TL/DR
Don't wait for the regulator to tell you what to worry about and manage risk proactively. Now!
A new MIT-linked study shows where government is paying attention to AI risk and where it isn't.
For business leaders the message is simple. As said in the TL/DR above, don't wait for the regulator to tell you what to worry about. Please don’t.
What this means for your AI roadmap?
Whether you run a bank in New York or a hospital chain in Chennai, the lesson travels.
1. Stop treating regulation as your risk map
If you only manage the risks regulators write about, you will miss the ones experts fear most. The study shows the two lists don’t match. Build your own map based on where your business is actually exposed.
2. A mention is not a control
This is the lesson most companies can use tomorrow. Look at your own AI policy. Does it say something like “we will monitor for bias” and stop there? That is the same shallow coverage the researchers found in government documents.
Every risk in your policy should have four things. A named owner. A test. A threshold that triggers action. A clear escalation path. If it doesn’t have those, it’s a sentence, not a safeguard.
3. Finance leaders: make fraud your number one AI priority
Voice cloning, deepfake video calls and AI written phishing are already hitting banks and insurers. The federal playbook here is thin. Invest in detection, train your staff on impersonation attacks and tighten verification for high value transfers. Also make sure you can explain any AI driven credit or claims decision to a customer or regulator.
4. Healthcare leaders: design for overreliance
The risk isn’t only that AI gets it wrong. It’s that tired clinicians stop checking. Keep humans meaningfully in the loop for diagnosis and treatment decisions. Track how often staff override AI recommendations. If that number drops close to zero, that is a warning sign, not a success.
5. Get ahead on AI agents before everyone else does
This is the sleeper risk. Companies are rolling out AI agents that book, buy, negotiate and reply on their behalf. Soon your agent will be talking to a supplier’s agent. Almost no one is governing what happens then.
Before you scale agents, set spending and action limits, keep full logs, build a kill switch and spell out in vendor contracts who is liable when an agent makes a costly mistake.
6. Build for speed, not for annual reviews
If models change every few months and laws take nearly two years, a yearly AI risk review is too slow. Move to quarterly reviews for high impact systems. Re-test every time your vendor pushes a major model update.
7. Own the people question
Job quality and the value of human work are barely touched by federal documents. That doesn’t make them low risk. It makes them your reputational risk to manage. Be clear with employees about how AI will change their roles. The companies that handle this badly will be the case studies in the next paper.
8. Put AI energy use on the ESG radar
Environmental harm got almost no detailed treatment in the documents. Investors and customers are asking anyway. Start tracking the compute and energy footprint of your AI use now so you aren’t scrambling when disclosure rules arrive.
9. Smaller and service businesses: don’t assume you’re off the hook
Hotels, restaurants, admin support and professional services barely register in federal AI documents. That is partly because adoption is slower there. But when AI comes in through a vendor’s booking system or HR tool, the risk comes with it. Ask your vendors hard questions before you sign.
10. Watch the states and your sector regulator
If Washington stays quiet, states will fill the gap. Assign someone to track state level AI bills in the markets you operate in. For companies outside the U.S., the same logic applies to your own regulators and to the EU.
The bottom line
The blank pages in the AI rulebook are not a free pass. They are a to do list.
The regulator will eventually catch up. When it does, it will look at what you knew, when you knew it and what you did about it. This study makes it hard for anyone in finance or healthcare to say they didn’t know.
The smartest move right now is to govern your AI as if the detailed rules already existed. Because for your customers, the risks already do.


