA and the Five Pillars rather than trusting the appearance of activity.

Read the article →

Hype-Driven Assessment Metrics

Judging AI progress by short-term ROI and perceived importance rather than actual integration, an overestimation pattern that hardens where organisations fail to track AI impact at all.

Read the article →

Pilot Success Trap

Isolated pilot wins that create a seductive appearance of advancement while revealing nothing about systemic readiness across an organisation whose functions sit at different stages.

Read the article →

Tool-Centric Illusion

Counting AI tools deployed as evidence of maturity when, without integrated infrastructure, those deployments create capability silos rather than organisational transformation.

Read the article →

More Board Briefings

More complete resources on AI and emerging technology for the Boards that need the full picture.

I use cookies to understand how my website is used. This data is collected and processed directly by me, not shared with any third parties, and helps me improve my website. See my privacy and cookie policies for more details.