Most organisations that have "done something" about AI have written a policy. It says what staff must not do: don't enter confidential data into public tools, don't use AI for decisions without approval, check the output. All sensible, but does it enable governance and drive value?
A policy tells people the rules but does not in itself enable experimentation, innovation and calculated risk taking. A risk appetite tells the organisation how much uncertainty it will accept in exchange for value, and where it will accept none. Without the second, the first is a list of fears with no way to say yes. The result is predictable: either everything slows to a crawl, or people quietly move around the rules and we're sure you've seen this before.
The mistake: setting appetite by tool
The instinctive approach is to approve or even ban tools. Tool X is allowed, tool Y is not. This fails for a simple reason: the risk does not live in the tool. The same model can draft an internal meeting summary (trivial) or influence a business decision (material). Approving the tool tells you nothing about either.
Set appetite on consequence and autonomy
Two questions do most of the work for any AI use case:
- What is the worst plausible consequence of a wrong output? Not the likely one, the plausible worst case.
- How much happens before a human applies judgment? Does the AI suggest, draft, decide, or act?
A third question refines the answer: how quickly can the error be reversed? An incorrect draft that a person reads is reversible in seconds, whereas an automated message to a customer is not.
Combine these and you get three tiers a board can actually reason about:
- Tier 1: low consequence, human in the loop. Drafting, summarising, analysis for internal use. High appetite, minimal friction. The cost of over-governing this tier is real and rarely counted.
- Tier 2: material internal decisions or customer-facing output. Moderate appetite. Human review required, and the review must leave evidence before the output is put into action.
- Tier 3: autonomous action on high consequence decisions. Credit, claims, employment, pricing, regulatory reporting. Very low appetite until the organisation has proven it can monitor and contain failure.
The appetite statement
A risk appetite statement that cannot be breached is decoration. It needs to be actionable and written in a way that can be tested. Compare:
"The organisation takes a responsible approach to AI."
with
"We accept low consequence errors from AI in internal drafting and analysis in exchange for productivity. We will not allow AI to take or communicate a decision affecting a customer's money, employment or legal position without a named human accountable for the outcome."
The second can be measured, challenged and breached. That is what makes it useful.
Indicators that tell you something
Most AI metrics measure activity: number of users, number of prompts. Appetite needs indicators that show whether you are inside the boundary:
- Register coverage: the share of known AI uses that have a named owner and an assigned tier.
- Declared versus actual: unregistered AI use found compared to registered use. A widening gap means your appetite exists only on paper.
- Override rate: how often humans change or reject AI output. If it is close to zero, your human review is probably theatre, not control.
- Time to contain: how long from an AI-related incident being identified to it being contained.
- Concentration: the proportion of critical processes dependent on a single model or vendor.
The appetite most boards forget: not adopting
Every appetite statement covers downside, but few cover the risk of falling behind. If competitors compress a three-day process into three hours, standing still is a strategic risk with a cost. A mature statement says explicitly how much under-adoption the organisation will tolerate. Otherwise risk functions become, by default, the brake — and the board never sees the trade-off it is making.
Appetite is not a one-off
Set it, then name the triggers that force a review: a material model change from a vendor, a new class of use case, a significant incident, a regulatory development. Annual review cycles were designed for risks that move slowly, and AI risks are definitely not those.
Where to start
Pick your five most consequential current or planned AI uses. Place each on the three tiers. Write one sentence of appetite per tier. Take it to your executive or board and see where they disagree. That disagreement is the whole point, and it is far cheaper to find now than after an incident.
Working through this in your own organisation?
We'd welcome the conversation — book time with the Cadie team.