New whitepaper · Qualifying and Quantifying Risk
AI governance has a measurement problem
A practical methodology for identifying, qualifying, and quantifying AI risk without creating false precision.
AI governance programs aren't struggling because organizations are unaware of AI risk. They're struggling because the discipline doesn't yet have a reliable way to know which AI systems exist, describe what kind of risk each one carries, and measure how that risk compares to everything else competing for attention and budget.

Qualifying and Quantifying Risk
By Nicholas Baker, MBA, JD · Head of Governance, Openlayer
Loading form…
What's inside
Drawing on peer-reviewed research, published risk taxonomies, and binding regulation, the paper shows why AI risk breaks down in three separate places, and what it takes to fix each one.
Identification
Why governance can't be applied to systems nobody has recorded, and how continuous, intake-driven inventory closes the gap.
Qualification
Scoring every use case on three independent dimensions: use case, enterprise, and model risk.
Quantification
Maximum-governs scoring, mandatory escalation triggers, and risk-tiered human oversight.
Lessons from nuclear and aviation
How probabilistic risk assessment matured, and what AI governance still needs before it can follow.
The case against moving too fast
Goodhart's Law, leaderboard gaming, and why a single averaged score invites the wrong incentives.
Grounded in the literature
Cross-checked against the MIT AI Risk Repository, the NIST AI RMF, the EU AI Act, and clinical AI frameworks.
Questions the paper answers
Written for governance, risk, and compliance leaders who need a defensible way to prioritize AI risk today.
Not because the risk is unknowable or because any one organization was careless. The discipline hasn't yet built reliable tools to identify which systems exist, qualify the risk each one carries, and quantify how those risks compare.
Scoring use case, enterprise, and model risk separately forces each risk to be described where it actually originates, and gives future incident data somewhere coherent to attach.
Classification follows the highest of the three dimension scores, not their average, so a critical failure in one dimension can't be diluted by strong performance in the others.
Only partly. The paper argues risk estimates should be published with their stated confidence and limitations, and lays out the conditions, chiefly accumulated incident data and independent external validation, still needed before AI risk quantification can mature.

