Agentic AI AcademyAgentic AI Academy

The AI Risk Taxonomy for Boards

Eight risks every leader must be able to ask about

Intermediate 14 minDecision-maker
What you'll be able to do
  • Name the eight AI risks a board must be able to ask about — data privacy, hallucination, bias, IP/copyright, shadow AI, prompt injection/agent security, vendor risk, and model/agent oversight
  • Ask one sharp, board-legible question for each risk that surfaces whether it is owned, assessed, and monitored
  • Recognize the landmark cases (hallucinated legal citations, Mobley v. Workday, Anthropic's $1.5B settlement) and what each teaches a leader
  • Distinguish risks that grow sharply with agentic autonomy and tool access from those that existed with simple chatbots
  • Apply the principle that every production AI system needs a named owner and that banning shadow AI is the wrong move
  • Frame governance as a value-enablement function — high performers govern deliberately and ship faster because trust is engineered in
At a glance

AI risk is now an enterprise and fiduciary issue, not an IT footnote: a majority of organizations report having already been burned, yet accountability at the top is thin. This lesson gives you a board-ready taxonomy of eight risks every leader must be able to ask about — with a single sharp question for each — and the named, board-legible cases that make each one concrete. You don't operate the controls; your job is to confirm each risk is owned, assessed, and monitored.

  1. 1Why this is a board-level issue now
  2. 2The eight-risk taxonomy at a glance
  3. 3Risk in focus: hallucination where the answer is load-bearing
  4. 4Risk in focus: bias that scales, and IP exposure on both sides
  5. 5Risk in focus: shadow AI — and why banning backfires
  6. 6The agentic multiplier: prompt injection, vendor risk, and oversight
  7. 7From taxonomy to oversight: owned, assessed, monitored

Why this is a board-level issue now

AI risk has crossed a threshold. It is no longer an IT or compliance footnote — it is an enterprise and fiduciary issue, and the data says the risk is already in the building.

  • Incidents are real and rising. Documented AI incidents reached 362 in 2025, up from 233 in 2024 (AI Incident Database, via Stanford HAI 2026 AI Index). The OECD AI Incidents Monitor peaked at 435 monthly incidents in January 2026.
  • Most organizations have already been burned. 51% of organizations reported at least one negative AI-related incident in the prior 12 months — output inaccuracy, compliance violations, reputational damage, privacy breaches, unauthorized actions by AI systems (McKinsey State of AI 2025).
  • Oversight ownership is thin at the top. Only 28% of organizations say the CEO is directly responsible for AI governance, and just 17% say the board is (McKinsey State of AI 2025). Accountability is diffuse — and that is the single clearest signal that leaders are getting this wrong.

Your role is not to operate controls. It is to be literate enough to ask the right questions — and to make sure that for each risk below, someone is named, the risk is assessed, and it is being monitored.

Governance is a value-enablement function, not a brake. High performers don't govern less — they govern deliberately and ship faster because trust is engineered in.

Watch out

Where leaders get it wrong

The most common failure is assuming 'someone owns AI risk.' With the CEO accountable in only 28% of organizations and the board in 17% (McKinsey 2025), accountability is usually diffuse — which means in practice no one owns it. Your first move is to fix where oversight lives.

Key insight

The reframe

Don't think of this as a list of controls you must understand technically. Think of it as a list of questions you must be able to ask — and answers you must be able to demand. Literacy to question, not expertise to operate.

The eight-risk taxonomy at a glance

Here is the full map. A board doesn't need to operate any of these controls, but it must be able to ask whether each risk is owned, assessed, and monitored. For each, there is one sharp question that cuts to the heart of it.

#RiskThe one question to ask
1Data privacy & leakageWhat data can our AI systems access, where does it go (including to third-party model providers), and who approved it?
2Hallucination / accuracyWhere is a model's wrong answer load-bearing (legal, medical, financial, safety), and what human check sits before it acts?
3Bias / fairnessFor AI that affects people's rights (hiring, credit, benefits, pricing), have we tested for disparate impact and can we explain decisions?
4IP & copyrightDo our vendor contracts indemnify us for IP claims, and what is our policy on AI-generated content ownership?
5Shadow AIWhat sanctioned, safe tool have we given people so they don't paste sensitive data into free consumer apps?
6Prompt injection / agent securityFor agents that can act (browse, email, transact), what high-impact actions require human approval?
7Vendor / third-party riskWhich of our critical AI capabilities are really someone else's model, and what happens if that vendor fails or is breached?
8Model / agent oversightDoes every production AI system have a named owner accountable for performance, safety, and compliance?

The next sections take the four risks that produce the most board-legible cautionary tales — hallucination, bias, IP, and shadow AI — and make them concrete, then close on the agentic-era risks that scale with autonomy.

Tip

The leadership move

Turn this table into a standing agenda item. For each of the eight risks, ask one question per board cycle: who owns it, how is it assessed, how do we monitor it? You don't need the technical answer — you need to confirm a credible owner has one.

Risk in focus: hallucination where the answer is load-bearing

Generative models confidently fabricate. They predict plausible next words; they do not consult a database of verified facts, and they never volunteer "I don't know." Output inaccuracy is the single most commonly mitigated AI risk in enterprises (McKinsey 2025) — for good reason.

The board-legible case is the courtroom. By early 2026, well over 1,000 documented cases worldwide involved AI-fabricated legal citations — fake cases, invented quotes, citations to decisions that never existed (Scientific American, 2026 — cite the live tracker, as counts climb weekly). Even elite firms have been caught and have had to apologize and pay sanctions. No legal AI tool produces citation-ready output without human verification.

The executive lesson is not "AI is unreliable, avoid it." It is a question of placement:

Where is a model's wrong answer load-bearing — where it would be acted on in a legal filing, a medical decision, a financial statement, or a safety-critical context? There, a human check must sit before the AI's output acts. Where a wrong answer is cheap and caught quickly, you can let it run.

Example

1,000+ fabricated-citation cases

By early 2026, courts worldwide had logged well over a thousand cases of AI-hallucinated legal citations, with elite firms among those sanctioned (Scientific American, 2026). The durable lesson: where a wrong answer is load-bearing, a human verifies before it acts — every time.

Watch out

Where leaders get it wrong

Letting AI act unverified in legal, medical, financial, or safety contexts. The failure is rarely the model alone — it is deploying it without a human-in-the-loop exactly where a confident wrong answer does the most damage.

Risk in focus: bias that scales, and IP exposure on both sides

Two risks here carry the heaviest legal weight, and each has a landmark case a director should know by name.

Bias / fairness — AI can scale discrimination. Algorithms that disproportionately screen out protected groups violate Title VII regardless of intent. The precedent that should be on every board's radar is Mobley v. Workday: a federal judge allowed a nationwide age-discrimination collective action and ruled that an AI screening tool can be the employer's "agent" (Fortune, 2025 — cite live). That is a liability-shifting precedent: the AI you deploy can be treated as acting for you. (Amazon famously scrapped a recruiting tool in 2018 after it penalized resumes containing the word "women's.")

IP & copyright — exposure runs two ways: (a) the model may have been trained on copyrighted data, and (b) its outputs may infringe. The landmark figure: Anthropic settled a class action for $1.5 billion in August 2025 — the largest copyright recovery in US history, roughly $3,000 per title across ~500,000 works (McKool Smith, 2025 — cite live; NYT v. OpenAI remains ongoing). Major vendors offer enterprise copyright indemnification — but coverage varies and has conditions.

Treat vendor indemnification as a contract term to negotiate, not a default you inherit. Ask your General Counsel: do our AI contracts indemnify us for IP claims, and under what conditions does that coverage lapse?

Example

Mobley v. Workday — the AI as your 'agent'

A federal court certified a nationwide collective and ruled an AI screening tool can be the employer's agent (Fortune, 2025). For any AI that touches hiring, credit, benefits, or pricing: test for disparate impact and be able to explain decisions — because liability can attach to you.

Tip

The leadership move

Anthropic's $1.5B settlement makes indemnification a board-relevant contract term. Direct your GC and procurement to negotiate IP indemnification explicitly in every AI vendor contract — and to document your policy on who owns AI-generated content.

Risk in focus: shadow AI — and why banning backfires

Shadow AI is unsanctioned use: employees adopting AI tools without approval, often pasting sensitive data — customer records, source code, strategy decks — into free consumer apps where it may be retained or used for training.

The numbers are sobering, and the punchline is counterintuitive: ~49% of workers admit using unsanctioned AI tools, and executives are among the worst offenders — roughly 69% of the C-suite tolerate it, and 60% say it's worth the security risk to meet deadlines (CIO / BlackFog, 2025 — cite live). Shadow-AI-linked breaches reportedly carry a higher cost than the baseline.

Here is where leaders most reliably get it wrong:

Banning AI drives it underground. A prohibition doesn't stop usage — it just removes your visibility and control. The fix is not a ban. It is a sanctioned, easy, safe alternative plus a clear policy: give people an approved tool that's at least as good as what they'd reach for on their own, and tell them plainly what's allowed.

This connects directly to the eighth risk: every production AI system needs a named owner. You cannot govern what you can't see, so the antidote to shadow AI is the same as the antidote to ungoverned AI generally — visibility (an inventory), a sanctioned alternative, and an accountable owner for each system.

Watch out

Where leaders get it wrong

Responding to shadow AI with a ban. Prohibition pushes usage into channels you can't see and can't control — and executives are the most frequent violators. The ban feels like governance; it is the opposite.

Tip

The leadership move

Pair a clear acceptable-use policy with a sanctioned, genuinely good tool that kills the incentive to go rogue. Then build an inventory and assign a named owner to every production AI system — you can't govern what you can't see.

The agentic multiplier: prompt injection, vendor risk, and oversight

Three risks behave differently once AI stops merely answering and starts acting. Autonomy plus tool access is a multiplier on every other risk.

Prompt injection / agent security. Prompt injection is hidden malicious instructions — buried in a webpage, email, document, or database the AI reads — that hijack its behavior. For a chatbot this was embarrassing. For an agent that can browse, email, run code, and call APIs, the blast radius becomes data exfiltration, unauthorized transactions, and cascading failures (OWASP Top 10 for Agentic Applications, 2026). You don't need to operate the mitigations, but you can ask for them: least-privilege tool access, sandboxing, input validation, and — the executive lever — human approval for high-impact actions.

Vendor / third-party risk. Most enterprise AI risk is inherited. A large share of your AI is really someone else's model, embedded in software you bought. Centralized third-party risk management is now the norm and is shifting from annual questionnaires to continuous monitoring (PwC; ISO 42001). Ask: which of our critical AI capabilities are really someone else's model, and what happens if that vendor fails, changes, or is breached?

Model / agent oversight. Every production AI system should have a named owner accountable for performance, safety, and compliance — and the scrutiny should be risk-based (a doc-summarizing chatbot is not a loan-approval model). Agentic systems add a control layer of their own: oversight of autonomy, tool permissions, and the ability to halt and roll back.

The governing question for the agentic era: the more autonomy and tool access a system has, who is steering it, and can we stop it?

Key insight

The reframe: autonomy is the risk dial

The same flaw is trivial in a chatbot and material in an agent. As you grant a system more autonomy and tool access, every risk in this taxonomy scales with it — so the level of oversight, approval gates, and halt/rollback capability should scale too.

Example

Inherited risk is the silent majority

Most of your AI exposure isn't a model you built — it's a model embedded in a vendor's product. ISO 42001 and PwC both stress AI-specific third-party risk management precisely because the risk arrives through procurement, not engineering.

From taxonomy to oversight: owned, assessed, monitored

The taxonomy is only useful if it changes what happens in the boardroom. The translation is simple: for each of the eight risks, you are confirming three things.

TestWhat you are confirmingWhat 'good' looks like
OwnedA named person or function is accountableEach production AI system has a named owner; an executive sponsor owns the mandate and budget
AssessedThe risk has been evaluated before deploymentRisk-based tiering and an impact assessment before go-live (chatbot ≠ loan-approval model)
MonitoredThe risk is watched after deploymentOngoing monitoring, an AI-system inventory, and the ability to halt or roll back

This maps cleanly onto the durable frameworks your governance team will use — you don't need to operate them, but you should recognize the names: NIST AI RMF (Govern, Map, Measure, Manage) gives the operating vocabulary; ISO/IEC 42001 is the certifiable management-system standard; and the EU AI Act sets risk-tiered legal requirements (regulatory dates are actively shifting under the 2025–2026 Digital Omnibus — point at the live source rather than memorizing a date).

The board's specific job, per Deloitte and PwC: ensure the AI strategy drives value and fits the risk appetite, decide and document where oversight lives, and build directors' literacy to "ask the right questions." That is exactly what this taxonomy equips you to do.

Tip

The leadership move

Adopt 'owned, assessed, monitored' as your three-word test. In any AI review, for any system, ask all three. If any answer is a shrug, you've found your gap — and your next action.

Note

Frameworks are complementary, not competing

OECD principles set the values; NIST AI RMF organizes the risks and roles; ISO 42001 makes the management system certifiable; the EU AI Act sets legal requirements. One well-built program can address several regimes at once — your team shouldn't be choosing between them.

Try it: Build your board's AI risk register

Goal: turn the eight-risk taxonomy into a one-page oversight artifact you could table at your next board or executive meeting. 1) List the eight risks down the left of a simple table: data privacy/leakage, hallucination/accuracy, bias/fairness, IP/copyright, shadow AI, prompt injection/agent security, vendor/third-party risk, model/agent oversight. 2) Add four columns: Named owner, Assessed? (and how), Monitored? (and how), and The one question I will ask. 3) Fill what you can today from memory of your own organization — and mark the gaps honestly; the blanks are the point. 4) Pick your two highest-stakes AI uses (where a wrong answer or unauthorized action would be load-bearing — legal, financial, hiring, safety, or any agent that can transact) and write, for each, the single human-in-the-loop or approval gate that must exist. 5) Stress-test shadow AI: note whether your people have a sanctioned, genuinely good tool — and if not, draft the one-line policy + tool decision that would replace a ban. 6) Decide where oversight lives (full board, audit/risk committee, or a new AI committee) and who the executive sponsor is. 7) Write three sentences for your board: which risk is least owned today, which case (hallucinated citations, Mobley v. Workday, or the Anthropic settlement) is most relevant to your business, and the first action you will direct. This produces a real register and the literacy to ask the right questions — no controls to operate, just ownership to confirm.

Key takeaways

  1. 1AI risk is now an enterprise and fiduciary issue: 51% of organizations reported a negative AI incident in the prior year, yet the CEO owns governance in only 28% of them and the board in 17% (McKinsey 2025) — diffuse accountability is the core failure.
  2. 2Memorize the eight risks and one sharp question each: data privacy, hallucination, bias, IP/copyright, shadow AI, prompt injection/agent security, vendor risk, and model/agent oversight. Your job is to confirm each is owned, assessed, and monitored.
  3. 3Three cases make the risks concrete: 1,000+ AI-fabricated legal citations by early 2026 (verify human checks where wrong answers are load-bearing); Mobley v. Workday (an AI tool ruled the employer's 'agent'); and Anthropic's $1.5B copyright settlement (make vendor indemnification a negotiated contract term).
  4. 4Banning shadow AI drives it underground and executives are the worst offenders — the fix is a sanctioned, safe alternative plus clear policy, and a named owner for every production system.
  5. 5Autonomy is the risk dial: prompt injection that was embarrassing in a chatbot becomes data exfiltration and unauthorized transactions in an agent — require human approval for high-impact actions and the ability to halt and roll back.
  6. 6Govern deliberately, not less. High performers ship faster because trust is engineered in; the durable frameworks (NIST AI RMF, ISO/IEC 42001, EU AI Act) give your team a shared, complementary toolkit.

Quiz

Lock in what you learned

Check your understanding

0 / 4 answered

1.A board member asks, 'We use AI to draft customer-facing legal summaries — what's the single most important control?' Which answer best reflects the hallucination risk?

2.Your CISO reports that roughly half of employees — including several executives — are pasting work data into free consumer AI apps. What is the correct leadership response?

3.In Mobley v. Workday, why is the ruling significant for any company deploying AI hiring tools?

4.Which statement best captures how risk changes as AI moves from a simple chatbot to an autonomous agent that can browse, email, and transact?

Go deeper

Hand-picked sources to keep learning