THE FRAMEWORK
Traditional ERM was built for risk that behaves deterministically, with failures that leave a traceable causal chain. AI breaks both assumptions. EW-AiRM™ is the layer that closes the gap, built to augment what you already run, not replace it.
ARCHITECTURE
Most AI risk frameworks pick a level and stay there: EW-AiRM™ deliberately spans three layers, because the strategic questions cannot be answered with operational tools alone, and the operational layer cannot anticipate Black Swans. And the HAiPECRTM ethical filter running across all of them. With a AI controls library drawn from over 800 evidence-based mitigations, not just asserted from first principles.
LAYER 1
Six pillars. Necessity, readiness, maturity, tolerance, governance and accountability, through-the-lifecycle monitoring. Sets the conditions any AI deployment has to meet before it goes live.
Can also be applied retrospectively, as part of an enterprise's AI maturity assessment.
Complemented by HAiPECRTM, the ethical filter: the same seven questions asked at every significant AI decision, across all three layers, aligned to UNESCO's 2021 Recommendation.
LAYER 2
MIT AI Risk Repository (CC BY 4.0): more than 1,000 risks across 7 domains and 24 subdomains.
Mapped to 831 controls in 4 quadrants (Governance & Oversight, Technical & Security, Operational Process, Transparency & Accountability).
For control mappings in Primary, Secondary, and Tertiary tiers.
This layer does not ask organisations to build an AI risk taxonomy from scratch; it gives practitioners the evidence base and the tools to apply it.
LAYER 3
Eight 人工智能黑天鹅类别 -governed, governed through Robust Foundations, Continuous Sensing, Adaptive Response.
Includes multi-agent emergence and the quantum cryptographic transition (NIST FIPS 203/204/205).
For risks that do not fit the operational taxonomy.
The response to unknown unknows is resilience, not prediction.
FLOOR CONDITIONS : The 5 Non-Negotiables
1
Named accountability for every deployed AI system
2
HAIPECR run as a pre-deployment filter, documented
3
Human override capability tested with a 4-hour SLA
4
Documented board or executive risk acceptance
5
Incident reporting pathway, with named recipient
STRATEGIC LAYER
Each pillar is a question the organisation must answer in writing before a system can be deployed, and a check that must hold across the deployment lifecycle.
P-I
Strategic Alignment
+ Necessity Assessment
Is AI the right tool for this problem at all? If a deterministic system would do the job, AI is the wrong answer.
P-II
P-III
Technological Maturity
Is the underlying model, vendor, and integration pattern ready for this use case at this risk level?
P-IV
Risk Tolerance
Has the board signed off on the residual risk, and is the tolerance documented at the right level of granularity?
P-V
Governance & Accountability
Who owns the decision, and who owns the incident? Named, not implied.
P-VI
Through-the-Lifecycle Monitoring
+ Adaptability
What changes trigger a re-review? Who runs the re-review? What is the kill-switch SLA?
道德覆盖
HAIPECR is the ethical filter that runs across all three layers. Mapped to the UNESCO 2021 Recommendation on the Ethics of AI (10 core principles, not 9). Listed on the OECD AI Policy Observatory since April 2023.
Human oversight - Named accountability, override tested.
Accountability - mapped to UNESCO P5.
Inclusivity - an embedded prerequisite,
not a pillar. (Hence, the lowercase "i").
Privacy - Data protection, safety, security.
Ethics - Explainability, Transparency, fairness, non-discrimination.
Conduct - based on the Universal Conduct Risk Paradigm (UCRP).
Resilience - Sustainability, intergenerational rights.
UNESCO MAPPING:
H → P7 Human Oversight
A → P5 Accountability
i → P4 Multi-stakeholder Governance + P9 Awareness & Literacy
P → P3 Privacy + P2 Safety & Security (+ 2024 UNESCO Neurotech)
E → P6 Transparency & Explainability + P10 Fairness
C → P1 Proportionality / Do No Harm
R → P8 Sustainability
UNESCO MAPPING: H → P7 Human Oversight A → P5 Accountability i → P4 Multi-stakeholder Governance + P9 Awareness & Literacy P → P3 Privacy + P2 Safety & Security (+ 2024 UNESCO Neurotech) E → P6 Transparency & Explainability + P10 Fairness C → P1 Proportionality / Do No Harm R → P8 Sustainability
RESILIENCE LAYER
EW-AiRM identifies eight distinct AI Black Swan categories.
Each has discrete characteristics, a distinct reason for unpredictability, and a separate governance response.
The categories are not mutually exclusive: multiple categories can interact, amplifying each other’s effects in ways that make the combined event more severe than any category alone:
Characteristic:
Foundation models exhibit unexpected capabilities not explicitly trained or designed into the system. These capabilities emerge from the complex interactions of billions of parameters in ways that are not predictable from the model’s specification.
Why unpredictable:
Models have billions of parameters; behaviour emerges from complex parameter interactions that cannot be fully predicted even by the engineers who built the system. Capability emerges at scale thresholds that are themselves unpredictable.
Governance response:
Pls get in touch with us to identify suitable response strategies or check out Chapter 14 in the EW-AiRMTM Book.
Characteristic:
Failure of a central AI infrastructure element (most prominently a major foundation model provider, but also cloud GPU providers, AI accelerator providers, and vector database providers as the AI stack matures) cascades across thousands of dependent applications simultaneously, creating economy-wide disruption rather than isolated organizational failures.
Why unpredictable:
The scale of dependency across the ecosystem is unknown until failure occurs. Individual organizations assess their own dependency, but no single governance actor has visibility into the aggregate dependency across the entire financial system, healthcare system, or other critical sector.
Governance response:
Pls get in touch with us to identify suitable response strategies or check out Chapter 14 in the EW-AiRMTM Book.
Characteristic:
A model pursues its specified objectives in ways that are harmful because the optimization process has found a path to the objective that was not anticipated by the system designers. The model does exactly what it was optimized to do. But the optimization produced unintended consequences.
Why unpredictable:
It is difficult to anticipate all the ways in which an optimization process could find a path to an objective that causes harm. The optimization is mathematically correct; the problem is the gap between the specified objective and the intended one. Frontier AI safety research from Anthropic, OpenAI, Google DeepMind, and the UK and US AI Safety Institutes has documented that this gap widens rather than narrows as model capability increases, making alignment failure a structurally growing risk rather than a problem that improves with technical maturity.
Governance response:
Pls get in touch with us to identify suitable response strategies or check out Chapter 14 in the EW-AiRMTM Book.
Characteristic:
Unexpected and harmful behaviours emerge from the combination of text, image, audio, and other AI modalities in a system, where the individual modalities have been individually assessed as acceptable, but their combination creates compound effects that were not present in either alone.
Why unpredictable:
The interactions between modalities are difficult to predict from analysis of individual modalities. Biases that are individually manageable may compound in ways that produce qualitatively more severe harm when modalities interact.
Governance response:
Pls get in touch with us to identify suitable response strategies or check out Chapter 14 in the EW-AiRMTM Book.
Characteristic:
A novel attack technique is discovered that defeats existing AI defences across the industry: not just one organization’s defences, but the fundamental approaches that all major systems have implemented.
Why unpredictable:
The attack surface of AI models is enormous, and new attack angles are always possible. When a new attack technique is discovered that exploits a fundamental property of the model architecture (for example, the next-token-prediction objective that all language models share, or the gradient-based optimization that all neural networks use), it may work against all models with that architecture regardless of individual defensive measures.
Governance response:
Pls get in touch with us to identify suitable response strategies or check out Chapter 14 in the EW-AiRMTM Book.
Characteristic:
Failure or attack in the AI supply chain (training data, model libraries, compute infrastructure, or data annotation services) propagates downstream and compromises all systems built on that supply chain component.
Foundation model provider risk is treated separately as Category 2 (Systemic Concentration); Category 6 covers the upstream and infrastructure layers of the AI supply chain.
Why unpredictable:
Supply chains are complex and their vulnerabilities are hidden until exploited. Malicious actors who understand the supply chain can introduce vulnerabilities at points that affect hundreds of downstream systems simultaneously.
Governance response:
Pls get in touch with us to identify suitable response strategies or check out Chapter 14 in the EW-AiRMTM Book.
Characteristic:
Failure or harmful behaviour emerges from the interaction between two or more AI systems acting on each other’s outputs, where each system was individually evaluated as acceptable, but the interaction produces compound effects, cascading authority transfer, or coordinated behaviour that no single system was designed to produce. The failure is a property of the interaction, not of any individual agent.
Why unpredictable:
Multi-agent interactions create a combinatorial space that cannot be exhaustively pre-evaluated. Each agent’s behaviour is bounded; each agent’s interaction with another agent is bounded; the combination of N agents interacting across M tools and K decision points produces a behaviour space that exceeds practical evaluation capacity. Emergent behaviours, including coordination, deception, and goal drift, have been documented in research environments and are increasingly observed in production agentic deployments. Traditional safety evaluation evaluates one agent at a time; multi-agent emergent failure is invisible to that evaluation methodology by construction.
Governance response:
Pls get in touch with us to identify suitable response strategies or check out Chapter 14 in the EW-AiRMTM Book.
Characteristic:
A cryptographically relevant quantum computer becomes available (either
through gradual capability development or a discontinuous breakthrough), and the cryptographic foundations of AI infrastructure become simultaneously vulnerable: standard cryptographic surfaces (TLS, API authentication) and AI-specific cryptographic dependencies (model weight integrity verification, audit trail signing, supply-chain attestation through model signing) across the entire deployed AI estate.
Separately, previously-exfiltrated encrypted data (acquired via the HNDL attack) becomes decryptable retroactively.
Why unpredictable:
The Q-Day timeline is bounded but uncertain. Expert estimates from the Global Risk Institute Quantum Threat Timeline Report (Mosca and Piani 2024) and equivalent sources cluster around 2034–2036 with considerable tail risk extending from the late 2020s into the 2040s. A breakthrough in quantum error correction, a new qubit modality reaching scale, or a classical algorithmic attack on post-quantum schemes could shift the timeline discontinuously.
Governance response:
Pls get in touch with us to identify suitable response strategies or check out Chapter 14 in the EW-AiRMTM Book.
WHERE THIS COMES FROM
EW-AiRM™ is grounded in publicly licensed standards: the MIT AI Risk Repository (CC BY 4.0), the UNESCO 2021 Recommendation on the Ethics of AI, NIST AI RMF, ISO 31000 (general risk), ISO 42001 (AI risk management systems), and the UNECE (ECE/TRADE/486, 2024). HAIPECR was originated by Prof. Markus Krebsz and has been listed on the OECD AI Policy Observatory since April 2023.
Here's a comparsion of EW-AiRMTM with those other frameworks and the EU AI Act:
| Dimension | EW-AiRM™ | NIST AI RMF | ISO 42001 | COSO ERM | EU AI Act |
|---|---|---|---|---|---|
| UNECE-grounded | Yes (ECE/TRADE/486) | No | No | No | No |
| Primary scope | Enterprise-wide AI Risk Governance framework & approach | AI Risk Management | AI Management System | (Traditional) Enterprise Risk Management | AI Regulation |
| Target audience | Boards, Risk functions, CTOs, CISO, Risk community | US Federal & Enterprise | Any organisation | CFO, Board, ERM teams | Operators & Providers (EU) |
| Layers | Strategic, Operational, 韧性 + HAiPECR | Govern, Map, Measure, Manage | Plan, Do, Check, Act | Strategy, Performance | Prohibited, High-risk, GPAI |
| Certifiable | No (Open framework) | No (Voluntary) | Yes (ISO audit) | No (Guidance) | Public, EU-wide Regulation |
| Open / free | Yes (CC BY 4.0 base) | Yes | Paid standard | Paid guidance | Public regulation |
| UNESCO-aligned | Yes (HAiPECR) | No | Partial | No | Partial (GPAI) |
The framework is the conceptual picture. The three-tier comparison shows what it looks like in deployment.
人类人工智能学院 是一个独立的思想/行动智库,召集关于人工智能治理的多边和多方利益相关者对话。该研究所与联合国、联合国教科文组织、经合组织、欧盟委员会和世界各国政府进行合作。
之家 EW-AiRM™ — 一个开放的、三层的企业级人工智能风险管理框架,基于公开许可的标准,并与联合国教科文组织、联合国欧洲经济委员会、美国国家标准与技术研究院、国际标准化组织和欧盟人工智能法案保持一致。
商业咨询、培训和咨询服务由以下机构提供: De-Risking Solutions Ltd. 和 RiskAi.Ai
人工智能与技术解决方案
人工智能、代理工具和技术解决方案由...提供 Human-Ai.Solutions.
人类人工智能学院
由...运行和维护
De-Risking Solutions Ltd.
电子邮件:
contact [at] human-ai.institute
已列入经合组织人工智能政策观察站 · 联合国大学人工智能网络创始成员 · 符合教科文组织、UNECE WP.6、NIST 和 ISO 42001 标准
EW-AiRM™ 和 HAiPECR™ 是 De-Risking Solutions Ltd. 在英格兰和威尔士注册的商标(公司编号 09900565)。保留所有权利。
© 2026 人工智能学院。