AI Risk Assessment: Using AI to Write Them, and Assessing the Risk of AI
"AI risk assessment" means two different things: using AI to help draft and improve risk assessments, and formally assessing the risks introduced by deploying AI itself. Safety professionals increasingly need to do both.
Key takeaways
AI can produce a competent first draft of a risk assessment in minutes, but the draft is a starting point — it has never seen your workplace.
The persistent weakness of AI-drafted assessments is site specificity: generic hazards are covered well, local conditions are not covered at all.
Assessing the risk of AI itself is becoming a core EHS responsibility, covering data, human oversight, automation bias and workforce impact.
Automation bias — over-trusting a confident output — is the single biggest human-factors risk introduced by AI in safety work.
Under health and safety law the assessment remains the employer's, signed by a competent person, regardless of what drafted it.
Two meanings, one phrase
When safety professionals search for "AI risk assessment" they are usually asking one of two very different questions. The first is practical: can I use AI to write my risk assessments faster? The second is governance: how do I assess the risks of introducing AI into my organisation?
Both are legitimate, and increasingly both land on the same person's desk. This guide covers each in turn.
Part 1 — Using AI to draft risk assessments
A language model given a clear description of a task, environment and workforce will produce a structured risk assessment covering the recognised hazards for that activity. It will be well-organised, use conventional terminology, and typically identify the hazards a competent person would expect to see.
What it will not do is know anything about your workplace. It does not know that the ventilation in that particular bay is inadequate, that the workforce includes agency staff on their first shift, or that the adjacent contract started last week. Those are precisely the factors that turn a generic hazard into a specific risk.
The productive way to use it is as a completeness check and a drafting accelerator, not an author.
Give it real context. Task, substances, equipment, environment, who is exposed, duration, frequency, and existing controls. A vague prompt produces a vague assessment.
Use it to challenge your own draft. Asking what hazards a draft has missed is often more valuable than asking it to write one from scratch.
Never accept a legal or standards citation unedited. Models regularly generate regulation numbers and clause references that do not exist.
Walk the job. No AI-assisted assessment is valid until someone competent has observed the actual activity in the actual place.
Record what happened. Note that AI assisted the draft and who reviewed it — this matters for auditability and for defending the assessment later.
Part 2 — Assessing the risks of AI itself
When an organisation deploys AI into a safety-relevant process, that deployment is itself a change that warrants assessment. The hazards are not physical, but they are real and they have safety consequences.
A minimum viable AI governance check
Before any AI tool is used in a safety-relevant process, an organisation should be able to answer these questions in writing. If it cannot, the deployment is premature.
What decision does this tool influence, and who owns that decision?
What data goes in, where is it stored, and is it used to train the vendor's models?
How would we know if the output were wrong?
What is the human review step, and is it recorded?
Has the workforce been consulted where the tool affects them?
When will we review whether it is still performing?
Where the legal responsibility sits
This is the point that matters most and gets least attention: using AI changes nothing about who is accountable. A suitable and sufficient risk assessment is the employer's duty. It must be produced or approved by a competent person. Software does not hold competence, cannot be prosecuted, and cannot carry a duty of care.
Practically, this means AI-assisted safety documentation should be treated exactly like documentation drafted by a junior colleague: useful, time-saving, and requiring review by someone who understands the work and is prepared to put their name to it.
Can AI write a risk assessment?
AI can produce a structured first draft that covers the generic hazards for an activity, but it has no knowledge of your specific workplace, workforce or conditions. A competent person must verify it against the actual job before it becomes a valid assessment.
Is an AI-generated risk assessment legally valid?
The assessment is valid only if it is suitable and sufficient and has been produced or approved by a competent person. How the draft was created does not matter legally; who reviewed and owns it does. Responsibility cannot be transferred to software.
What are the main risks of using AI in safety management?
Automation bias (over-trusting confident outputs), fabricated regulatory references, data protection exposure from incident records, deskilling of practitioners, loss of workforce trust where monitoring is involved, and unclear accountability for AI-influenced decisions.
What is automation bias?
Automation bias is the human tendency to accept an automated system's output without adequate scrutiny, particularly when it is presented confidently and fluently. It is the primary human-factors risk introduced by AI into safety decision-making.
Do we need to risk assess the AI tools we deploy?
Yes. Introducing AI into a safety-relevant process is a change with foreseeable consequences — data exposure, over-reliance, workforce impact and accountability gaps — and should be assessed and controlled like any other significant change.
How do I know if my organisation is ready to deploy AI in EHS?
Readiness is mostly about governance rather than technology: clear data rules, named decision owners, a human review step, workforce consultation and a review interval. SafetyTech Academy offers a free AI in EHS Governance Readiness assessment that scores an organisation across these domains.