Three-Risk AI Assessment
Assess power, regulation, and workforce reskilling before adopting AI
- Difficulty
- Moderate
- Time to result
- ~weeks to results
- Steps
- 6
- Confidence
- 94%
The Three-Risk AI Assessment evaluates adoption through three distinct but related exposures. First, examine capability risk: what happens if the system becomes more powerful, autonomous, or consequential than anticipated? Second, examine regulatory risk: which current rules apply, what new controls are plausible, and could compliance changes undermine the deployment? Third, examine workforce-transition risk: which tasks, roles, or entire vocations may decline in value, and how many people would need reskilling? For each category, estimate severity, affected stakeholders, reversibility, and timing, then define safeguards and review triggers. The assessment is especially important because AI may disrupt highly educated computer-based professions as well as lower-skill work, potentially creating a reskilling challenge larger than prior technological transitions.
Origin
Kip Bodner summarized three major AI risks during a debate with Kieran Flanagan. Extracted from Marketing Against The Grain.
Core principles
- 01AI risk extends beyond technical performance.
- 02Increasing machine capability can create broad societal consequences.
- 03Regulatory uncertainty can constrain deployment and reshape economics.
- 04Workforce disruption requires active reskilling rather than passive displacement.
- 05High-skill and low-skill work may both be exposed.
How to run it
- 1
Assess capability risk
Model the harm that could arise if the system gains more capability, reach, or decision authority than planned.
Pro tip Include low-probability outcomes when their consequences would be severe.
Watch out Do not equate current limitations with permanent safety.
- 2
Assess regulatory risk
Identify applicable rules, unresolved legal questions, and foreseeable restrictions across relevant regions.
Pro tip Track both formal regulation and procurement or industry standards.
Watch out Government policy may lag technological development and then change abruptly.
- 3
Assess workforce exposure
Map the tasks, roles, and vocations that automation or machine learning could reduce or transform.
Pro tip Evaluate high-skill computer-based work as well as routine tasks.
Watch out Task disruption can accumulate into the obsolescence of an entire role.
- 4
Estimate reskilling demand
Determine how many workers need new capabilities, what those capabilities are, and how quickly transitions must occur.
Pro tip Compare training time with the expected pace of deployment.
Watch out Assuming displaced workers will automatically move into better jobs ignores institutional reskilling failures.
- 5
Design mitigations
Define human oversight, deployment limits, compliance controls, retraining paths, and contingency plans for each risk.
Pro tip Assign an owner and measurable trigger to every mitigation.
Watch out A mitigation without funding or decision authority is only an aspiration.
- 6
Review continuously
Reassess all three risks as models improve, use cases expand, and regulations evolve.
Pro tip Tie reviews to capability releases and material changes in deployment scope.
Watch out A one-time review becomes stale quickly in a fast-moving field.
In the wild
A company considers software that analyzes live sales calls and recommends behavior. It assesses whether bad guidance could harm customers, whether recording and profiling rules constrain deployment, and whether managers or enablement staff will need redesigned roles. The company pilots with human review, limited data retention, and a retraining plan before broader rollout.
→ The organization captures coaching benefits while managing capability, compliance, and workforce risks.
Common mistakes
Focusing only on existential danger
Extreme capability risks matter, but regulatory and workforce-transition risks can affect the organization much sooner.
Assuming only low-skilled work is exposed
AI can disrupt expensive, highly educated, computer-based professions as well as routine labor.
Treating reskilling as automatic
Economies and organizations often fail to retrain workers at the scale and speed technological transitions require.
Is it for you?
Best for
It is best for leaders considering AI deployments that could materially affect customers, employees, or regulated decisions.
Not ideal for
It is not ideal as a substitute for detailed legal advice, technical safety testing, or workforce consultation.
From the transcript
“And Kieran, I'd argue that there are three big risks, and we've talked about two of them, which is Elon's concern that AI becomes too…”
“It kind of the corollary to that and the related to that is regulation.”
“And the third, I I think is interesting and controversial, and I want to get your take on it.”
From the episode
The Impact of AI in Marketing (Friend or Foe?)