New whitepaper · Qualifying and Quantifying Risk

AI governance has a measurement problem

A practical methodology for identifying, qualifying, and quantifying AI risk without creating false precision.

AI governance programs aren't struggling because organizations are unaware of AI risk. They're struggling because the discipline doesn't yet have a reliable way to know which AI systems exist, describe what kind of risk each one carries, and measure how that risk compares to everything else competing for attention and budget.

Cover of the Openlayer whitepaper Qualifying and Quantifying Risk

Qualifying and Quantifying Risk

By Nicholas Baker, MBA, JD · Head of Governance, Openlayer

Loading form…

What's inside

Drawing on peer-reviewed research, published risk taxonomies, and binding regulation, the paper shows why AI risk breaks down in three separate places, and what it takes to fix each one.

Identification

Why governance can't be applied to systems nobody has recorded, and how continuous, intake-driven inventory closes the gap.

Qualification

Scoring every use case on three independent dimensions: use case, enterprise, and model risk.

Quantification

Maximum-governs scoring, mandatory escalation triggers, and risk-tiered human oversight.

Lessons from nuclear and aviation

How probabilistic risk assessment matured, and what AI governance still needs before it can follow.

The case against moving too fast

Goodhart's Law, leaderboard gaming, and why a single averaged score invites the wrong incentives.

Grounded in the literature

Cross-checked against the MIT AI Risk Repository, the NIST AI RMF, the EU AI Act, and clinical AI frameworks.

Questions the paper answers

Written for governance, risk, and compliance leaders who need a defensible way to prioritize AI risk today.

Not because the risk is unknowable or because any one organization was careless. The discipline hasn't yet built reliable tools to identify which systems exist, qualify the risk each one carries, and quantify how those risks compare.

Scoring use case, enterprise, and model risk separately forces each risk to be described where it actually originates, and gives future incident data somewhere coherent to attach.

Classification follows the highest of the three dimension scores, not their average, so a critical failure in one dimension can't be diluted by strong performance in the others.

Only partly. The paper argues risk estimates should be published with their stated confidence and limitations, and lays out the conditions, chiefly accumulated incident data and independent external validation, still needed before AI risk quantification can mature.

Put the methodology into practice

Openlayer helps enterprises inventory AI systems, classify risk, and monitor models in production, so governance happens at intake, not after the fact.