Quantifying AI risk for the board means expressing it as a range of expected financial loss over a defined period, with a stated confidence level. Not a color, not a maturity score, and not a count of tools discovered. The units are those the board already uses for every other decision it makes: money, probability, and time.
The distinction is not academic. A board allocates capital. It weighs AI risk against a plant upgrade, a litigation reserve, or an acquisition. Ordinal scales do not survive that comparison: you cannot trade a “High” in one domain against a “Medium” in another. A financial estimate, with an honest range around it, can be compared with other business investments and exposures.
Because a color is an opinion with a border drawn around it, heat maps endure as they are defensible in the wrong way: nobody can prove an amber square wrong. But a board performs three operations on every risk it weighs, and a color supports none of them.

Ask a director to allocate capital against an amber square and the conversation stops.
A heat map is what a risk model looks like when you cannot adequately quantify risk.
Worth admitting before you say anything to a board: security leaders do not present colors because they prefer colors. They present colors because they lack the data needed to consistently quantify risk.
Exposure comes from the standard loss model. It combines how often a scenario occurs with what it costs when it does, modeled as a distribution rather than a single point estimate. FAIR is the common vocabulary, and your audit committee has likely seen it applied elsewhere. Sizing the inputs is primarily a costing exercise, not a security one.
Concentration can matter as much as or more than exposure because risk is rarely evenly distributed. A handful of systems often carry most of the range, and naming them turns a number into a target. Marginal return ends the meeting well. Everything before it is context.
Because loss magnitude for an AI system is not what the tool was bought to do, it depends on everything it can reach. An assistant procured to summarize meeting notes, then wired into file storage, the CRM, and a code repository, can carry a loss magnitude shaped by the most sensitive data and systems it can access across all three.
You cannot price a blast radius you have not mapped.
The model needs three inputs, all grounded in telemetry rather than judgment: the population (there is no rate without a denominator), the permission set (what each system can do), and the reachable data (what it can access). Reco's AI Agent Security continuously maps every AI app and agent to an owner, a permission set, and the systems it connects to. That is not a risk model. It is the missing input to one.
Yes, and it is already on the clock. The SEC's disclosure rule obliges a public company to file within four business days of determining that a cybersecurity incident is material. The clock starts at that determination, not at discovery. Materiality is a financial judgment.
So if you cannot reasonably estimate the potential financial impact of an AI incident, determining whether it is material becomes significantly more difficult, and you risk delaying the clock you are legally required to start. Quantification stopped being only a maturity exercise the moment a regulator tied a filing deadline to materiality.
Note: four days is generous only if the analysis already exists. Companies that improvise a loss estimate mid-incident discover, in the worst week of the year, that they cannot fully identify what the system could reach.
Give ranges, not points. A point estimate invites an argument about the point. A range with a stated confidence invites a decision.
Own the uncertainty out loud. A board trusts the executive who says the frequency estimate is weak and explains what would strengthen it. It does not trust suspicious precision.
Never present a number without a decision attached. Exposure, then options, then what each buys. A board report ending in a number and nothing else is a status update wearing a suit.
Attach a name. A quantity with no owner is trivia, which is why who owns AI risk has to be settled before anyone tries to price it.

Action: Open your last board deck and find the AI slide. If a director could not have allocated capital from it, it was not a risk report.
The board does not need to understand AI. It needs to know what AI costs, how confident you are, and what the next dollar buys. That is the kind of conversation boards have been having for a century.
Boards have never governed technology. They have always governed business decisions. AI does not change that. What changes is whether AI risk is expressed in a form directors can compare, challenge, and fund. Expected financial loss, stated confidence, and investment tradeoffs are not a new way to talk about AI. They are the language boards already use to govern every other material risk. The organizations that learn to speak that language will not just understand AI risk better. They will make better decisions about it.

Gal is the Cofounder & CPO of Reco. Gal is a former Lieutenant Colonel in the Israeli Prime Minister's Office. He is a tech enthusiast, with a background of Security Researcher and Hacker. Gal has led teams in multiple cybersecurity areas with an expertise in the human element.