AI Didn’t Change Risk. It Exposed It.

Let me start with something that might sound a little counterintuitive.

AI didn’t change risk.

It exposed it.

Everywhere I go right now, the question is the same, “What’s our AI risk?”

And I get it. It’s the right question, just asked in the wrong way.

Because most organizations don’t have an AI risk problem.

They have a data problem. They have a control design problem. They have a third-party dependency problem. And in a lot of cases… they have a “we don’t actually know how this works” problem.

AI didn’t create any of that. It just turned the lights on. Let me give you a way to visualize what’s actually happening. Think of your organization’s technology environment like a game of Jenga.

At the very top… that’s your AI. That’s the shiny part. That’s what everyone is talking about. That’s what’s driving investment. But AI isn’t standing on its own.

Underneath it… you’ve got applications. Under that… your data pipelines. Under that… third-party services. And at the bottom… shared infrastructure.

Cloud. Compute. Regions. Things you don’t control. Now here’s the problem.

Most organizations are staring at the top block… asking: “Is this stable?”

Instead of asking: “What happens if something shifts… three layers down?”

We’ve spent years organizing risk into neat categories.

Cyber sits over here. Third-party risk over there. Privacy, compliance… all in their own lanes.

Clean. Structured. Manageable. But that’s not how the tower actually works.

Every block depends on the ones beneath it. And when you introduce AI, you’re not just adding a block. You’re adding weight… to the very top of the tower. Which means every weakness underneath it… matters more.

This is what I call dependency stacking.

It’s not just one layer supporting another. It’s multiple layers… each with their own unknowns. Your AI depends on a SaaS platform. That SaaS platform depends on a hyperscaler. That hyperscaler shares infrastructure across thousands of companies. So when a block shifts… it’s not always obvious where the instability started. But the impact shows up at the top.

There are four shifts happening here.

First, velocity risk. AI speeds everything up. Decisions that used to take days now take seconds. In Jenga terms, we’re not taking turns anymore. We’re pulling blocks out rapidly. Sometimes multiple at a time. And the faster we move, the less time we have to notice instability.

Second, scale risk. In the past, one bad decision impacted one outcome. Now it impacts thousands… or millions. In the tower, this isn’t a small adjustment. It’s pulling a critical block and watching the entire structure react.

Third, opacity risk. From the outside, the tower looks fine. Straight. Balanced. Standing. But you can’t see which blocks are loose. You can’t see which ones are carrying weight. You can’t see which ones are about to shift. That’s the reality of AI. We’re trusting systems we don’t fully understand.

Fourth, attribution risk. When the tower starts to wobble… who’s responsible? The person who placed the block? The one who removed it? The one who designed the game? Right now, we don’t have clear answers. Because our accountability models are still built for human decisions. Not probabilistic systems.

Now let’s talk about how organizations are responding to this. Most AI governance programs I see are focused on the top of the tower. Policies. Frameworks. Documentation. They’re trying to stabilize the visible layer… while ignoring what’s happening underneath. That’s not governance. That’s decoration. You don’t stabilize a Jenga tower by writing a policy about it. You stabilize it by understanding where the weight is, where the gaps are, and how the structure behaves under stress.

So what actually works?

First, think in capability, not controls.

Not “Do we have a control?” But: “Can we keep the tower standing… under pressure?”

Second, don’t isolate AI.

AI isn’t a new tower. It’s the top of the existing one. If you treat it separately, you miss the dependencies.

Third, govern decisions, not just technology.

Focus on where blocks are being moved, how decisions are made, and when intervention happens.

Fourth, map the structure.

You need to understand what’s holding up your AI… and what your AI is holding up. Because right now, most organizations are building upward…without understanding the base.

Fifth, test the collapse.

Everyone tests stability. Very few test failure. What happens when the tower actually falls? Because eventually… something will shift.

So here’s where I’ll leave you.

AI didn’t change risk. It just made the tower taller. And the taller the tower gets, the less forgiving it becomes. The organizations that succeed with AI won’t be the ones building the fastest. They’ll be the ones that understand the structure well enough to keep it standing. And here’s the uncomfortable part. Most of us didn’t build the tower. We inherited it.

And now we’re the ones adding blocks to it.

Previous
Previous

Panic or Denial?

Next
Next

Cognitive Resilience or Cognitive Delusion?