Advising communications leaders
FRENGESIT中文한국어日本語DEIndia · ENहिन्दी

Industry atlas

AI: build a risk matrix that goes beyond the product demonstration

An AI crisis may involve an error, misuse or an unjustified decision. Preparation must start from the people and decisions affected.

Belief System ·

The sector’s crisis communication challenge

An artificial intelligence system can show good overall results and still produce a significant error in a particular situation. Crisis communication cannot simply recall average performance. It must examine the use, the people affected and the control mechanisms actually available. A successful demonstration is not proof of robustness in all contexts.

NIST offers a voluntary framework for managing AI risks. The analysis presented here focuses on the connection between product governance and public responsibility. The central question is that of decision-making power: who can interrupt a use, correct an exit or organize an appeal when the system produces a problematic result? [1]

Build the risk matrix

The matrix must distinguish editorial assistance, recommendation and participation in a decision affecting a person. The consequences of an error vary depending on whether it can be detected, challenged, and reversed. The same model can thus present very different risks depending on its integration.

The scenario should specify the system version, relevant data, users and human controls. A generic mention of supervision is not enough. It is necessary to check whether the manager has the time, skills and authority to contradict the output. The matrix must make these conditions visible rather than assuming them.

Prepare decisions and public messages

When a controversy arises, the company must acknowledge the observed result and explain what it is verifying. This will avoid attributing the problem too quickly to a user or an unusual instruction. Predictable use but not planned by the team deserves to be analyzed as a question of design and governance.

Communication must distinguish between correction of a case, modification of the product and re-evaluation of a use. A corrected demonstration does not prove that the problem has disappeared in all situations. Commitments must therefore specify their scope and the evaluation criteria, without promising total absence of error or bias.

Test the response with a crisis simulation

In a fictional scenario, a person demonstrates that a tool produced a result that they believe is unjustified. The exercise tests the ability to find the version, relevant parameters and the decision circuit, while protecting personal information. The company must offer access to the review when this falls within its system, and explain the responsibilities of the different actors.

The simulation can introduce a second case in another language. If behavior varies, the response should not be limited to translating the first statement. It is necessary to check the operation in this context and distinguish a language defect from a more general problem. Crisis tests must therefore include real international uses.

Verify recovery and learn from the incident

The report must present the modifications and evaluations carried out, with their limits. A reduction in the number of complaints is not enough to demonstrate a reduction in risk; people may ignore the remedy or no longer use the product. Indicators must link technical quality, user experience and ability to correct.

An AI crisis matrix becomes useful when it helps decide which uses should be strengthened, suspended or redesigned. Communication then follows verifiable governance. It does not serve to transform uncertain technology into the promise of universal mastery.

Sector risk matrix — illustrative example

Hypothetical ratings over twelve months, not a measured company assessment. P × G supports prioritisation; an impact of 5 requires priority attention. Operational thresholds must be set by the competent teams. How to use the matrices

Sector risk matrix — illustrative example
ScenarioLikelihoodImpactScoreWarning signDecision to prepareEvidence required
Wrong output in reversible use428Error detected and reproducibleCorrect and document the limitTest cases and system version
Decision affecting a person without clear recourse3515*Supported challengeEnable review and evaluate usageTraceability of the decision and responsibilities
Different behavior depending on language3412Difference confirmed by testsEvaluate each context before generalizationMultilingual results and scope of corrections

Sector source

[1] NIST — AI Risk Management Framework

Sources accessed on 9 October 2026. Examples are hypothetical and do not describe client assignments.

Further reading

Cite this article

Belief System. AI: build a risk matrix that goes beyond the product demonstration. . https://beliefsystem.fr/en/regards/ai-risk-governance-controversy/

Discuss your risks and crisis communication

Belief System →