Do We Actually Need an 'AI Risk Model'?
KT Corporation recently paid just under $40 million for the privilege of ignoring a data breach for eleven months. Eleven months. In the world of IT, that's an epoch; in the world of regulatory filings, it's practically an eternity of negligence. While they were presumably updating their corporate values or refining their digital transformation strategy, someone was quietly walking out the back door with a mountain of user data.
At the same time, if you glance at the current trade press, there is a frantic, almost breathless rush to define "AI Risk Operating Models." We are told that AI-driven HR tools create "high-risk environments" and that banks need sophisticated authorisation protocols for their "kill switches." The PCAOB is being urged to set corporate AI standards. Everyone wants a new framework.
The conventional wisdom suggests that AI represents a fundamental shift in risk: a brand new beast that requires a brand new cage. This is the argument used by consultants to justify those expensive, multi-layered governance frameworks. They'll tell you that traditional risk management is insufficient for the stochastic nature of large language models.
I find this profoundly optimistic. It assumes we've actually mastered the "traditional" part.
Look at the carnage from this week. CareCloud has notified north of 345,000 patients about data theft. AnMed Communications had to shut down 83 facilities because a cyberattack effectively deleted their ability to function. We have GP networks leaking records onto the dark web. These aren't "stochastic" risks; they are basic hygiene failures.
The claim is that we need these new AI models to prevent systemic collapse or ethical drift. But there is a glaring disconnect between the high-minded debate over AI ethics and the reality of the paperwork. If an organisation cannot detect a breach for nearly a year, their "AI Governance Framework" is little more than expensive wallpaper.
It's a curious priority. We are worrying about whether a medical AI might hallucinate a diagnosis (a serious concern, certainly) while simultaneously leaving the actual patient records in a bucket that's essentially open to the public. One is a failure of sophisticated technology; the other is a failure to check if the door is locked.
The strongest objection here is that AI risks are additive. The argument goes that we can't ignore the new threats just because we haven't solved the old ones. We must move forward on both fronts.
Perhaps. But the second-order effect of this "framework fever" is a massive diversion of resources. Compliance budgets are finite. Every hour spent drafting an AI Ethics Charter by a committee of people who don't know how to write a SQL query is an hour not spent auditing access logs or testing backup restoration for those 83 closed facilities. The downstream victims aren't just the patients whose data is on the dark web, but the auditors who will eventually have to sign off on a "robust" AI policy while the underlying infrastructure is crumbling.
The regulators are starting to notice the gap, though they're attacking it from different angles. South Carolina is going after personal liability for employees regarding age-appropriate design. That's an interesting pivot. Instead of asking for another company-wide policy document, they're asking which specific human is going to be held accountable when things go wrong.
I suspect we'll see more of that. The era of the "corporate framework" as a shield is wearing thin. A 50-page PDF on AI Governance doesn't stop a breach, and it certainly doesn't explain why it took eleven months to notice one.
Until I see a significant drop in the number of facilities forced to close their doors during a cyberattack, I remain unconvinced that we need a new risk model. We just need people to actually do the boring stuff they were already told to do ten years ago.
I'll be interested to see if KT Corporation's fine included a requirement to actually read their own security logs.