News / August 2026

AI Risk Governance: A Structured Approach for Investors and Corporate Boards

A new CLTC white paper explores how investors and other stakeholders can better understand financial risks related to companies’ development and use of artificial intelligence (AI). The report, “AI Risk Governance: A Structured Approach for Investors and Corporate Boards,” introduces a novel approach for categorizing AI risks related to financial performance, cybersecurity and privacy, reputational loss, and other factors.

The report was authored by Oumou Ly, who conducted the research while serving as a non-resident fellow with CLTC’s AI Security Initiative (AISI). Ly previously served as the Senior Advisor for Technology and Ecosystem Security at the White House. She was an architect of President Biden’s 2023 AI Executive Order and played a central role in developing and implementing the National Cyber Workforce and Education Strategy and the National Standards Strategy for Critical and Emerging Technologies.

Between March-October 2025, Ly conducted interviews with more than 20 corporate, venture capital (VC), and equity investors, with a goal to assess current AI investment and risk management practices, identify gaps in existing approaches, and determine where additional guidance is needed. In December 2025, Ly worked with the AISI to convene a private roundtable of more than 50 asset owners and allocators, AI security researchers, and representatives from leading AI development labs to refine the early research findings.

A figure showing the different types of AI-related risks that can arise for investors — and how they frequently overlap.

“Investors need methods to determine which companies can successfully scale AI-native businesses, provide or capture efficiency gains from AI integration, and avoid value-harming risks, such as reputational impacts, cybersecurity and privacy incidents, and poor financial performance,” Ly explains in the report’s introduction. “This report provides an initial approach to help investors better understand value-harming risks in the context of AI, as well as how to partner with companies to mitigate them.”

Ly notes that while the paper is primarily geared toward practitioners, including fund and asset managers and their investment, stewardship, and diligence teams, as well as the advisors who support them, it may also be of benefit to those designing oversight frameworks around AI, or those working in sectors that rely on mechanisms for ongoing visibility into emerging risks. “We hope this work contributes to a broader shift in how the investment community understands their role in the innovation economy,” Ly writes.

A Structured Approach for Assessing AI Risk

The report introduces a structured approach for assessing AI risk in investment processes, organized around five distinct phases of the investment lifecycle: deal sourcing (the earliest stages of an investment), due diligence, post investment, growth, and exit (when investors are focused on an acquisition, merger, public offering, or other liquidity event.) “This approach equips investors with the structure and tools to move from ad hoc awareness of AI-related risks to systematic risk oversight over the investment lifecycle,” Ly explains. 

The report aims to enable investors to Identify and evaluate AI-specific risks across their portfolios using structured assessment criteria; develop screening questions and evaluation protocols that can be integrated into existing diligence processes; and prioritize risks according to their materiality to investment outcomes.

The AI Risk and Investor Oversight Matrix provides a framework for sorting AI risks facing investors’ firms.

The structured approach offers a two-tiered method for gaining visibility into AI-related risks across priority risk domains. The first tier presents a set of observable proxies (i.e., signals) that allow investors to gauge the magnitude of risk exposures throughout the investment lifecycle. The second tier provides a more detailed set of considerations, evaluation criteria, and engagement prompts designed for investors with the capacity and intent to assess risk more thoroughly.

The report also introduces an “AI Risk and Investor Oversight Matrix” that offers broad strategies to mitigate the impact of risks identified through the structured approach. It compares the level of influence an investor has over the evolving risk situation with the risk’s impact on potential returns. A case study in the report provides an example of how this matrix can be used to categorize different forms of AI-related risk.

We hope this approach becomes a working tool in deal rooms, portfolio reviews, and adapted for fund strategies and sector contexts,” Ly writes. “We are particularly hopeful that it can help smaller funds and first-time investors in AI-intensive sectors develop risk oversight practices that are proportionate to their resources but impactful in their value added.

AI Risk Governance: A Structured Approach for Investors and Corporate Boards