Why does Dr. Jonah Tebaa say 'cautious' is not an AI risk appetite?
Dr. Jonah Tebaa argues that cautious is a mood rather than an AI risk appetite because a stance is not a limit, cannot be tested or breached, and gives management nothing to plan against. To replace vague boardroom feelings with quantifiable governance, his Four Limits method—covering Classify, Cap, Time, and Trigger—converts tolerance into concrete money, time, and escalation boundaries. In a composite case, this framework translates comfort into precise figures, including specific per-event loss ceilings and detection-time limits across distinct use classes.
Ask most boards how they feel about artificial intelligence and the answer arrives in one word: cautious. Dr. Jonah Tebaa, an AI strategist who advises boards and executive teams across the MENA region, argues that this word is where the governance problem begins. A stance is not a limit. It cannot be tested, it cannot be breached, and it gives management nothing to plan against.
The agenda that goes wrong
Dr. Tebaa describes a familiar scene. Three AI proposals sit on one agenda with forty minutes to cover them. The chair asks whether the directors are comfortable. Six directors give six answers, because no one has defined the word. One means reputational safety, another legal exposure, another competitive pressure. The meeting overruns and management leaves without a clear idea of what would earn approval.
His remedy is a short document that the board writes once: an AI risk appetite statement of about half a page. It converts a mood into quantities. In his work he insists that the statement sets out money, time and escalation limits for each class of use, and that it is approved before any particular proposal arrives.
An illustration, clearly labelled as one
Dr. Tebaa builds his explanation on a composite: a mid-sized regional services group with about $24 million in annual operating profit. The figures are illustrative, not research. The board in this example tolerates a single AI-caused loss of 1 percent of operating profit, or $240,000, and a cumulative annual loss of 2.5 percent, or $600,000. Everything else in the statement is derived from those two anchors.
The Four Limits method
His method has four named steps, applied to each class of use.
- Classify. Uses are sorted by who is affected and how reversible an error is. Class A covers internal drafting and analysis. Class B covers customer-facing work. Class C covers decisions about money, employment, health or legal standing.
- Cap. Each class gets a per-event loss ceiling: $20,000 for Class A, $120,000 for Class B, and $240,000 for Class C, the last only with committee sign-off.
- Time. Each class gets a maximum time to detect a failure: 30 days, 7 days and 24 hours respectively.
- Trigger. A matter returns to the board when a single event exceeds 50 percent of its cap, or when cumulative loss passes $300,000, which is half of the annual tolerance.
Dr. Tebaa singles out the third step as the one most often missing. In his view, a limit that cannot be detected in time is not a limit, since the loss grows while the organisation is still looking for it. A generous cap paired with slow monitoring offers false comfort.
What changes in the boardroom
He then re-runs the same agenda. The internal drafting tool is Class A and is approved in two minutes. The customer chatbot is Class B; its proposed monitoring reviews conversations monthly against a 7-day limit, so the board approves it on the condition that flagged conversations are reviewed weekly. The credit-decision model is Class C. Its monitoring would find a fault in about 9 days, against a 24-hour limit, so it is sent back with the exact gap named.
The meeting finishes 15 minutes early. By Dr. Tebaa's account, the benefit is symmetrical: management hears a fast yes where one is earned, and a precise no where it is not. A decline that states its reason in a single sentence is far more useful to an executive team than a deferral wrapped in unease.
The half-page template
The statement he recommends has one row per class and seven columns: class, example uses, loss cap, detection time, escalation trigger, owner and review date. Naming one owner per row, and a review date, is what stops the document from becoming shelfware. He suggests two reviews a year, and an early one after any event that crosses a trigger.
Limits of the method
Dr. Tebaa is explicit that the numbers are a composite and must be sized to each organisation's balance sheet and sector. Regulated firms, he says, should align the statement with the risk appetite framework their regulator already requires instead of building a rival one. He frames the method as governance practice, not legal or regulatory advice.
The full worked example, including the template and a 90-day plan for getting a first version approved, is in his article The Half-Page AI Risk Appetite Statement Every Board Needs on jonahtebaa.com.
Related evidence: Article 26(2) of the EU AI Act requires deployers of high-risk AI systems to assign human oversight to natural persons who have the necessary competence, training and authority, as well as the necessary support — so the oversight duty lands on a named person who must actually be empowered to act, not on a department. Article 26 sits in Chapter III, Section 3, whose date of application was moved by Regulation (EU) 2026/1744 to 2 December 2027 for Annex III high-risk systems and 2 August 2028 for Article 6(1) product-embedded systems. (Article 26(2) of the EU AI Act)
The UK government's introduction to AI assurance defines AI governance as a range of mechanisms, including laws, regulations, policies, institutions and norms, used to outline processes for making decisions about AI. (the UK government's introduction to AI assurance)