FISTA Solutions does not load Google Analytics until you accept. Rejecting keeps optional analytics off. Read the Cookie Policy.

All field notes

Leadership ¡ 4 minute read

How to Set AI Risk Appetite

AI risk appetite is the executive statement of how much and what kind of AI risk the company will accept, expressed concretely: which actions agents may take alone, which errors are tolerable at what rate, which data may leave the environment, and which lines are never crossed. Written this way, engineers can enforce it and boards can oversee it.

By FISTA Solutions¡ AI-Native Engineering Team¡
How to Set AI Risk Appetite article cover

Every AI decision that reaches an executive is, underneath, a question about risk appetite: how wrong may the system be, how much may it do alone, and what may never happen. When appetite is unstated, each decision is negotiated from scratch and the program slows to the pace of the most cautious voice in the room. This guide shows leaders how to set AI risk appetite in terms that can be enforced, mapped to controls, and reviewed on evidence.

Why does an explicit appetite speed things up?

Because it converts case-by-case negotiation into rules. A team that knows "reversible internal actions may run autonomously above a stated pass rate, customer-facing actions need approval until agreement exceeds a stated level, and these actions are never automated" can design, build, and deploy without escalating. Security and legal can review against the statement rather than reopen first principles. The board can oversee something written. FISTA's AI risk management guide covers the wider framework; this piece is about the appetite statement itself.

What should the appetite cover?

Risk categoryAppetite statement answersEnforced by
AutonomyWhich action classes may run without a person, at which consequence tier, above what evidencePermissions and approval gates per tier
Error toleranceWhat error rate is acceptable for which output destinationsEvaluation thresholds; release gates
DataWhat data classes may be sent to which models under which terms; what never leavesGateway classification rules; redaction; deployment choices
SpendBudget and rate limits per agent; what triggers a stopGateway budgets; stop conditions
Vendor concentrationHow much dependence on one model or provider is acceptableTested alternatives; routing
Prohibited actionsWhat agents may never do regardless of evidenceAbsent permissions; policy lines

The executive guide to AI agent governance describes the tiering that the appetite statement attaches to.

How should it be written?

As specific, testable statements. Compare:

  • Unenforceable: "We take a balanced approach to AI risk and prioritize customer trust."
  • Enforceable: "Tier 1 actions (internal, reversible, no sensitive data) may run autonomously once the evaluation pass rate exceeds the stated threshold over the stated volume. Tier 2 actions (customer data, financial records) require approval until reviewer agreement exceeds the stated level over the stated volume, after which sample review applies. Tier 3 actions (external commitments, payments above the threshold, regulated decisions) require approval permanently. No personal data of the stated classes is sent to external models."

The second version tells engineers what to build, auditors what to test, and the board what to oversee. The exact thresholds are the company's decision; the structure is what matters.

How does appetite map to autonomy and controls?

Appetite sets the ceiling for each tier; evidence determines where each agent sits beneath it. An agent earns autonomy through agreement rates, pass rates, and incident history, up to the ceiling appetite allows and no further. Controls are the mechanism: permissions and gates enforce the autonomy ceiling, evaluation thresholds enforce error tolerance, gateway rules enforce data appetite. The how much autonomy should AI agents have guide describes the evidence side; the AI guardrails explained for executives piece describes the control side.

Which lines sit outside appetite?

Some prohibitions are not risk-appetite decisions; they are policy or law. Regulated decisions with legal effect on individuals, legal and contractual commitments, communications in a crisis, and anything that would breach a regulatory obligation are held regardless of how confident the evidence becomes. Name them separately, so nobody argues that strong evidence should move them. This is general guidance, not legal advice; the specific lines depend on jurisdiction and sector.

How is appetite reviewed?

Annually; after any material incident; when regulation changes; and when the evidence base suggests a tier's ceiling is wrong in either direction. Each review cites the operating record: incidents by tier, evaluation trends, autonomy changes made, and near misses. Appetite that is never loosened as evidence accumulates leaves value on the table; appetite that is never tightened after incidents is not being governed. The AI risk register guide provides the record the review draws on.

What should executives ask?

  • Is our AI risk appetite written as enforceable statements, or as principles?
  • Which agent permissions and gates implement it, and could we show an auditor the mapping?
  • What error rate have we accepted for customer-facing outputs, and is it measured?
  • Which lines are held by policy regardless of evidence?
  • When was appetite last reviewed, and what evidence was cited?

How can FISTA Solutions help?

FISTA Solutions works with executive, risk, and security teams through its AI enablement practice to write risk appetite in enforceable terms and map it to tiers and controls, and builds AI agents whose permissions, gates, thresholds, and data rules implement the statement directly. Since 2017, FISTA has delivered 150+ projects for 50+ companies across 12+ countries.

To turn your AI risk principles into a statement engineers can enforce, talk to FISTA on WhatsApp, or read the AI oversight for boards whitepaper for how directors should oversee it.

Share-ready article cover

Download the generated social format.

Download cover

Clear answers

Questions raised by this field note.

Straightforward guidance for evaluating scope, fit, and the next step.

01What is AI risk appetite?

The amount and type of AI-related risk the company will accept to achieve its objectives, stated concretely enough to guide decisions: which actions agents may take without a person, what error rates are acceptable for which outputs, what data may go to which models, and which actions are prohibited. Executives set it; the board oversees it.

02How should AI risk appetite be written?

As specific, testable statements by risk category and consequence tier: for example, agents may act autonomously on reversible internal actions with an evaluation pass rate above a stated threshold; customer-facing communications require approval until agreement exceeds a stated level; no personal data of a given class leaves the environment. Vague statements cannot be enforced.

03Who sets AI risk appetite?

The executive team, with input from risk, security, legal, and the business, and with board approval where AI is material. The CEO owns the overall statement; functional executives own the appetite for their processes within it; engineering implements it as permissions, gates, thresholds, and data rules.

04How does risk appetite relate to AI agent autonomy?

Appetite defines the ceiling on autonomy for each consequence tier; evidence determines where each agent sits below that ceiling. An agent can earn autonomy up to what appetite allows, and no further. When appetite changes, the ceilings change, and agents are reviewed against the new limits.

05How often should AI risk appetite be reviewed?

Annually as a matter of course, after any material incident, when regulations change, and when the evidence base matures enough that a tier's ceiling looks too conservative or too loose. Reviews should cite evidence: incident history, evaluation trends, and the operating record since the last review.

Start with the hard problem

Need the outcome owned, not merely analyzed?

Tell us where delivery is constrained. We’ll map the fastest credible path from intent to verified production.

Start a project