
AI Risk Is Not One Risk
TL;DR
AI risk is not a single governance category. It is at minimum six distinct risk types: model risk, third-party and vendor concentration, conduct and bias, data governance, operational resilience, and infrastructure and balance sheet exposure, each already owned by an existing risk discipline elsewhere in the institution. The expectations are already concrete: the NAIC AI Model Bulletin, adopted in 25 US jurisdictions as of April 2026, requires named ownership and documented bias testing today, and the EU AI Act classifies credit scoring and insurance underwriting as high-risk, with binding obligations from 2 December 2027,and the NAIC AI Model Bulletin, adopted by 25 US states as of mid-2026 with eight more in process, requiring named ownership and documented bias testing. Institutions governing AI risk through a single committee reporting to technology are not ahead of a coming requirement; they are behind an existing one.
The same folder, a different risk
Most institutions can point to where AI risk lives. It is usually one committee, one policy, sometimes one newly created role, reporting up through a single line, often technology or innovation. Against a starting point of no structure at all, that feels like progress. It is also, on its own, close to a category error.
AI risk is not one risk. It is at minimum six distinct risk types, each with its own failure mode, its own supervisory expectation, and, in most institutions, its own owner already sitting somewhere in the existing risk function, doing a version of this work for something else. Model risk teams already validate models. Third-party risk teams already assess vendor concentration. Conduct teams already test for discrimination. None of that expertise disappears because the model in question happens to be built on a large language model instead of a logistic regression. It simply stops being asked the question.
The result is not an absence of governance. It is governance that already exists, sitting in the wrong place, disconnected from the risk it was built to cover.
The discipline is already forming
Regulators and standard-setters are not waiting for institutions to work this out on their own. Over the past eighteen months, AI risk has moved from a general concern to a set of specific, binding, and increasingly detailed expectations.
Development | What it signals |
|---|---|
EU AI Act, high-risk classification | Credit scoring and insurance underwriting formally classified as high-risk AI, with binding obligations applying from 2 December 2027. |
NAIC AI Model Bulletin | Adopted in 25 US jurisdictions as of April 2026, with four more states applying their own AI rules. |
ECB supervisory expectation | AI accountability now expected to sit inside existing risk and control functions, not a standalone technology team. |
FSB sound practices for AI adoption | Global standard-setter consultation published June 2026, final report due to the G20 in October 2026. |
EIOPA AI governance opinion | Risk-based AI governance and supervision expectations set for insurers. |
One of the five developments above is already in force, not proposed. Institutions still governing AI risk through a single committee are not ahead of a coming requirement. They are behind an existing one.
Six risks, one name
Walk through what that single committee is actually being asked to cover, and the fragmentation becomes obvious.
Model risk
AI and machine learning models that adapt and retrain over time do not sit still the way a traditional model does, and validating them is already testing the limits of standard model risk frameworks. The Federal Reserve's SR 11-7 and the Prudential Regulation Authority's SS1/23 were both written for models that behave deterministically, not for generative and agentic systems that can hallucinate or drift in ways a validation cycle built for a logistic regression was never designed to catch. UK supervisors have said as much directly, questioning whether those traditional model risk management and validation approaches can scale to this new generation of models.
Third-party and vendor risk
A small number of AI model and cloud providers now sit underneath a very large share of the industry's AI use cases. Under the EU's Digital Operational Resilience Act, that concentration is no longer generic vendor risk; providers designated as Critical ICT Third-Party Providers carry direct supervisory oversight of their own. The European Central Bank has flagged the resulting concentration dependency directly, and rating agencies have warned that a single shared infrastructure failure could affect many institutions at once rather than one at a time.
Conduct and bias risk
Insurers underwriting and pricing with AI are now expected, under state model bulletins already adopted across half the United States, to test outcomes for adverse impact against protected classes and preserve that testing as auditable evidence, not an internal note.
Data governance
Every high-risk AI decision now carries its own logging, retention, and explainability obligations under frameworks such as the EU AI Act, obligations that sit closer to a data governance and privacy function than to a technology team. A narrower version of the same problem is already inside most institutions today: employees feeding proprietary or client data into public AI tools to draft a summary or a memo, a version of shadow IT that most data governance functions cannot yet see, let alone log or explain.
Operational resilience
Shared dependency on the same handful of AI and cloud providers turns an ordinary vendor outage into a correlated one. This is precisely the scenario DORA's operational resilience testing regime was built to surface, and operational resilience teams already know how to think about it for other forms of concentrated infrastructure; the only change is that AI dependencies now belong on that same testing schedule.
Infrastructure and balance sheet exposure
Financial institutions are also lenders, investors, insurers, and counterparties to the AI infrastructure buildout itself, an exposure large enough and concentrated enough to belong inside the credit and market risk taxonomy in its own right.
What this looks like in practice
A mid-tier institution stands up an AI governance committee, chaired by the head of technology, reporting quarterly to the board. The committee reviews use cases, approves new deployments, and maintains a use-case inventory that grows every quarter.
Eighteen months in, a routine market conduct exam asks a narrower question: can the institution produce documented adverse-impact testing for the AI system now embedded in its underwriting decisions. The AI committee approved that use case. It never ran that test, because the test belongs to a discipline the committee was never built to include, and no one had asked, in eighteen months, whether it had been done.
At the same time, an unrelated internal audit finds that three business units have been running client portfolio data through an unapproved public AI tool to draft summary reports. Nobody approved it, because nobody in the AI committee's structure was positioned to see it. It was never a deployment the committee reviewed. It was a habit, and it had been running for months.
A committee that reviews AI use cases is not AI governance, any more than a sustainability report was ever climate risk governance.
What integration requires
The fix is not a bigger committee or a longer charter. It is the same discipline this series has already argued for elsewhere, applied here first.
Map it
Every AI use case should be mapped to the existing risk discipline that already governs its underlying risk, model, third party, conduct, data, operational, credit, or market, rather than defaulting to a single AI category.
Assign it
Ownership should sit inside each of those disciplines, with a named accountable owner, not inside a standalone AI function that cannot itself validate a model, test for bias, or assess vendor concentration.
Hold it to the existing standard
AI-related risk should meet the same evidentiary bar, documented testing, audit trails, demonstrated challenge, that each discipline already applies to everything else it governs.
Aggregate it at the top
The board should retain one place where all six categories are visible together, not to govern them centrally, but to know, at any point, whether each one currently has an answer.
Questions before the next board risk committee
Six questions, one for each category, are worth putting on record.
1 Model risk. Who validates the AI and machine learning models now embedded in our decisioning, and is it the same function that validates every other model, or a separate AI task force?
2 Vendor concentration. Could we name our single points of failure among AI and cloud providers, and do we know which of our peers and counterparties share them?
3 Conduct and bias. Have our AI-assisted underwriting, pricing, and claims systems been tested for adverse impact against protected classes, and is that testing documented and defensible under examination?
4 Data governance. Do we know which AI systems generate decisions that must be logged, retained, and explained to a customer or regulator, and are we already doing it?
5 Operational resilience. If our primary AI vendor, or the cloud infrastructure it depends on, failed for a day, what stops, and have we tested that assumption?
6 Infrastructure exposure. Do we know our aggregate exposure to the AI infrastructure buildout as a lender, investor, insurer, or counterparty, or is it still scattered across sector codes nobody has connected?
If any of the six produces hesitation, the fragmentation this article describes is not a future risk. It is the current state.
Closing
Sustainability risk took the better part of a decade to move from a single desk to a governed, distributed discipline, and it took several expensive supervisory findings to force the pace. AI risk is being handed the same test, with regulators moving faster and the underlying technology changing quarter to quarter, not year to year. The institutions that treat AI risk as six problems now will spend far less time relearning that lesson than the institutions that still treat it as one.
Not sure whether your AI risk is genuinely governed, or gathered under one committee that was never built to cover six different disciplines? The ARCHITECT™ Governance Maturity Assessment gives mid-tier financial institutions a structured diagnostic over two to three weeks, testing exactly this kind of fragmentation before a regulator or an incident does.
Start the AI Governance Assessment →
Sources
Author bio
Brendan Walsh is the founder of Walsh SRA and creator of the ARCHITECT™ Governance System. He brings more than 30 years of global executive leadership at American Express across the US, Europe and Asia, including as Chairman of American Express Services Europe and American Express Bank Russia. He has served as a Board Advisor to OFGEM, the UK energy regulator, and as a Board Member of the ECB's Euro Retail Payments Board. He holds a Master's in Sustainability from Harvard and GARP certifications in Sustainability & Climate Risk and AI Risk. Walsh SRA advises mid-tier banks, insurers, asset managers and private equity firms on governance for climate, sustainability and AI risk.