top of page

What's your AI entropy budget?

Your risk register probably has three columns. With AI, you need a fourth.


For years, when something unexpected happened, it was due to one of three main reasons: the system broke, the process failed, or a person made a mistake. All your monitoring and controls focus on these. But agents introduce a fourth reason: errors that happen during normal operation. Agents are built on probability. The same prompt can lead to different outputs. This isn’t a flaw; it’s how they work. No one in your organisation is watching for this kind of error, because it hasn’t been an issue until now.


Determinism doesn’t solve this problem. You can make an agent repeat its results and be easy to audit if you invest more time or better hardware. But you still can’t know in advance what answer a prompt will give. The uncertainty doesn’t go away; it just shifts from randomness to the context.


Your first reaction is probably the usual one: buffer against known risks. Use reserves, redundancy, or extra capital.

This approach has worked for a long time, and it can work here too, but only if the risk is first recognised, assessed, and included in your board’s risk appetite and management framework. Until then, notice how this risk is different from the three you already track:

The risks you know have stable patterns. This new one changes every time the model updates or the data shifts.


The errors you’re used to are independent and often balance each other out. With agents, errors can build on each other because they use each other’s outputs.

Traditional errors are easy to spot. This new kind can look like a reasonable decision and can slip past your controls, affect future decisions, and even shape the data you use for your next plan.


So the real question isn’t just, "How accurate is the model?" Instead, ask yourself: What’s your entropy budget? How much hidden risk is entering your operations and plans through the agents you use? Once you recognise and assess this risk, you can manage it like any other—set aside reserves, set thresholds, and include it in your risk appetite. Treat it like you would latency or capital: accept it when it brings flexibility, and avoid it when it doesn’t.


There are tools for managing this fourth type of risk: post-execution checks, guardrails, governance, and agents trained with human feedback. All of these start with acknowledging that this risk exists. Chapter 11 of Architecture of Intellect covers this in detail.


For practitioners: Has anyone in your organisation ever measured the additional risk associated with deploying AI? Or do you track the accuracy it claims to deliver?

Related Posts

See All
AI Agents have no damping, but they must have one.

AI Agents have no damping, but they must have one. The damping must be engineered in deliberately, and deciding precisely where the absorbing human belongs is an architecture decision, not a staffing

 
 
 
An LLM answers. An agent acts.

An LLM is a timeless function. An AI agent is an actor with consequences. The actor that runs in your enterprise hour after hour was assessed by nobody, because no methodology on your risk register kn

 
 
 

Comments

Rated 0 out of 5 stars.
No ratings yet

Add a rating

Get the next argument first. Articles, campaign posts and book news. No more than one email a week.

bottom of page