Skip to content

Framework · MindXO · CC BY 4.0 · free

Deployer AI Risk Register

82 deployer-side risks plus 61 MITRE ATLAS-anchored entries, crosswalked to ISO/IEC 42001, the EU AI Act and both OWASP Top 10s.

A single organisation's project.

Source: airiskdeployer.org↗

Against the five tests

The map is scored for a specific reader: a firm of roughly 20 to 500 people, no CISO and no compliance department, using agents it bought and agents it built, looking for a named document it can check itself against.

Test The question Score
Agent-scoped Covers agents, tools, MCP and autonomy, not AI in general. ◐
Adopter-facing Usable by a firm deploying agents, not only building them. ✔
Checklist-shaped Enumerable requirements you can pass or fail. ✘
Right-sized Digestible without dedicated security staff. ✔
Recognised A name a client, auditor or insurer would accept. ✘

✔ yes · ◐ partly · ✘ no · scores are this site’s reading of the document

The sixth test: risk across many agents

The five tests above ask whether a firm can use each document. A sixth question sits underneath them, and none of the five brings it out: does any of these documents address risk that appears across many agents at once, rather than inside one?

✔Records model monoculture with correlated failure, and multi-agent interaction dynamics, as deployer-side risks.

✔ addresses it · ◐ names it, within one system · ✘ does not

Other frameworks on the map