Session
AI Risk Appetite: From Documented to Lived (And How to Get There)
Most enterprises have a documented AI risk appetite. Almost none have a lived one. The gap is the difference between what gets approved in a leadership offsite and what actually constrains decisions when the business is moving at AI speed. This session diagnoses why documented risk appetite fails to constrain behavior and presents an operational path to making appetite actually lived.
Drawing on the speaker's 15-plus years across regulated industries and her tenure as Chief Compliance Officer at a publicly traded payments technology company, this session walks through three structural failures of typical AI risk appetite programs.
First, risk appetite is signed off but not drafted by the owner. The traditional pattern is that ERM proposes appetite, leadership tweaks and signs. The owner never internalizes what they approved. Lived appetite requires that the owner DRAFTS the appetite themselves, with ERM in a supporting role.
Second, risk appetite is not specific enough to be actionable. Statements like 'we will not tolerate material AI risk' protect nothing because nobody knows what material means in any specific decision. Lived appetite is specific enough that frontline decision-makers can map their use case against it and reach a defensible answer.
Third, risk appetite is approved but not enforced. The pattern of 'metric flags red, gets explained away, asked to bring it to green next quarter, nothing actually happens' is endemic in enterprise risk management. AI compresses the timeline and amplifies the consequences. Without lived consequences for breach, documented appetite is theater.
The session presents a working framework: a floor (what we will not do, prohibited classes of AI use), a ceiling (what is explicitly permitted within stated bounds), and a gray middle (what requires explicit escalation and case-by-case judgment). The narrower the gray middle, the faster the workforce can operate; the more iteration on the appetite statement against real cases, the narrower the gray middle becomes.
Real-world failure modes anchor the discussion, including the Workday-style discrimination cases that exemplify the gap between documented and lived appetite.
Learning objectives:
Diagnose three structural failures of documented AI risk appetite.
Distinguish documented from lived appetite at the level of specific decisions.
Apply the floor-ceiling-gray-middle framework to AI use case categories.
Build owner-drafted appetite that workforce can actually execute against.
Practitioner-derived frameworks, broadly applicable across regulated industries.
For organizers: panel placement welcome.
Andrea Elliott
CEO & Founder @ EMG : Global GRC & Foresight Practitioner helping companies use AI Responsibly
Atlanta, Georgia, United States
Links
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top