← Back

Method

How to assess your own AI risk — six questions, and what counts as an answer

You cannot assess your exposure to AI by researching AI. The evidence that decides your position is organisational, and nearly all of it is already in front of you: what your employer can realistically deploy, what management has said and pointedly not said, whether the last big change produced capability or slides, and whether you sit inside or outside the room where those decisions get made. What follows is six questions you can answer in an afternoon from things you have already seen. Answering them honestly is harder than finding them, and the honest answers are sometimes bad.

Key points

  • Researching the technology tells you what is possible. It tells you almost nothing about what your employer will do.
  • Every input you need is observable: budgets, announcements, hiring, who is in the room, what happened the last time.
  • A question you can only answer reassuringly is a badly framed question.
  • The output is not a score. It is a short list of which factors are load-bearing for you specifically.
  • One weak dimension is noise. Three pointing the same way is a finding.

Why the reading never resolves anything

People who worry about this are usually well informed. They have read the capability studies, followed the releases, watched two credible economists reach opposite conclusions in the same week. More reading does not help, and the natural inference is that they have not yet found the right source.

The source does not exist. Not because the research is bad, but because it answers a different question. Benchmark results tell you what a system can do under test conditions. Your exposure is determined by what a specific employer, with a specific budget and a specific tolerance for disruption, decides to do in the next eighteen months. Those are not the same question and the first does not constrain the second nearly as much as people assume.

So stop studying the weather. The question is whether your roof leaks.

Six questions, and what a real answer looks like

Each of these is answerable from evidence you can get without special access. The point of writing them down is that vague dread does not survive contact with a specific question.

  • What in my actual work could a system do end to end, without a person checking it? Not your job title — the tasks. Go through last week. Which outputs would have been fine unreviewed, and which would have caused a problem?
  • Could my employer actually deploy it? Separate two things people constantly merge: whether the technology exists, and whether this organisation has the data, the integration budget, the vendor relationships and the appetite for a year of disruption. Plenty of firms cannot deploy what they have already bought.
  • What has management said, and what have they conspicuously not said? Silence about headcount in a communication that covers everything else is information. So is a commitment made only in a town hall and never in writing.
  • When this organisation last had to change, what actually happened? Look at the previous transformation. Did people end up with capabilities they did not have before, or did it produce a training portal nobody finished and a slide deck? Track record generalises better than intention.
  • Am I inside or outside the room? Not seniority. Whether decisions about tooling in your area get made with you present, with you consulted, or with you informed afterwards. The third is a materially different position from the first.
  • Does regulation give me leverage, or take it away? In some functions, incoming obligations create a requirement for a named accountable human. In others, the same rules mostly generate documentation work that gets automated next. Both exist. Find out which one applies to you.

None of these requires you to predict anything. They ask what is already true.

These six are the IssueSpace dimensions, in the order the assessment scores them: Domain Fit, Technical, Leadership, Org Learning, Influence, Ethical Value.

The two ways this goes wrong when you do it alone

The first is recency. Whatever you read most recently dominates the assessment, and what you read most recently is selected for being alarming or reassuring rather than for being relevant to you. A useful correction: for each answer, write down what you are basing it on. If the basis is an article rather than something you observed at work, mark it. You will be surprised how many of the six are marked.

The second is subtler and worse. People frame the questions so that only a comfortable answer fits. “Am I adding value?” cannot be answered badly by anyone still employed. “Would my last six deliverables have survived without review?” can. If a question has never once produced an answer you did not like, it is not doing any work.

Reading the answers together

Resist the urge to average them into a number. The six are not comparable units and a mean of them is a fiction.

What you are looking for is convergence. One weak dimension surrounded by five solid ones is normal and usually not worth acting on — everyone has a soft spot. Three that point the same direction is a pattern, and patterns are what you can plan against. A person whose tasks are automatable but who sits inside the decision-making room and works for an employer with no deployment capacity is in a completely different situation from someone with identical tasks, no visibility and a management team already piloting.

Same job title. Same tasks. Different exposure. This is the entire reason occupation-level risk scores mislead.

When the reading is bad

Sometimes you run this honestly and the result is that you are exposed. Three or four dimensions agree, the evidence is not ambiguous, and no amount of reframing changes it.

The advice offered at that point is usually to upskill. It is not wrong, exactly, but it is aimed at the wrong variable. If your exposure comes from being outside the room, learning to prompt better does not put you in the room. If it comes from an employer with no deployment capacity, you may have more time than you think and the right move is to use it rather than to panic-train. If it comes from a management team that has already made a decision they have not announced, the useful question is about timing and options, not skills.

The value of knowing which factor is load-bearing is that it tells you which lever is real. That is the whole return on doing this properly, and it is a large one. It is not comfort.

What the tool adds, and what it does not

We built this into an assessment because doing it on paper has a consistency problem. People answer question three with the standard they applied to question one, drift by question five, and read the result through whichever mood they started in. A structured instrument fixes the framing, scores the dimensions separately, and writes the analysis back without knowing you well enough to be kind.

It cannot predict what will happen to your role. Nothing can. It cannot tell you whether to leave. It maps a position, and a position is a much better starting point than a feeling.

If you would rather not use it, use the six questions. They are the method. The tool is one implementation of it.

Questions

An afternoon if you are honest, ten minutes if you are not. The time goes into finding the evidence for each answer rather than into the answering itself.

Yes. Every input is either something you already observed or something publicly stated. None of the six requires you to ask your manager anything, though a couple of them get sharper if you do.

No. The questions are about your organisation, not about the technology. Technical knowledge helps with exactly one of the six and is not decisive there either.

That is a finding. Not knowing what management has committed to, or whether you are inside the decision, is itself a description of your position — and usually a less comfortable one than people want to conclude.