# AI Writing Task Risk Assessment

Decide whether and how AI may assist a writing task by evaluating data, factual, audience, rights, security, misuse, and accountability risks.

## Usage note

Assess the specific task, tool, data, audience, and output use together. An approval for low-risk outline ideas does not automatically authorize confidential inputs, automated publication, or consequential advice.

## How to use this template

1. Break the proposed workflow into concrete AI and human steps with outputs and decision points.
2. Classify inputs, audience, claims, scale, reversibility, and consequence for each AI-assisted step.
3. Identify privacy, security, rights, factual, fairness, misuse, and accountability risks.
4. Select a decision and specify enforceable safeguards, evidence checks, owners, and stop conditions.
5. Approve a time-bounded pilot or use case, monitor incidents, and reassess on material change.

## Blank template

### Task and workflow

- **Project and task ID:** [Enter]
- **Proposed AI step:** [Describe narrowly]
- **Human steps before and after:** [Describe]
- **Tool/service and account type:** [Enter]
- **Output audience and channel:** [Enter]
- **Scale and frequency:** [Enter]
- **Can a person reject before use?:** [Yes / No / Partly]
- **Consequence of a plausible error:** [Describe]

### Input and output risk

- **Input data classes:** [Public / Internal / Confidential / Personal / Regulated / Security]
- **Rights or license limits:** [Describe]
- **Retention, training, and sharing status:** [Verified facts or Unknown]
- **Material claim types:** [Product / Health / Legal / Financial / Safety / Other]
- **Affected or vulnerable groups:** [Describe relevant context]
- **Identity or impersonation concern:** [Describe or None]
- **Foreseeable misuse:** [List]
- **Irreversible or high-scale effect:** [Describe]

### Risk and safeguard record

Duplicate per material risk.

- **Risk scenario:** [Cause, event, impact]
- **Likelihood evidence:** [Low / Medium / High and basis]
- **Impact:** [Low / Medium / High and basis]
- **Existing control:** [Describe]
- **Additional safeguard:** [Redact / Restrict / Verify / Review / Log / Other]
- **Control owner and test:** [Name, evidence]
- **Residual risk:** [Describe]

### Decision and monitoring

- **Decision:** [Prohibit / Redesign / Pilot / Approve with controls / Approve]
- **Permitted tool and data:** [Exact scope]
- **Prohibited behavior:** [List]
- **Required review and approver:** [Who checks what]
- **Disclosure and provenance:** [Requirements]
- **Stop conditions:** [Incident, failure rate, data change, other]
- **Approval owner and expiry:** [Name/date]
- **Monitoring and incident route:** [Enter]
