Assess

Describe your use case, get its risk register

Tick the elements your solution contains — components, design choices and capabilities, following the ARC framework's element lens. The tool derives the activated risks from the 44-risk enterprise taxonomy, the relevant control categories, and one-line control statements with Cardinal / Standard / Best-practice levels — then lets you download the complete register and its mapping tables, with stable IDs on every element, risk, category and statement. Cardinal control statements are readiness-aware: declare your enterprise infra and statements whose prerequisites are missing are flagged as gated, not day-one mandates. Specific guardrail implementations are designed downstream by system teams; this tool stays at the control-statement level.

Elements you can declare (19)

Components: EL-01 LLM / foundation model · EL-02 Tools / function calling · EL-03 Instructions / system prompt · EL-04 Memory / knowledge store

Design: EL-05 Agentic architecture (multi-agent)

Capabilities: EL-06 Planning & goal management · EL-07 Agent delegation · EL-08 Tool selection & use · EL-09 Natural language communication · EL-10 Multimodal understanding & generation · EL-11 Official communication · EL-12 Business transactions · EL-13 Internet & search access · EL-14 Computer use · EL-15 Other programmatic interfaces · EL-16 Code execution · EL-17 File & data management · EL-18 System management · EL-19 Privileged system access

AI RiskAtlas is an educational model of how GenAI & agentic systems work and fail. Architectures and payloads are illustrative and simplified for learning — not operational guidance. Real-world cases are summarised from public reporting.

Sources & further reading →·Built by Shi Yuan ↗