Abstract
<title>Abstract</title> <p>Artificial intelligence is being deployed at organizational scale faster than security postures can adapt. Existing risk quantification frameworks, including the Common Vulnerability Scoring System (CVSS), Factor Analysis of Information Risk (FAIR), and machine learning based risk models, were designed for conventional IT environments and share a fundamental structural gap: none adequately accounts for the threat landscape specific to AI systems. Prompt injection, model drift, training data poisoning, and adversarial manipulation are not addressed by these frameworks in any meaningful way. Neither is the regulatory exposure accumulating under the EU AI Act, CMMC, and emerging AI governance requirements worldwide. This paper introduces a conceptual framework for assessing, communicating, and managing cybersecurity risk specific to AI systems. Instead of proposing an additional scoring formula, it identifies five dimensions of AI risk that current tools consistently fail to capture: Attack Surface, Model Exploitability, Data Integrity, Regulatory Exposure, and Control Maturity. The framework explains how these dimensions interact to produce financial loss exposure and is designed to serve multiple audiences simultaneously. It provides senior executives and boards with clarity that requires no background in security engineering, gives GRC professionals a structure they can operationalize within existing risk programs, and offers regulators a reference point for developing proportionate AI governance standards. This framework is not a finished actuarial product. It is scaffolding, sturdy enough to support consistent and comparable conversations about AI risk that current frameworks simply cannot enable. The field's most pressing gap is not insufficient threat intelligence but the absence of shared vocabulary for translating that intelligence into organizational decisions.</p>