# AI governance has a measurement problem

New whitepaper · Qualifying and Quantifying Risk

> A practical methodology for identifying, qualifying, and quantifying AI risk without creating false precision.

AI governance programs aren't struggling because organizations are unaware of AI risk. They're struggling because the discipline doesn't yet have a reliable way to know which AI systems exist, describe what kind of risk each one carries, and measure how that risk compares to everything else competing for attention and budget.

[Download the full paper](#download)

## Qualifying and Quantifying Risk

By Nicholas Baker, MBA, JD · Head of Governance, Openlayer

Download the full paper with the form at [https://www.openlayer.com/resources/whitepapers/qualifying-and-quantifying-risk#download](https://www.openlayer.com/resources/whitepapers/qualifying-and-quantifying-risk#download).

## What's inside

Drawing on peer-reviewed research, published risk taxonomies, and binding regulation, the paper shows why AI risk breaks down in three separate places, and what it takes to fix each one.

### Identification

Why governance can't be applied to systems nobody has recorded, and how continuous, intake-driven inventory closes the gap.

### Qualification

Scoring every use case on three independent dimensions: use case, enterprise, and model risk.

### Quantification

Maximum-governs scoring, mandatory escalation triggers, and risk-tiered human oversight.

### Lessons from nuclear and aviation

How probabilistic risk assessment matured, and what AI governance still needs before it can follow.

### The case against moving too fast

Goodhart's Law, leaderboard gaming, and why a single averaged score invites the wrong incentives.

### Grounded in the literature

Cross-checked against the MIT AI Risk Repository, the NIST AI RMF, the EU AI Act, and clinical AI frameworks.

## Questions the paper answers

Written for governance, risk, and compliance leaders who need a defensible way to prioritize AI risk today.

## FAQ

### Why do AI governance programs keep failing?

Not because the risk is unknowable or because any one organization was careless. The discipline hasn't yet built reliable tools to identify which systems exist, qualify the risk each one carries, and quantify how those risks compare.

### Why keep three risk scores instead of one?

Scoring use case, enterprise, and model risk separately forces each risk to be described where it actually originates, and gives future incident data somewhere coherent to attach.

### What does 'maximum governs' mean?

Classification follows the highest of the three dimension scores, not their average, so a critical failure in one dimension can't be diluted by strong performance in the others.

### Can AI risk be quantified today?

Only partly. The paper argues risk estimates should be published with their stated confidence and limitations, and lays out the conditions, chiefly accumulated incident data and independent external validation, still needed before AI risk quantification can mature.

## Put the methodology into practice

Openlayer helps enterprises inventory AI systems, classify risk, and monitor models in production, so governance happens at intake, not after the fact.

[Request a demo](/request-a-demo)
