Case study · work product
Risk AI Council
An AI-risk assessment platform. I led go-to-market and content — who it was for, what it said first, how the site was sequenced, and the learning programs sitting behind six categories of AI risk.
The model. Six risk categories are the load-bearing element — they are the assessment's question set, the content's table of contents and the site's information architecture, all at once. Each maps back to the two reference frameworks.
the problem.
AI got regulated faster than it got understood. The NIST AI Risk Management Framework and the EU AI Act both set out what responsible AI is meant to look like — but they land on a team as long documents written in the language of policy, not as something you can act on during a sprint.
So the gap isn't awareness. Everyone building with AI already knows they are supposed to be managing risk. The gap is translation: turning a framework's language into a set of questions a team can actually answer about the system in front of them, and then into something they can go and learn.
That makes it a content problem as much as a product one. An assessment platform is only as good as the vocabulary it hands its users — if the categories don't make sense to the person answering, neither does the result.
what it is.
Risk AI Council is an AI-risk assessment platform. It organises AI risk into six categories, and pairs the assessment with learning programs — so a team doesn't only find out where it stands, it gets a route from there.
The two frameworks it aligns to:
- NIST AI RMFThe US National Institute of Standards and Technology's voluntary framework for identifying and managing risk across an AI system's life cycle.
- EU AI ActThe European Union's regulation of AI systems, which sorts them into risk tiers and attaches obligations to each tier.
On what's not on this page: the six category names, the assessment content and every internal number stay with the company. Nothing here is a metric, a screenshot or a customer. What's here is the structure and the reasoning — the part that was mine.
what I owned.
-
01
Target users
Deciding who the assessment was actually for, and therefore what level it had to be pitched at. An AI-risk tool can speak to a compliance officer, an engineering lead or a founder — and those are three different products wearing one name. Choosing narrows every decision downstream, which is exactly why it goes first.
-
02
Launch messaging
The words the product leads with. In a category most buyers can't yet name, the first job of messaging isn't persuasion — it's definition. You have to give someone the concept before you can convince them they need it, and you have to do it without reprinting the regulation at them.
-
03
Site structure
The order the story gets told in: what a first-time visitor sees, what they need to understand before the assessment means anything, and where the assessment itself sits in that sequence. Structure is the argument — put the assessment too early and it reads as a quiz; put it too late and nobody reaches it.
-
04
Learning programs
A program behind each of the six risk categories, aligned to NIST AI RMF and the EU AI Act. This is where the translation work actually lives: taking a framework obligation and turning it into something a team can be taught, in the same vocabulary the assessment uses to score them.
how it works.
The flow is deliberately short: six categories → one assessment → the learning program for what the assessment surfaced, with every category traceable back to the framework clause it came from.
The design decision worth calling out is that the six categories do three jobs at once. They are the assessment's question set. They are the table of contents for the learning programs. And they are the site's information architecture — the thing a visitor navigates by. One taxonomy, three surfaces.
That's why the categories couldn't be settled as a content task after the product was built. Renaming a category renames a nav item, re-cuts a learning program and changes what the assessment is asking — so the taxonomy had to be right before anything downstream could be. It's the clearest case I've worked on of content decisions being product decisions, rather than describing them.
The framework alignment is what keeps the taxonomy honest. Six categories invented in a room are marketing; six categories that each map to something in NIST AI RMF or the EU AI Act are a position a customer's compliance team can check.