Ben Pirt, Principal Technologist at Made Tech, explains why the new Made Tech AI Risk Assessment Framework has been developed and how it helps teams understand the risks and make sensible decisions about using AI on government projects.
There is plenty of appetite to use AI at the moment, both from clients and from the people delivering projects. But when somebody actually asks for permission to use it, the safest answer can still be no.
That is often because the person making the decision doesn’t have a straightforward way to understand the risks involved. And that was the starting point for Made Tech’s new AI Risk Assessment Framework.
We wanted something that would help teams work through what the AI risks actually are, how serious they might be and what could be done about them. Importantly, it also gives the person signing it off something useful to make a decision with.
Different uses, different risks
Using AI to analyse some code or getting it to process research transcripts is very different from building an AI-enabled feature into a public service. The risks change depending on what you are doing, what information is involved and how much freedom you are giving the AI to act.
The framework covers common uses including software development, live service support, user research, design and business analysis. Teams document what information they’re sharing, check the tool they intend to use and work through the eight risk areas, covering things such as data leakage, hallucinations, bias, security and licensing.
There’s also a less obvious risk around people becoming over-reliant on AI. If the answer to every problem becomes asking an AI tool to produce something, people can miss the learning that comes from working things out themselves.
Actually writing the risk down
For each relevant risk, the team looks at the likelihood of something going wrong and the impact if it did. They consider how much autonomy the AI has, decide what safeguards are needed and then assess the risk that remains.
It sounds quite involved, but a straightforward assessment can be worked through relatively quickly. AI itself can even help teams think through some of the questions.
The important bit is that there’s a record of the thinking. Instead of asking someone to approve something they can’t really see, teams can show them the risks, explain what they’re doing about them and address any concerns.
It’s useful further down the line too. If a service assessment asks what has been done about hallucinations, for example, the team can show its assessment and explain the mitigations. There’s a big difference between saying something will probably be fine and demonstrating that you’ve actually thought about it.
Built to be used
We’ve deliberately made this a practical framework rather than an abstract piece of AI policy. It comes from the reality of trying to use AI on government projects, where teams want to make progress but also need to be sure they’re not introducing risks they haven’t properly understood.
The framework is already being used on project work and we’re starting to use it more widely across Made Tech. We’ve also released it under an open licence so other government departments, suppliers and delivery teams can pick it up and use it themselves.
This is the first version, and we expect it to change as AI evolves and we learn more. We’d welcome feedback, critique and suggestions from people using it on their own projects, particularly if they find things we’ve missed or ways of making it more useful.