What kind of risk is this?
The nine domains answer who owns a risk; a board also needs the other lens — what kind of exposure it is. Every category spans all nine domains; what differs is where each concentrates. Each card names the domains where the exposure is most acute and how it's captured, documented, and escalated.
Falling behind on AI capability, misaligned investment, or graduating students unready for an AI workforce — risk to the institution's long-term competitiveness and mission.
Bias and disparate impact, opacity in consequential decisions, and erosion of academic integrity — risk to how AI treats people and knowledge.
Model drift, security exposure, shadow AI, and agentic systems acting unsupervised — risk to the continuity and safety of AI-enabled operations.
FERPA and privacy, IP and training-data terms, export control, and funder rules — risk of breaching the law, contracts, or sponsor conditions.
Public backlash when AI use becomes visible — in admissions, proctoring, or communications — and the loss of community trust that follows.
These categories are a reporting lens, not a parallel process. A single AI system usually carries several at once — a retention model is ethical, operational, and reputational simultaneously. Its domain still owns it and the RMF still governs it; the category simply tells the board why it matters and routes it to the right committee.