Most organisations can produce an AI policy document within a week. Almost none can tell you, with confidence, who actually assessed the risk on the AI project a business unit quietly stood up last month.
That gap — between the policy on the shelf and the assessment that never happened — is where AI risk self-assessment either earns its keep or gets exposed as theatre.
The 30-second take
AI risk self-assessment only works if it’s a business-led decision tool, not a compliance form.
Done well, it lets the people closest to an AI use case identify risk, apply controls and escalate early — before a project is too embedded to redesign. Done badly, it’s a checklist nobody owns. The evidence from 2026 so far is that most organisations are still closer to the second version than the first, even as regulatory expectations for documented self-assessment start to harden.
Boards know less than they think
Deloitte’s 2026 State of AI in the Enterprise research found that only 21% of enterprises have mature governance in place to manage the risks of agentic AI, and that 66% of boards still report limited-to-no working knowledge of AI — an improvement on the prior year’s 79%, but still a majority.
That’s not a technology gap. It’s a decision-rights gap: if the people accountable for risk appetite don’t understand what they’re approving, self-assessment becomes the only mechanism left that can catch a problem before it ships.
Australia says governance is a priority — the numbers say otherwise
KPMG’s Global AI Pulse survey, run in the first quarter of 2026, found 31% of Australian businesses name AI governance a focus area, against a 26% global average, and 38% rate trust and security as a high priority versus 26% globally.
On paper, Australian organisations are ahead. But naming governance a priority and operationalising a self-assessment process that a business owner can actually complete without a risk team holding their hand are two different achievements.
The Governance Institute of Australia’s own 2026 commentary makes the same point from a different angle: the standard governance toolkit — data governance, risk assessment, explainability, continuous monitoring — still applies, but agentic systems are moving fast enough that static, point-in-time assessments are starting to fall behind the risk they’re meant to catch.
Europe just made self-assessment a legal document, not a best practice
From 2 August 2026, the EU AI Act’s high-risk system obligations became fully applicable, including a specific requirement that providers relying on the Article 6(3) filter must complete and document a self-assessment — covering the system’s intended purpose, why it qualifies as high-risk, and why it doesn’t perform profiling — before the system goes to market, with penalties attached for getting the classification wrong.
Australian organisations operating in or selling into the EU don’t get to treat self-assessment as an internal nicety anymore; for a defined category of systems, it’s now a filed record a regulator can audit. That’s a preview of where local expectations are likely headed.
Questions to put to your own organisation
- If we picked five AI use cases live in the business today, could the person who approved each one show us a completed risk self-assessment — not a policy reference, an actual document?
- Who owns escalation when a business-led self-assessment flags something the assessor isn’t equipped to resolve alone?
- Are our risk appetite thresholds specific enough that a non-specialist could apply them consistently, or do they only make sense to the risk team that wrote them?
- How many of our board members could explain, in their own words, what “agentic” risk means for a system we’ve already deployed?
- If a regulator or customer asked for evidence of our AI risk assessment process tomorrow, would we be producing it or reconstructing it?
- Does our self-assessment process get revisited when a system’s behaviour changes, or only at initial sign-off?
None of this requires a bigger framework. It requires an honest look at whether the assessment step is a live decision tool or a document that exists to say one exists.
Run a readiness snapshot against your own AI risk self-assessment practice in the Innovation of Risk Reading Room to see where the gap sits in your organisation.

