Direct answer
What belongs in a production AI-agent risk register?
#A production agent risk register should describe the scenario, trigger, likelihood, impact, affected assets and people, preventive controls, detection signals, containment and recovery actions, owner, review cadence, and evidence. It should cover authority, identity, tools, memory, coordination, data, reliability, cost, and auditability.
- Risks are written as scenarios rather than labels.
- Every material risk has an owner and observable signal.
- Controls must be tested, not merely documented.
Source basis: reviewed synthesis of the strategy corpus. Report-derived claims remain subject to the verification boundary in the source library.