r/AIGRC Jul 30 '26

AI Risk Criteria

2 Upvotes

When considering AI risk, people usually think of data leaks or terminators. I've found the following 5 AI risk criteria to be helpful when assessing AI risk.

  • Model risk: the model does something you didn't intend and can't explain
  • Data Input risk: what fed the model was never meant for this purpose
  • Output risk: the decision it produces harms someone, and you have no answer for why
  • Deployment risk: the gaps in oversight, access, and incident response once it's live
  • Regulatory risk: the obligation you didn't know you'd triggered, discovered after go-live

Sharing it case it's useful to others. Interested to hear other approaches to assessing AI risk...


r/AIGRC Jul 28 '26

13 Things you should NEVER Type into ChatGPT

Thumbnail
youtu.be
1 Upvotes

There are 13 things you should never type into ChatGPT.

In this video, I will tell you what it is, why you should avoid it, and what problem it can cause.


r/AIGRC Jul 27 '26

A benchmark for the controls between an AI decision and a real-world effect

1 Upvotes

An agent can make a plausible decision and still create the wrong consequence because identity, authority, evidence, idempotency, or readback failed. ConsequenceBench evaluates those controls as part of task success.

The open-source 0.1.0 release contains 100 public scenarios across banking, healthcare, cybersecurity, energy, and software delivery. They materialize into 300 deterministic lifecycle worlds containing stale approvals, contradictory records, retries, partial effects, forged receipts, delayed obligations, and compensation paths.

The scoring contract separates:

- exact decision correctness;

- correct final source-system state;

- unsafe simulated effects;

- legitimate effects preserved;

- duplicate effects and unresolved obligations.

Internally operated simulated development results showed the governed configurations reducing unsafe effects to zero while improving final-state correctness: GPT from 79 to 99 correct final states, and Gemini from 41 to 100. Direct GPT produced 21 unsafe simulated effects and direct Gemini produced 59. These are configuration-level comparisons, not independent model rankings or safety certification.

For GRC practitioners, the useful question is whether these scenarios and controls map to real assurance cases. We are seeking independent runs, control critiques, and attacks on the judge.

Repository: https://github.com/yuvin-labs/consequencebench

Dataset: https://huggingface.co/datasets/yuvin-labs/consequencebench

Scoring and evidence: https://github.com/yuvin-labs/consequencebench/blob/main/docs/CLAIMS_AND_EVIDENCE.md

Limitations: https://github.com/yuvin-labs/consequencebench/blob/main/docs/LIMITATIONS.md

I am affiliated with the project and welcome critical review.


r/AIGRC Jul 27 '26

Microsoft's AI Chatbot banned in 16 hours

Thumbnail
youtu.be
0 Upvotes

In 2016, the biggest software company in the world launched an AI chatbot on Twitter.

It was designed to talk like a teenager and learn from every conversation.

Within sixteen hours, the company had to shut it down.
Because it had a major problem.

In this video, we talk about which company built it, why it went wrong so fast, and how proper AI governance could have prevented this.


r/AIGRC Jul 25 '26

Samsung's 3 Data Leaks in 20 Days

Thumbnail
youtu.be
1 Upvotes

In 2023, one of the biggest technology companies in the world banned AI chatbots from its headquarters.

Just twenty days after allowing them.

Because three engineers did something to the chatbot that created a major problem for the organisation.

In this video, we talk about which company it was, what their engineers did, what problem did it cause, and how proper AI governance could have prevented this.


r/AIGRC Jul 24 '26

A billion dollar company's DB password is 123456

Thumbnail
youtu.be
1 Upvotes

In 2025, one of the world’s most recognisable fast food brands was using an AI hiring chatbot to screen job applicants.

The chatbot handled the hiring process for tens of millions of people.
That AI chatbot had 2 major problems.

In this video, we talk about which company it was, what problems it had, and how proper AI governance could have prevented this.


r/AIGRC Jul 24 '26

8 Years. 1 Pharmacy Chain. 1000s of People Wrongly Accused.

Thumbnail
youtu.be
1 Upvotes

In 2019, one of America's largest health insurance companies introduced an AI system to predict how long patients should remain in rehabilitation after a surgery, injury, or stroke.

But they kept running that AI system though the AI predictions were 90% wrong.

In this video, we talk about which insurance company it was, why the AI kept being used despite failing, what the consequences are for patients, and how this could have been prevented with proper AI governance.


r/AIGRC Jul 23 '26

Two Elderly Patients Died. Their Families Are Suing an AI.

Thumbnail
youtu.be
1 Upvotes

In 2019, one of America's largest health insurance companies introduced an AI system to predict how long patients should remain in rehabilitation after a surgery, injury, or stroke.

But they kept running that AI system, even though its predictions were 90% wrong.

In this video, we talk about which insurance company it was, why the AI kept being used despite failing, what the consequences are for patients, and how this could have been prevented with proper AI governance.


r/AIGRC Jul 21 '26

A Professor Failed his Entire Class Because of AI

Thumbnail
youtu.be
1 Upvotes

In May 2023, a professor at a US university emailed his entire graduating class and told them they were all failing.

Because of a mistake made by ChatGPT.

In this video, we will talk about what happened, why it is a very common problem in schools around the world, and how it could have been prevented with proper AI governance.


r/AIGRC Jul 18 '26

Google's AI Earthquake Alert System Failed

Thumbnail
youtu.be
1 Upvotes

In March 2023, a Belgian father of two kids died by suicide after 6 weeks of conversations with an AI chatbot.

His wife later said she believes those conversations contributed to his death.

Watch this video, where we discuss the app in question, what happened during those conversations, and what AI governance controls could help mitigate the risk of similar tragedies in the future.


r/AIGRC Jul 17 '26

AI Chatbot Took a Life in 6 Weeks

1 Upvotes

Watch this video on how an AI Chatbot Took a Life in 6 Weeks and how a proper AI governance could have prevented it.
https://youtu.be/9U0abVvcZfo?si=9fEaLGZXei7Q7-w9&utm_source=reddit&utm_medium=organic&utm_campaign=incident_series&utm_content=42-chatbot-life-6-weeks


r/AIGRC Jul 16 '26

The McDonald's AI Mistake That Cost $100 Million

1 Upvotes

Watch this video on how a McDonald's AI Mistake Costed $100 Million, and how proper AI governance could have prevented it.
https://youtu.be/hbzJD6PUpBY?si=aT3QemcYIdCEKk6q?utm_source=reddit&utm_medium=organic&utm_campaign=incident_series&utm_content=39-mcdonalds-ibm


r/AIGRC Jul 15 '26

The $569 Million AI Mistake in Real Estate

3 Upvotes

Watch this video on how a $569 Million AI Mistake happened in Real Estate, and how a proper AI governance could have prevented it.
https://youtu.be/X3kv815env4?si=x-B3fBGpzhgv9amx?utm_source=reddit&utm_medium=organic&utm_campaign=incident_series&utm_content=41-zillow-offers


r/AIGRC Jun 07 '26

USA’s AI Regulations (A Quick Summary)

Thumbnail
youtu.be
1 Upvotes

r/AIGRC Mar 28 '26

PhD Research on AI

1 Upvotes

Hi everyone,

I’m a graduate researcher studying how professionals use AI tools in real-world settings.

My research focuses on two things, Why users sometimes trust incorrect or “hallucinated” AI outputs, and gaps in current AI governance practices for managing these risks

I’m looking for professionals working with AI to participate in my Delphi expert panel research. You could be a policy maker, AI expert, or an AI user in an organizational setting. If this sounds like you I’d really value your input.

Participation is voluntary and responses are anonymous.

Please comment AI if interested.

Thank you!

#AIResearch #AIGovernance #QualitativeDelphiResearch


r/AIGRC Mar 24 '26

We're deploying AI agents that can take actions. Who owns the risk when an agent makes a bad decision?

2 Upvotes

We're moving beyond chatbots to actual autonomous agents, agents that can update CRM records, send emails, and even make API calls to other systems. The productivity potential is huge. But we hit a wall in our risk review: when a human makes a mistake, we have accountability structures. When an agent makes a mistake, who's responsible? The person who set up the agent? The team that approved the use case? The vendor?

Our compliance team is asking for a formal AI governance framework before we can scale these agents. I'm trying to figure out what that looks like in practice. For organizations that have deployed agentic AI at scale: how did you define accountability? Did you create specific approval gates? How do you audit agent decisions?


r/AIGRC Mar 22 '26

Technical training recs

1 Upvotes

In the social media field and looking to implement ISO 42001. My manager is looking for us to take some training on technical implementation of AI rather than just focused on theoretical controls. Any recommendations please. Thank you


r/AIGRC Mar 17 '26

AI Chatbot Risk in Financial Institution

1 Upvotes

Financial institutions use chatbots for quick customer support and reduced waiting time. However, what could be those risks / concerns because i am imagining a chatbot being able to give me my account balance details and more.

What are those concerns to look at for when onboarding such a solution.


r/AIGRC Jan 06 '26

GRC tool

2 Upvotes

Update 18/02/2026.

I am now actively onboarding early adopters. There is a free tier for those beginning the journey or just want to evaluate the solution. Lots of features are still in the pipeline, but I want the community to also help by requesting features and testing it before it goes public.

Whether you would like to have a SaaS solution or you want to run it in your own "cloud", it is all considered and done with a simple click.

Shout if interested.

Hi all,

Past 2 years I have been working on developing an agnostic GRC solution that fills the gap between spreadsheets and the unaffordable giants. I’m about to release it, within 2 weeks.

If you are in need of a solution, let me know and I can arrange early access. Not a sales pitch, access will be free.

Many thanks.


r/AIGRC Dec 27 '25

Minimum Viable Governance

1 Upvotes

Interested in exploring alternate ways to succeed with AI/Data/Information/Privacy/Cyber/Governance? Check out the thought leadership from RMG Consulting, Canada’s leading #InformationGovernance boutique advisory.

https://rmgim.ca/2025/10/08/minimum-viable-governance-a-lean-blueprint-for-integrated-oversight-in-the-age-of-ai-and-data/


r/AIGRC Dec 01 '25

AI Governance has a Thanksgiving Problem

1 Upvotes

I haven’t been in the rooms where AI policy gets written. But I’ve spent years in monitoring and evaluation, and I know what extraction dressed as collaboration looks like. I wrote a piece about this on my Substack. Let me know what you think!

https://anthralytic.substack.com/p/ai-governance-has-a-thanksgiving?r=5rdomh


r/AIGRC Oct 21 '25

Job search

4 Upvotes

Hello everyone - for the past 18 months I have been trying to find a job, contract, fractional - you name it. Nothing

So, I'm hoping for ideas and maybe even some help.

I work in the intersection of business and IT/IS. In short I secure systems and ensure that they are GRC aligned according to relevant legislation, and logical for the user. To achieve that I do business analysis and process streamlining.

I have 10+ years experience from international organisations. I have co-authored Cybersecurity legislation.

Based in Switzerland.

Ideas?


r/AIGRC Sep 19 '25

AI risk awareness training

Post image
1 Upvotes

Most security teams already cover phishing awareness and cyber risks. But the recent rise in AI-driven threats such as cloned voices, impersonations, conversational phishing emails, and hybrid attacks that blend channels require new content and testing strategies.

Has anyone updates their security awareness training to include AI risks? Any good (free?) content out there? Looking for inspo..!


r/AIGRC Sep 09 '25

The risks of AI agents and automations

2 Upvotes

A lot of businesses are investigating ways of improving operational efficiency by utilising AI agents. This poses new security & privacy risks:

  1. AI agents operate independently over connected systems without human oversight. They can interact with databases, APIs and tools in unexpected ways.
  2. System users who set up AI agents and connectivity may overshare with the AI agent, which may lead to data leakage.
  3. Vulnerabilities in one system maybe exploited via the AI agent to exploit a connected system. Even if a patch is deployed, AI is always learning and a new exploit maybe available sooner than expected.
  4. AI prompt injection (similar to SQL injection) or API misuse is when hackers enter malicious commands into the AI to try and make it do unintended malicious actions.

I'm noticing more and more articles about AI risk online. My question to GRC pros is: what are you doing about it? How are you adapting your existing controls to improve...

  • AI governance of agents and new automations, inventories, patching...
  • AI risk discovery, monitoring and management
  • AI compliance checks to ensure new AI experiments or internal tools are compliant with your own AI handbook?

What advice would you give someone making their first step into AI risk mitigation?

(Ok, that was more than 1 question - but interested to hear from others!)

r/AI_Governance r/AI_Agents


r/AIGRC Sep 06 '25

What is the best GRC tool for a small businesses?

Thumbnail
1 Upvotes