Global AI Assurance · Layer 08

    AI Systemic Risk Monitor

    An AI failure is rarely local. The same model, the same framework and the same inference infrastructure sit beneath controls that were designed as if they were independent. The systemic view reads incidents and dependencies together, at four levels.

    Within the institution

    One provider, one framework or one tool server sitting beneath controls that were assumed to be independent.

    Across the group

    Subsidiaries choosing the same model for the same function, so a single withdrawal degrades every entity at once.

    Across the market

    Peers concentrating on the same inference infrastructure, which turns a vendor event into a sector event.

    Across the supervisor

    A regime that assumed diversity in a layer where none exists, which is where policy attention arrives next.

    Concentration reads

    Illustrative readings from a sample estate. Each one is a resilience question before it is a procurement one.

    Critical workflows resting on a single model provider

    73 per cent of the sample estate

    Single-provider withdrawal is a service-continuity event, not a procurement one.

    Critical agents on one tool-server dependency

    41 agents

    One infrastructure fault removes a set of controls simultaneously.

    Inference performed outside the home jurisdiction

    28 per cent of governed calls

    Residency and compellability questions apply to more of the estate than the register shows.

    Embedded models with no institutional owner

    39 systems

    Obligations exist with nobody assigned to discharge them.

    Where it lands

    Concentration, drift, autonomy and incident history do not produce a separate AI score for the board. They move the institution's resilience position, through the AI and Agentic Resilience dimension.

    Model dependencyAgent autonomyTool accessData permissionsHuman oversightModel driftAgent driftProvider concentrationThird-party dependencyCyber exposureIncident historyRecovery capabilityFallback modelEvidence freshnessControl effectiveness