Named risk
A risk stated using the framework's own vocabulary, drawn from the five negative outcomes (erroneous actions, unauthorised actions, biased or unfair actions, data breaches, disruption to connected systems), the CSA/OWASP Agentic Security Initiative's T1 to T15 threat taxonomy, or a control category's own stated failure mode, rather than an invented label.
Defined in 2 GAGE programs, which carry 2 distinct definitions of it. The wording above is taught in Certified Agentic AI Governance Professional (CAAGP).
How each discipline defines it
The same term does different work depending on who is using it. These are the definitions as each program teaches them, unedited.
A risk stated using the framework's own vocabulary, drawn from the five negative outcomes (erroneous actions, unauthorised actions, biased or unfair actions, data breaches, disruption to connected systems), the CSA/OWASP Agentic Security Initiative's T1 to T15 threat taxonomy, or a control category's own stated failure mode, rather than an invented label.
A specific, mechanism-level statement of the strongest argument against a memo's recommendation, written by the memo's own author before a skeptical reader or opposing party can raise it, paired with a stated response showing how the recommendation accounts for it.
Where it is taught
The exact lessons this term appears in. The first module of every program is free with a free account.
- Derivation Trails · The Capstone: Deploy and Defend, Certified Agentic AI Governance Professional (CAAGP)
- The Decision Memo: One Page, One Recommendation · Government and Policy Navigation, The AI Lobbyist: Certified AI Policy Strategist
Terms it appears with
Not an alphabetical neighbourhood: these are the terms taught in the same lessons, ranked by how often they appear together.