Risk Management

Know which AI risks you carry, what holds each one down, and when it is due for another look.

A risk assessment written once for an audit goes stale the week the agent gets a new tool. Praesidia keeps the AI risk register next to the systems it describes, records the EU AI Act risk tier of each agent, flags every review that runs past its date, and reopens a classification when the system changes.

Risk register · Claims Triage AI system Illustrative
Support agent can read full customer recordsData privacy · residual risk medium · 3 mitigations
Review overdue
Triage agent ranks claims for payout priorityDiscrimination · residual risk high · 8 of 8 dimensions assessed
Review due 12 Jan
Agent can call the payments tool without a second approverAutonomy · residual risk low · 2 mitigations
Review due 03 Mar

Each row names the system it belongs to, what keeps it in check, the risk that is left, and the day it next needs a reviewer.

What you get

Three things the register gives you

Risks tied to real systems

Each risk sits against the AI system, asset or agent it describes, so a reviewer starts from the system and not from a spreadsheet tab.

The risk that is left, stated

Every entry says what remains after its mitigations, so the register answers the question an assessor actually asks.

Reviews that come back on time

A passed review date is flagged, and a material change to the system reopens its classification instead of waiting for the calendar.

How it works

Classify, register, rate, review

  1. 1

    Classify each agent against the EU AI Act's risk tiers from a short questionnaire about what it is used for and the safeguards around it.

  2. 2

    Register the specific risks for each AI system or asset: the category, what could go wrong, and the mitigations in place.

  3. 3

    Rate the dimensions you have evidence for and the residual risk that remains.

  4. 4

    Set a review date. Overdue reviews are flagged, and a classification that falls due prompts your team to reassess it.

  5. 5

    When the system changes in a way that matters, its classification is reopened for review.

Technical details

What the register records, and where it stops

An entry in the risk register
Each entry in the AI risk register records one specific risk against the AI system, asset or agent it belongs to — a risk category (data privacy, discrimination, safety, security, transparency or autonomy), what could go wrong, the mitigation measures in place, and, where there is one, the incident that raised it.
Residual risk and the eight dimensions
Every risk carries a residual risk level of low, medium or high — what remains once its mitigations are in place — and can be rated on eight dimensions: impact, likelihood, autonomy, data sensitivity, privilege, external exposure, regulatory impact and business criticality. A dimension nobody has assessed is shown as not assessed, never quietly counted as low.
EU AI Act risk classification
Agents, MCP servers and applications can each be classified into one of the EU AI Act's four risk tiers — unacceptable, high, limited or minimal — from a questionnaire about what the system is used for and the safeguards around it, or from a first-pass automatic classification you then review. Each classification records a compliance status and a tracked remediation plan. Classification is a plan feature; see pricing.
Review dates and reassessment
Every risk and every classification carries a review date. A risk past its date is flagged as review overdue in the register; a classification past its date moves to due and then overdue, and your organization is notified to reassess it. By default, a material change to an AI system — a new model, new tools, a new data source, wider permissions or more autonomy — reopens its classification for review before that date comes round.
What it is not
A classification records your assessment and the platform's first pass. It is not legal advice or a conformity assessment, and it does not by itself make a system meet the EU AI Act's requirements.

Read the docs: the AI agent risk register · EU AI Act risk classification. Then: runtime security · audit & evidence.

Put your first AI system on the register

Start with one workspace, one agent and the risks you already know about.