AI Governance, Risk & Red Teaming
Strategic · M7 · lesson 7 of 25 · queued
Preview — browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll →
The AI Risk Appetite Statement - Board Approval in 2026
📖
now learning

The AI Risk Appetite Statement - Board Approval in 2026

15 min

Acme's Q2 2026 board meeting opens with the audit-committee chair turning to the Chief Risk Officer with a single question: "We've just approved a €240M capital allocation for the generative-AI agent program. How do we know we have an appetite for this?" The CRO begins to answer, "Our enterprise risk appetite statement covers all material risks", and stops mid-sentence. She knows the enterprise statement was last refreshed in 2023. It mentions "technology risk" and "cyber risk" and "model risk for traditional credit models." It says nothing about autonomous agents, foundation-model concentration, fundamental-rights exposure under Article 27, Annex III tiering, prohibited-deployment carve-outs under Article 5, or the 12% inventory ceiling the AI Governance Committee has been informally enforcing for six months. The AI risk appetite is implicit. It is not ratified. It is not measurable. It is not breach-tested. And the regulator who arrives next quarter will ask to see the board-signed AIRA, the same way they would ask to see the cybersecurity or operational risk appetite. This lesson is the L4 leadership-tier framework for the AI Risk Appetite Statement: the eight dimensions, the quantitative KRIs with red-amber-green thresholds, the 12-section template, the breach-response protocol, and the Acme worked example showing a Q3 KRI dashboard breach in the Tier 4 autonomous-count line and the breach-response timeline executed.

What Is an AI Risk Appetite Statement (AIRA)

The AI Risk Appetite Statement (AIRA) is a board-ratified, written declaration of the level and type of AI risk the organization is willing to accept in pursuit of its strategic objectives. It is distinct from, and additive to, the enterprise risk appetite statement, the cybersecurity risk appetite statement, the operational risk appetite statement, and the model risk appetite statement that financial-services firms maintain for traditional models under SR 11-7. The AIRA exists because AI risk has dimensions that the inherited statements do not capture: autonomy, fundamental-rights impact, Annex III tiering, foundation-model concentration, and the long-tail of generative outputs that are neither traditional model outputs nor traditional cyber events.

The AIRA is the leadership artifact that ISO 42001 Clause 5 leadership commitment expects the board and top management to produce, and that ISO 42001 Annex A.3 organizational roles, responsibilities, and authorities maps to the AI Governance Committee. It is the artifact that NIST AI RMF Govern 1.1 (legal and regulatory requirements involving AI are understood, managed, and documented) and Govern 1.2 (the characteristics of trustworthy AI are integrated into organizational policies, processes, procedures, and practices) expect at the policy level. It is the artifact that the EU AI Act Article 17(1)(b) quality management system expects under "strategies for regulatory compliance, including compliance with conformity-assessment procedures and procedures for the management of modifications", the AIRA is the strategic compliance instrument. It is the artifact that the Bank of England PRA SS1/23 (model risk management principles for banks) and the Federal Reserve SR 11-7 (guidance on model risk management) expect at the governance pillar, where the board's role is to "approve risk appetite and the level of model risk the firm is willing to accept." It is the artifact that the OECD AI Principle 1 (responsible stewardship of trustworthy AI) expects from the C-suite as a public-facing commitment.

The AIRA is not a one-page slogan. It is not "we accept AI risk to deliver business value." That sentence is a directional statement, not an appetite statement. An appetite statement quantifies, in red-amber-green thresholds tied to Key Risk Indicators (KRIs), the specific levels of exposure the board has ratified. The board signs it. The AI Governance Committee operationalizes it. The Second Line of Defense (Risk function) tests against it. The Third Line of Defense (Internal Audit) audits adherence. The regulator, in 2026, asks to see it: and asks to see the evidence of board signature, the KRI-trend dashboard against thresholds, and the breach-response history.

The Eight Dimensions of AI Risk Appetite

The mature 2026 AIRA defines appetite across eight orthogonal dimensions. The dimensions are not interchangeable, a board may accept high exposure on one and zero on another, and the AIRA must distinguish. The eight dimensions:

  • (1) Risk category. Annex I-style categorization of the harm type the AI system could produce: physical safety (medical-device AI, industrial-control AI, autonomous-vehicle AI); fundamental rights (Article 27 FRIA categories: discrimination, dignity, privacy, expression, due process); financial (credit decisions, pricing, fraud); reputational (PR exposure from output failures, hallucinations, brand misalignment); regulatory (Article 99 penalty exposure, sectoral overlays); operational/cyber (OWASP LLM Top 10, MITRE ATLAS adversarial techniques, availability/integrity of the AI service); environmental (training-compute carbon footprint, water consumption); ethical (alignment, value-laden outputs, dual-use risks). The AIRA defines appetite per category, the board may accept moderate financial risk and zero physical-safety risk.
  • (2) AI use-case tier. The EU AI Act tier the system falls into: prohibited (Article 5, zero appetite, always); high-risk (Article 6 + Annex III, bounded appetite with Article 27 FRIA and board AI subcommittee approval); limited-risk (Article 50, moderate appetite with transparency obligations); minimal-risk (Article 4 literacy applies; appetite generally permissive). The board declares maximum portfolio share per tier.
  • (3) Autonomy tier. Per the lesson 049 framework, the four-tier autonomy ladder: Tier 1 read-only (suggest-only, human approves every action); Tier 2 bounded action (act within pre-approved allowlist); Tier 3 supervised autonomy (act broadly, human can intervene); Tier 4 autonomous (act independently, human notified post-hoc). The AIRA caps systems per tier, most mature 2026 statements limit Tier 4 to a small, named set of low-consequence systems.
  • (4) Consumer-impact magnitude. The directness of impact on a natural person: consumer-direct (the AI output reaches a consumer with material consequence: credit decision, employment screening, insurance pricing, medical recommendation); consumer-indirect (the output informs an employee who acts toward a consumer); internal-only (the output is consumed by an internal user with no consumer-facing chain). Appetite is typically tighter for consumer-direct, particularly when intersecting Annex III categories.
  • (5) Reversibility. The recoverability of the harm if the system fails: reversible (refund, retry, undo); partially reversible (partial restitution possible but reputational or fundamental-rights damage persists); irreversible (death, loss of liberty, irrevocable benefit denial, public deepfake of a real person, irreversible discrimination embedded in records). The AIRA typically declares zero appetite for irreversible harms in autonomous-action systems.
  • (6) Geographic deployment. The regulatory regimes the system operates under: EU (AI Act, GDPR, Member State implementing laws); UK (PRA SS1/23 for banks, ICO guidance, sectoral); US (state laws, Colorado AI Act, Texas TRAIGA, NYC LL 144; federal sectoral, EEOC, CFPB, FDA); global (other jurisdictions). Appetite differs by jurisdiction because penalty exposure and enforcement maturity differ. The AIRA names the jurisdictions the firm operates in and the appetite differential.
  • (7) Sector exposure. The regulated industries the firm operates in, with their sectoral overlays: financial services (SR 11-7, PRA SS1/23, MiFID II, CFPB UDAAP); healthcare (FDA SaMD, EU MDR, HIPAA); employment (NYC LL 144, EEOC, EU AI Act Annex III §4); education (Annex III §3, Title VI, FERPA); critical infrastructure (Annex III §2, NIS2). The AIRA recognizes that a single AI system in a regulated sector carries compounding obligations.
  • (8) Vendor concentration. The dependence on a single foundation-model or AI-platform provider: single-vendor (>80% of AI workloads on one provider); dual-vendor (40-80% split between two); diversified (no single provider above 40%). Concentration risk has become a board-level concern in 2026: single-provider outages, API deprecations, pricing shifts, and licensing changes can disrupt operations. The AIRA names the concentration ceiling.

The dimensions intersect. A high-risk Annex III §5(b) creditworthiness system that is consumer-direct, irreversible (denying credit damages credit file), operates in EU + UK + US, sector-exposed to financial services, at Tier 2 autonomy, on a 70%-concentrated foundation-model stack, that single system intersects all eight dimensions. The AIRA gives the board the language to declare appetite for each dimension and to evaluate the system against the intersection.

Quantitative KRIs and Red-Amber-Green Thresholds

Qualitative appetite statements ("we are conservative on autonomy") are not auditable. The mature 2026 AIRA anchors each dimension to one or more Key Risk Indicators with red-amber-green thresholds the board ratifies and the Second Line of Defense measures monthly. Examples of the quantitative anchors used in 2026 enterprise AIRAs:

  • Autonomy tier KRI. "Maximum % of AI inventory at Tier 4 autonomy: green ≤2%, amber 2-5%, red >5%. Maximum absolute count of Tier 4 systems: green ≤3, amber 4-6, red ≥7." A breach trips the breach-response protocol.
  • Annex III inventory ceiling. "Maximum % of AI inventory in Annex III high-risk categories: green ≤8%, amber 8-12%, red >12%." Some boards declare absolute caps (e.g., maximum 25 Annex III systems portfolio-wide).
  • Open red-team findings. "Maximum number of unmitigated red-team findings open beyond 30 days: green ≤2, amber 3-5, red ≥6." Aligned with OWASP LLM Top 10 and MITRE ATLAS testing cadence.
  • Vendor concentration. "Maximum % of AI workloads on a single foundation-model provider: green ≤40%, amber 40-60%, red >60%. Maximum % of inventory dependent on a single AI platform: green ≤50%, amber 50-70%, red >70%."
  • Vendor ISO 42001 coverage. "Minimum % of material AI vendors with ISO 42001 certification (or equivalent attested AIMS): green ≥80%, amber 60-80%, red <60%." Drives the vendor-risk policy upgrade lifecycle.
  • Article 73 serious-incident rate. "Maximum serious-incident rate per 100,000 active sessions for any deployed agent: green ≤0.5, amber 0.5-1, red >1." Calibrated against the system's expected use; consumer-direct systems carry tighter ceilings.
  • Fairness disparity ceiling. "Minimum 80% rule selection-ratio compliance across protected groups: green ≥0.90, amber 0.85-0.90, red <0.85." The 80%-rule threshold (0.80) is the regulatory floor; the AIRA declares the firm's stricter internal threshold.
  • FRIA coverage. "Minimum % of Annex III deployer systems with completed Article 27 FRIA: green 100%, amber 90-100%, red <90%." A 100%-green target means any uncovered system triggers a board-level escalation.
  • Article 47 declaration currency. "Maximum number of Article 47 declarations past their renewal due date: green 0, amber 1-2, red ≥3." Tied to the signing-officer accountability framework.
  • Tabletop-exercise cadence. "Minimum number of Article 73 tabletop exercises in the trailing 12 months: green ≥4, amber 2-3, red ≤1."
  • Literacy coverage. "Minimum % of in-scope personnel with Article 4 literacy training completed in the trailing 12 months: green ≥95%, amber 85-95%, red <85%."
  • Aggregate Article 99 worst-case. "Realistic-case Article 99 portfolio exposure: green ≤€50M, amber €50-150M, red >€150M." Calibrated to firm turnover and capital base.

Each KRI is owned by a named Second-Line role (e.g., AI Risk Officer, Model Risk Officer, Vendor Risk Lead, FRIA Program Lead, Incident Response Lead). The AI Governance Committee reviews the KRI dashboard quarterly. The board AI subcommittee reviews semi-annually. The full board reviews annually with the AIRA ratification. Any single red KRI triggers the breach-response protocol within 24 hours.

The Twelve-Section AIRA Template

The mature 2026 AIRA document follows a twelve-section structure. The structure exists so that the regulator, the auditor, the board director, and the AI Governance Committee can each navigate to the section relevant to their role:

  • Section 1 - Preamble + scope. The strategic context (why the firm uses AI, what business value it pursues), the scope (which legal entities, which jurisdictions, which subsidiaries), the relationship to the broader corporate purpose, and the signature line for board chair endorsement.
  • Section 2 - Link to enterprise risk appetite. Explicit reference to the enterprise risk appetite statement, the points of intersection (technology risk, conduct risk, operational risk), and the explicit declaration that the AIRA is additive and AI-specific. Cross-reference to model risk appetite (if maintained separately under SR 11-7) and cybersecurity risk appetite.
  • Section 3 - AI risk taxonomy. The eight-dimension framework defined above, with named definitions and examples. The taxonomy provides the shared vocabulary the rest of the document uses.
  • Section 4 - Appetite by category. The qualitative appetite statement per category in plain English ("we are zero-appetite on Article 5 prohibited; bounded-appetite on Annex III high-risk; permissive on minimal-risk"). The qualitative statements set the tone; the quantitative thresholds in Section 5 set the boundary.
  • Section 5 - Quantitative thresholds + KRIs. The full KRI dashboard structure with red-amber-green thresholds, KRI owners, measurement methodology, data sources, and refresh cadence. The KRI dashboard is the operating instrument the AI Governance Committee reviews quarterly.
  • Section 6 - Escalation paths. Who escalates to whom on amber and red, the escalation timing (24h on red, 5 business days on amber), the documentation requirements, and the integration with the AI Governance Committee charter and the board AI subcommittee charter.
  • Section 7 - Prohibited deployments. The categorical list of deployments the firm will not undertake regardless of business case: any Article 5 prohibited practice; any deployment in a jurisdiction with active enforcement actions against similar use cases; any deployment without completed FRIA on Annex III; any Tier 4 autonomy on consumer-direct irreversible decisions; any deployment using a non-ISO-42001 foundation model on a regulated-sector consumer-direct system without explicit AIGC waiver.
  • Section 8 - Approval gates. The pre-deployment gates per tier: intake form, AI risk assessment, FRIA (where applicable), DPIA (where personal data is in scope), red-team test, conformity assessment (Annex III), AIGC review, board AI subcommittee approval (where required). The gate matrix is the operationalization of the appetite.
  • Section 9 - Reporting cadence to board. The cadence calendar: monthly Second-Line KRI dashboard to AIGC; quarterly AIGC report to board AI subcommittee; semi-annual board AI subcommittee report to full board; annual full-board AIRA ratification. Plus the on-event reporting triggers (regulatory change, major incident, M&A integration, substantial use-case addition).
  • Section 10 - Breach response. The named protocol for a red-line breach: 24h notification, 72h written assessment, immediate-action options, post-breach AIRA recalibration consideration. Detailed in the next section.
  • Section 11 - Review cadence. Annual board ratification (the AIRA is re-signed every year, not just reviewed); semi-annual board AI subcommittee review against KRIs; trigger-based update on substantial change (acquisition, new use-case category, regulatory change, major incident, business-strategy shift). Each refresh cycle has a documented change log.
  • Section 12 - Board signature page. The signature block: board chair; CEO; CRO; AI Officer; audit-committee chair; independent-director designee on the AI subcommittee. The signature date is the AIRA effective date; the next ratification date is twelve months later.

The document is typically 18-32 pages in the L4 mature program. Shorter than that and the KRI thresholds and escalation paths are under-specified; longer and the board will not read it. The accompanying KRI dashboard (a one-page operating summary that the AIGC reviews quarterly) is the everyday operating artifact; the full document is the annual signed reference. A two-page board-facing executive summary is typically prefixed to the front of the document for the annual ratification meeting. It captures the eight dimensions, the highest-priority KRI thresholds, the breach-response trigger summary, and the year-over-year change log. Directors read the executive summary; the AIGC operates from the full document; the Second Line of Defense measures against the KRI dashboard; the Third Line of Defense audits adherence using the full document plus the breach-response history; the regulator examines all four artifacts in any enforcement-readiness inquiry.

Breach-Response Protocol When a KRI Hits Red

A red KRI is not an audit finding to discuss next quarter. It is a board-level governance event. The mature 2026 AIRA names the breach-response protocol explicitly:

  • Within 24 hours of breach detection. Notification to the AI Governance Committee chair and the Chief Risk Officer. Documented in the AIGC incident log. Where the breach is on a KRI tied to a specific deployed system, the system's named accountable executive is notified simultaneously.
  • Within 72 hours of breach detection. Written assessment delivered to the board AI subcommittee. The assessment covers: which KRI breached, what threshold, root cause, impacted systems, downstream regulatory implications (Article 73 incident triggers, sectoral regulator notifications), proposed immediate action, proposed permanent remediation, AIRA implications.
  • Immediate-action options. The protocol names four standard options the board AI subcommittee chooses from: pause (suspend deployment of new instances in the affected tier or category pending remediation); retrofit-with-controls (add compensating controls: additional human review, tighter allowlist, monitoring uplift); partial-shutdown (decommission the worst-offending systems while retaining the broader category); retire (full decommission of the affected systems or pattern). The choice is documented with rationale.
  • Post-breach AIRA recalibration consideration. Within 30 days of breach resolution, the AIGC reviews whether the AIRA threshold needs recalibration. Three outcomes: threshold was correct (no change; the breach reflects operational failure); threshold was too loose (tighten, the breach revealed appetite was higher than the firm should have accepted); threshold was too tight (loosen, the breach reflects a calibration error, not an appetite error). The recalibration goes to the next board AI subcommittee meeting for ratification.

The breach-response protocol is the most-tested element of the AIRA in regulatory examinations. A regulator opening an enforcement action will ask: when did you first breach a KRI; what did you do within 24 hours; what did you do within 72 hours; what did the board AI subcommittee decide; what was the post-breach recalibration; and where is the documentation. An AIRA without a breach-response protocol, or with a protocol that has never been exercised, is a paper artifact, not a governance instrument.

Acme Worked Example - 2026 Q2 AIRA and Q3 Breach

Acme Inc. is a €10B-turnover diversified financial-services firm with retail banking, life insurance, and consumer credit lines. The 2026 Q2 AIRA, ratified by the board on April 22, 2026, contained the following specific statements that became part of the firm's public sustainability report:

  • "We will not deploy any AI system into a use case prohibited under EU AI Act Article 5, regardless of jurisdiction. The CRO maintains the annual negative-assurance attestation."
  • "We will not deploy any Tier 1 high-risk AI (per the firm's autonomy taxonomy aligned with Annex III) without a completed Article 27 FRIA and board AI subcommittee approval."
  • "We accept up to 12% of the AI inventory in Annex III high-risk categories, with no more than 3 systems at Tier 4 autonomy and zero Tier 4 systems on consumer-direct irreversible decisions."
  • "We will not accept vendor concentration above 60% on any single foundation-model provider, measured as inference volume across the rolling-90-day window."
  • "We accept a maximum incident rate of 1 Article 73 serious incident per 100,000 active sessions for any deployed agent."
  • "We will retire any system with fairness disparity exceeding 0.85 on the 80%-rule selection ratio for protected groups defined under applicable employment, credit, and insurance law."
  • "We will not deploy any AI system on a foundation-model provider that is not an ISO 42001 certified entity (or equivalent attested AIMS) without explicit AIGC waiver, documented annually."
  • "We commit a minimum of 0.15% of group revenue to the AI governance program, with annual board approval of the program budget through the AIGC asks slide."

The Q3 breach. On July 18, 2026, the Second-Line KRI dashboard registered a red on the Tier 4 autonomous-count KRI. Three months earlier the count was two; in May, the firm's wealth-management division had launched a portfolio-rebalancing agent at Tier 3; in June, two pilot programs (a customer-service triage agent and an underwriting pre-screen agent) crossed from Tier 3 to Tier 4 after expanded production scope. The board-ratified KRI threshold was: green ≤3, amber 4-6, red ≥7. The portfolio sat at exactly 4 by accident of the rebalancing-agent reclassification, then climbed to 7 when a fourth and fifth pilot transitioned without AIGC awareness.

Within 24 hours. The AI Risk Officer notified the AIGC chair (the CRO) and the Chief Risk Officer at 9:47am on July 19. The incident-log entry referenced KRI-A4-001 (Tier 4 autonomous count) with the threshold breach and the three system-IDs that had transitioned without AIGC review. The named accountable executives for each of the four newly-Tier-4 systems were notified by 11:00am.

Within 72 hours. By 4:00pm on July 21, the written assessment landed with the board AI subcommittee chair. The root cause: a tier-classification process gap where business-line product managers had operational authority to expand agent scope without re-classifying the autonomy tier. The downstream regulatory implications: two of the four Tier 4 systems were Annex III §5(b) creditworthiness adjacencies; an Article 27 FRIA had been completed at Tier 3 scope but not refreshed at Tier 4 scope; Article 73 incident reporting was not yet triggered (no serious incidents had occurred). The proposed immediate action: retrofit-with-controls: re-classify the four systems back to Tier 3 with enforced human-approval gates, refresh the FRIA at the new scope, and re-route the formal Tier 4 transition through the AIGC.

Board AI subcommittee decision. On July 24, the board AI subcommittee met (emergency session called by the chair) and ratified the retrofit-with-controls action plus a partial-shutdown of the wealth-management portfolio-rebalancing agent pending a fresh FRIA. The decision was documented in the subcommittee minutes with the named directors voting.

Post-breach AIRA recalibration. On August 18, the AIGC recommended to the board AI subcommittee that the Tier 4 threshold remain at green ≤3 (the threshold was correct; the breach reflected a process failure, not appetite miscalibration), but that the AIRA add a new operational requirement: any tier transition from Tier 3 to Tier 4 must route through the AIGC with named-director ratification at the next subcommittee meeting. The board ratified the addition at the September 12 quarterly review. The AIRA document version moved from v2026.Q2 to v2026.Q3 with the change log appended.

Audit-defensibility outcome. When the firm's external auditor tested AIRA adherence in October 2026, the breach and the response were a positive finding: the KRI dashboard had detected the breach; the 24h/72h timeline was met; the board AI subcommittee minutes documented the decision; the post-breach recalibration was ratified; and the AIRA version log showed the operational addition. The auditor's report cited the breach response as evidence of operating effectiveness of the AIMS leadership commitment under ISO 42001 Clause 5.

Common 2026 AIRA Mistakes and Cross-Walks

The most common mistakes in 2026 AIRAs are predictable and fixable:

  • (1) Inheriting cybersecurity appetite without AI-specific dimensions. The firm declares "AI risk is covered by our technology risk appetite": but technology risk appetite does not address autonomy, Annex III tiering, vendor concentration on foundation models, or fundamental-rights exposure. Fix: write a standalone AIRA that cross-references but does not collapse into the technology statement.
  • (2) Qualitative statements without KRIs. The AIRA says "we are conservative on autonomy" but offers no measurable threshold. Fix: every qualitative statement is anchored to one or more quantitative KRIs with red-amber-green thresholds.
  • (3) No breach-response protocol. The AIRA defines the thresholds but is silent on what happens when one is breached. Fix: write Section 10 with the 24h/72h/immediate-action/recalibration sequence.
  • (4) No Annex III mapping. The AIRA discusses "high-risk AI" generically without mapping to the eight Annex III categories. Fix: Section 4 declares appetite by Annex III §1-§8 with the portfolio share per category.
  • (5) No autonomy-tier framing. The AIRA discusses "AI" in aggregate without distinguishing read-only suggestion systems from autonomous-action agents. Fix: use the four-tier autonomy ladder and declare per-tier ceilings.
  • (6) No vendor-concentration ceiling. The AIRA omits the foundation-model provider concentration dimension. Fix: name the ceiling (typically 60% on inference volume) and the diversification expectation.

Regulatory cross-walks. EU AI Act: Article 5 (zero-appetite prohibited deployments); Article 6 + Annex III (high-risk tiering for appetite by tier); Article 9 (risk management system, the AIRA is the strategic instrument under which the Article 9 risk management system operates); Article 17 (QMS, strategic compliance is the AIRA); Article 26 (deployer obligations cross-referenced); Article 27 (FRIA gate for high-risk deployer systems); Article 51 (GPAI provider thresholds informing vendor-concentration KRIs); Article 73 (serious-incident KRI). NIST AI RMF: Govern 1.1 (legal and regulatory requirements documented, the AIRA is the document); Govern 1.2 (trustworthy AI characteristics in policy); Govern 2.1 (roles and responsibilities, KRI owners); Govern 3.1 (workforce diversity in AI risk teams); Govern 4.1 (organizational culture and risk tolerance, the AIRA defines tolerance); Govern 5.1 (engagement with relevant external parties, the AIRA is publishable). ISO 42001: Annex A.3 (organizational roles); Annex A.5 (resources); Clause 5 (leadership and commitment); Clause 6 (planning); Clause 9 (performance evaluation, the KRI dashboard). SR 11-7 + PRA SS1/23: governance pillar, the board approves model risk appetite, and AI risk appetite is the natural extension.

Penalty exposure. Article 99(2) at €35M / 7% of global turnover for any Article 5 prohibited-deployment exposure, and a board-signed AIRA that explicitly declares zero appetite for Article 5 is the leadership-commitment evidence the regulator looks for. Article 99(3) at €15M / 3% for Article 17 (QMS strategic compliance) and Article 26 (deployer obligations) failures, an absent AIRA escalates the regulator's view of the QMS deficiency and increases the multiplier on the penalty. Article 99(5) at €7.5M / 1% for misleading information, including misleading governance disclosures where the AIRA is referenced publicly but is not in fact ratified or operating.

The 2026-2027 outlook. The European Commission AI Office, the national market-surveillance authorities preparing for Aug 2, 2026 enforcement go-live, the Federal Reserve and OCC examining bank AI portfolios under SR 11-7, the Bank of England PRA examining UK firms under SS1/23, and the certification bodies issuing ISO 42001 attestations all converge on the same artifact: the AI Risk Appetite Statement is the leadership evidence that AI governance is operating, not declared. Firms that ratify an AIRA in 2026 with operating KRIs and tested breach-response history establish the regulatory benchmark; firms that defer the AIRA to 2027 face the harder posture of explaining the absence to an active examination.

Key Takeaways

  • The AI Risk Appetite Statement (AIRA) is a board-ratified, written declaration of the level and type of AI risk the firm will accept: distinct from cybersecurity, operational, and model risk appetite statements; the leadership artifact ISO 42001 Clause 5, NIST AI RMF Govern 1.1, EU AI Act Article 17(1)(b), and SR 11-7 + PRA SS1/23 expect.
  • Eight orthogonal dimensions define mature 2026 appetite: risk category; AI use-case tier (prohibited/high-risk/limited/minimal); autonomy tier (1-4); consumer-impact magnitude; reversibility; geographic deployment; sector exposure; vendor concentration.
  • Every qualitative statement must be anchored to a quantitative Key Risk Indicator with red-amber-green thresholds: Tier 4 count, Annex III inventory share, open red-team findings, vendor concentration %, fairness disparity ceiling, Article 73 incident rate, FRIA coverage %, aggregate Article 99 worst-case.
  • The 12-section AIRA template runs preamble → enterprise risk link → taxonomy → appetite by category → KRIs → escalation → prohibited deployments → approval gates → reporting cadence → breach response → review cadence → board signature page.
  • The breach-response protocol is non-negotiable: 24h notification to AIGC chair + CRO; 72h written assessment to board AI subcommittee; four immediate-action options (pause / retrofit-with-controls / partial-shutdown / retire); 30-day post-breach AIRA recalibration consideration.
  • Review cadence is annual board ratification with re-signature, semi-annual board AI subcommittee review against KRIs, and trigger-based update on substantial change (acquisition, new use-case, regulatory change, major incident, strategy shift).
  • Common mistakes in 2026 AIRAs: inheriting cybersecurity appetite; qualitative-only statements; no breach response; no Annex III mapping; no autonomy framing; no vendor concentration ceiling, each is fixable in a single AIRA refresh cycle.
  • Penalty exposure for an absent or paper AIRA: Article 99(2) €35M / 7% on Article 5 escalation; Article 99(3) €15M / 3% on Article 17 + 26 + 27 + 73 failures multiplied by absent leadership commitment; Article 99(5) €7.5M / 1% on misleading governance disclosure where the AIRA is referenced but not operating.