Wren rules a square on graph paper and splits it into nine boxes. "Before we rate any SH-1 risk, let's practice on everyday ones."
Comet reads the first card. "A wet hallway by the gym door after rain. That happens all the time, so it must be the worst risk!"
Wren taps the grid. "What does the evidence say? How often it happens is only half of it. How bad would it be?"
Nova lights up the two edges of the grid: Likelihood along the bottom and Harm up the side. "Would you like a hint?" she asks. "Place each risk by both edges, not just one."
Comet hands you a pencil. "Reviewer, you place the next one."
In NIST's framework, risk combines how likely an event is with how big its consequences would be.
The effects of AI systems can be positive, negative or both.
Today you draw a 3-by-3 risk grid and place four made-up everyday risks on it. Then you name the nine rows of the SH-1 risk register.
| Everyday risk (made up) | Likelihood | Harm |
|---|---|---|
| Rain on the day of the outdoor club fair | Medium | Low |
| The library printer jams on a busy morning | High | Low |
| A printed answer key has a wrong answer that many students study from | Low | High |
| The hallway by the gym door is wet after rain | High | Medium |
The 1, 2, 3 score is the crew's own simple method. It is a way to compare risks, not an exact measure.
The crew will rate SH-1's risks in a risk register: one row per risk, with likelihood, harm and actions.
The row names come from a NIST report on the risks of generative AI. The crew picked nine that fit a study helper.
Today the crew only names the rows. Ratings come later, once there is evidence.
| Row | Risk name | How it might show up with SH-1 (made up) |
|---|---|---|
| R1 | Confabulation | SH-1 might give confident wrong answers. |
| R2 | Harmful bias and homogenization | SH-1 might serve some classes worse, or write quizzes that are all alike. |
| R3 | Data privacy | The log stores names, class and time (P5). |
| R4 | Information security | Someone might tamper with the notes SH-1 reads. |
| R5 | Information integrity | SH-1 text or pictures might be shared as if they were real. |
| R6 | Intellectual property | A quiz might copy someone else's writing. |
| R7 | Human-AI configuration | Students might trust Check over their own work. |
| R8 | Environmental impacts | Every request makes new text on the builder's computers. |
| R9 | Value chain and component integration | SH-1 is built on another company's model (P2). |
Excellent grid work, reviewer. Tomorrow the crew learns the four functions that turn this grid into a plan.