Risks
Principles
Remediation Methods
Definitions
Regulations
100

This risk arises when using a vendor or third party to build the Gen AI tool, or from purchasing directly from a vendor or third party. 

What is 3rd-Party Risk?

100

This principle ensures proper ownership and oversight at each stage of the RAI process and ensures there is oversight in place to monitor the use case once it has been completed. 

What is Efficiency?

100

This is the process of identifying and removing or obscuring sensitive information within a dataset to protect individuals' privacy.

What is PII redaction?

100

The process of evaluating AI systems by intentionally introducing inputs designed to exploit weaknesses and vulnerabilities, to ensure robustness and security.

What is adversarial testing?

100

Protects Americans’ privacy, advances equity and civil rights, stands up for consumers and workers, promotes innovation and competition and advances American leadership around the world.

What is Biden’s AI Executive Order?

200

Involves the collection, processing, storage, management and usage during the training and operation of the Gen AI system.

What is Data Risk?

200

This principle refers to how GenAI Systems are assessed using Standard and Repeatable Responsible AI Intake and Risk Processes.

What is Safety and Accountability?

200

This is the process of evaluating and challenging the robustness, security, and reliability of machine learning models

What is adversarial testing?

200

An advanced artificial intelligence system trained on vast amounts of text data to understand and generate human-like language.

What is a large language model (LLM)?

200

Mandates that personal data must be protected through techniques like redaction and pseudonymization.  

What is GDPR?

300

Encompasses intentional or unintentional misuse, manipulation or attacks against a Gen AI system.

What is Use Risk?

300

This principle refers to making GenAI systems secure, capable of withstanding unexpected adverse events and adapting to unforeseen changes.

What is Security and Privacy?

300

This is an approach where human judgment is integrated into the decision-making process

What is Human in the loop?

300

Artificial intelligence systems that can create new content, such as text, images, music or code based on the data they have been trained on.

What is GenAI?

300

Proposes comprehensive regulations to ensure AI systems are safe, ethical and respect fundamental rights across the European Union.

What is the EU AI Act?

400

Arises from integrating Gen AI into existing processes or workflows without proper assessment.

What is Process Risk?

400

This principle refers to the education that equips United employees with the knowledge to recognize and mitigate risks within GenAI.  

What is Caring and Fairness?

400

This is an approach where there is disclosure letting the user know the output they see is generated by GenAI.

What is a transparency disclosure?

400

Artificial intelligence systems that use rule-based algorithms and statistical methods to perform specific tasks, relying on pre-defined instructions and data rather than generating new content.

What is Traditional AI?

400

Guidelines provided by a government agency for managing risks associated with AI, including establishing controls to ensure security, privacy and reliability throughout the AI system lifecycle.

What is NIST RMF Framework?

500

Relates to noncompliance with applicable laws, rules and regulations, including privacy and sector-specific guidance.

What is legal/compliance risk?

500

This principle provides access to appropriate levels of information based on the stage the GenAI use case is in the lifecycle.

What is Transparency and Trustworthiness Risk? 

500

This is a thumbs up or thumbs down where the user can let the GenAI model know if the output is correct. 

What is feedback mechanism?

500

An input or initial piece of text used to guide the generation of content by a generative AI model.

What is a prompt?

500

In 2026, this law will pass and apply to all developers and deployers using “high-risk artificial intelligence systems” to protect consumers from discriminatory consequential decisions.

What is the Colorado AI Act?

M
e
n
u