Francesca Rossi (IBM): AI risk classification by use case breaks down for agents

Tag: S-2026-07-28-ibm-rossi-agent-risk-axis Type: article (practitioner/vendor commentary — LinkedIn post, captured via secondary relay) Author(s): Francesca Rossi, IBM Fellow and IBM global leader for responsible AI; relayed by AI Pulse Daily Brief (30 Jul 2026) Date of source: 2026-07-28 (per the relaying brief) Date ingested: 2026-08-03 Authority weight: low — secondary relay of a LinkedIn post; the relaying brief itself flags “original source not verified”; the primary post was not fetched in this scan. Rossi’s seniority raises the signal’s interest, not its verification level. Personal commentary, not a stated IBM corporate position. Raw file: /_raw_sources/S-2026-07-28-ibm-rossi-agent-risk-axis.md

What it claims

Per the relay: Rossi wrote on 28 July 2026 that AI risk is almost always classified by what a system is used for — the EU AI Act works this way, and so do most corporate risk registers — and argues this test fails for agents. What decides an agent’s risk, she argues, is its autonomy, the tools and data it can reach, how reversible its actions are, and how long it runs before a person checks. She calls for a second classification axis alongside use case, and for risk assessment to run during operation rather than only before deployment. The relay draws the consequence: without this, the same approved use case configured with wider tool access is under-tiered while every register entry and sign-off still reads as correct.

Notable quotes

No verbatim quotes available — the primary post was not fetched; all content above is the relaying brief’s paraphrase.

What’s speculative vs. asserted

Everything here is asserted by the relay as a summary of Rossi’s argument; nothing is verified against the primary post. The argument itself is a normative proposal (how classification should work), not a factual claim. No indication that this is IBM product direction or corporate policy — treat any link to watsonx.governance as speculation [speculative — S-2026-07-28-ibm-rossi-agent-risk-axis].

Topics this feeds

IBM — positioning by IBM’s most senior responsible-AI figure on agent risk classification. Model Risk Management and Agentic AI — bears directly on the risk-tiering / classification strand (Credo default-high-risk stance, ValidMind governed risk tiering).

Open questions raised

Whether this framing appears in watsonx.governance product positioning (the vault’s watch item, not Rossi’s). Whether the post reflects or foreshadows IBM’s input to EU AI Office agentic guidance. Primary post URL known (LinkedIn activity 7487883861687914496) but unfetched — verify if it becomes citable.