Research paper
Applying MIRC to AI Risk and Policy
Origins
I developed the Matrix of Innovation-Risk-Crisis (MIRC) while studying at the University of Cambridge. Its original purpose was to visualise how different innovations contributed to the global financial crisis. I wanted to understand the particular functions those innovations performed in creating risk, disguising its presence and transmitting it through the financial system.
Breaking these contributions down made it possible to map how individual innovations could contribute to a wider crisis. An innovation might introduce a vulnerability, while another could make that vulnerability harder to recognise. Connections between institutions could then allow the consequences to spread. MIRC provided a way to organise these mechanisms within a common framework and examine how they interacted.
This paper proposes applying that approach to AI. The central thesis is that breaking down different elements of AI innovation according to their contribution to risk could provide a clearer basis for tailored policy recommendations. Understanding the mechanism through which an innovation affects risk should help identify where intervention would be useful and what it would need to change.
The framework
MIRC distinguishes between three functions through which innovation can contribute to risk.
| Function | Question |
|---|---|
| Creation of risk | How does an innovation introduce a new source of risk or increase an existing vulnerability? |
| Disguise of risk | How does an innovation make risk harder to identify or cause it to appear smaller than it is? |
| Transmission of risk | How does an innovation allow risk to spread between organisations or through connected systems? |
These functions can overlap. The same innovation may introduce a vulnerability and make its significance difficult to assess. Recording both contributions allows the analysis to explain why a risk exists and why it might remain unaddressed.
The framework also requires a distinction between mechanisms and consequences. A harmful outcome, such as a loss of human control, identifies what the analysis seeks to prevent. Explaining how a particular innovation could make that outcome more likely requires a further account of the changes it introduces.
Application to AI
Applying MIRC to AI would begin by identifying the particular innovation being examined. This could be a change in the authority an AI system is given, or a new way of integrating a model into other services. Each innovation would then be examined to identify how it could create, disguise or transmit risk.
The value of this approach is its specificity. A policy intended to address an unsafe capability may need to constrain how that capability is used. Where the problem concerns the spread of an existing weakness through connected systems, intervention may instead need to address the connections that allow it to spread. MIRC could help connect a policy recommendation to the mechanism it is intended to interrupt.
Developing policy
MIRC could provide a structure for moving from a broad concern about AI to a specific account of how an innovation contributes to risk. That account would make it easier to explain why a proposed intervention targets a relevant mechanism and where further evidence is needed.
The next step would be to apply the framework to particular AI innovations using technical evidence and documented deployment practices. Policy recommendations could then be developed around the mechanisms identified and assessed for their likely effectiveness. The aim is to make the reasoning between risk analysis and policy advice explicit enough to examine and improve.