DRJ, in partnership with the BCI, has released Version 1.0 of the ‘AI in Resilience Framework’.
The new framework gives the resilience profession a common starting point for AI resilience, built around three core areas:
Govern: oversight, accountability, policy
- Knowing who owns AI-driven actions before those actions occur.
- Translating emerging AI rules into resilience practice.
- Responsible use, explainability, and the trust stakeholders place in decisions AI has shaped.
Defend: AI as a risk to manage
- AI-augmented attacks, deepfakes, synthetic identity, and social engineering produced at scale.
- Model failure, drift, poisoning, fabrication, and dependence on third-party models and data.
- The failure of autonomous agents, the cascading actions they trigger, and the wider blast radius they create.
Apply: AI as a capability to use
- Business impact analysis, risk assessment, plan generation and maintenance, scenario design, and exercising.
- Anomaly and ransomware detection, automated recovery workflows, and real-time operational dashboards.
- Intelligent monitoring, information triage during an incident, and around-the-clock assistance.
- Assessing vendor claims, [CHANGE] building vs buying, integration, and the workforce change adoption brings.






