Only 38% of organizations taking part in a recent Airmic survey have carried out risk assessments related to the use of artificial intelligence.
50% of organizations have not conducted AI risk assessments and do not have current plans to do so; and 12% have not conducted one but do have plans to do so soon.
Of those organizations that have conducted AI risk assessments data protection and intellectual property issues emerged as the top risks.
Airmic believes that part of the problem is that there is not yet a universally accepted model for assessing AI risk, although the recently published ISO/IEC 23894 might be the best current starting point.
Julia Graham, CEO of Airmic, said: “Research indicates that most organizations, when they do conduct an AI risk assessment, are using traditional risk assessment frameworks better suited to the pre-AI world of assessment – this is an area of risk management still in its infancy for many.”
Hoe-Yeong Loke, Head of Research at Airmic, said: “Many governments are just beginning to develop policies and laws specific to AI, while those that have are competing to put their stamp on how this emerging technology will develop. Understandably, there is no universally accepted model for assessing AI risk, but risk professionals can look to recent published standards such as ISO/IEC 23894:2023 Artificial intelligence: Guidance on risk management.”
Looking ahead, Airmic says that it plans to produce an updated methodology for AI risk assessments, in consultation with Airmic members and the industry.






