Risk-impact matrix: which AI project to start with

How to prioritize AI projects by crossing business impact with risk of error. Start with high-impact, low-risk work, without burning your budget.

Risk-impact matrix: which AI project to start with

Most companies pick their first AI project based on what sounds most impressive, not on what is least likely to go wrong. The result is almost always the same: an expensive, highly visible pilot that fails in front of the customer and leaves everyone feeling that “this AI thing wasn’t for us”.

The risk-impact matrix flips that order. It is a simple way to decide where to begin: you cross how much value a project delivers if it works (its business impact) against what happens when the AI gets it wrong (its risk of error). The starting rule is to begin with high-impact, low-risk work. Boring to present in a meeting, but it is what builds confidence without gambling your reputation.

What is the risk-impact matrix and why does the order matter?

The risk-impact matrix is a square split into four parts. You place each AI idea you have on the table according to two questions, and its position tells you what to do with it: start now, make it conditional, or park it.

Before going further, a quick vocabulary note so nobody gets lost. When I say “AI” here I mean these tools that generate text, images, or answers from a request, in the style of ChatGPT. Under the hood they run on a language model, which in the jargon you will see as LLM: a program that has learned to predict the most probable answer to what you ask it. The key word is “probable”. It is not looking for the truth, it is looking for what sounds right. That distinction is exactly what drives the risk axis.

The order matters because your first project is not just a project. It is the one that decides whether your team and your leadership believe AI is good for anything. If you start with the flashiest option and it goes wrong, you don’t just lose that pilot: you lose permission to try the next ones.

Axis 1: business impact

Business impact measures how much your company changes if the project genuinely works. Not how cool it is, not how much people talk about it on LinkedIn. How much it moves the needle.

To score it, ask yourself concrete, measurable questions:

  • How many hours of work per month does it save, and for whom?
  • Does it touch many customers or a rare case that happens twice a year?
  • Does it cut a real cost or just move it somewhere else?
  • Does it unlock something you simply cannot do today?

A high-impact project answers with numbers anyone on your committee would understand: “it saves the equivalent of half a full-time person” or “it affects the process that brings in half of our revenue”. A low-impact one sounds like “it would be nice to have” and nobody can say why.

Watch out for a very common mistake here: confusing impressive with impactful. An assistant that answers questions on your website in natural language impresses in the demo. But if a help page already answered those questions well, the real impact is small. Impressing is an emotion. Impact is counted in time, money, or customers.

Axis 2: risk of error (and why the AI always gets it a bit wrong)

The risk of error measures what happens when the AI gives a wrong answer, because it will. This is the point almost nobody tells you in the optimistic presentations: an LLM is not a calculator. A calculator that adds two and two gives four every time. A language model, faced with the same question, can give you a good answer today and a confident but false answer tomorrow.

That failure is called a hallucination: the AI generates an answer that sounds perfectly believable, written with total confidence, but is incorrect. It gives no warning. It does not flag “I’m making this up”. And that is exactly the danger for a business, because the error arrives wrapped in a convincing answer.

So the question on the risk axis is not “can it get it wrong?”. The answer is always yes. The question is: what happens when it gets it wrong?

  • If an employee catches the error before it goes out, the risk is low. They fix it and that’s that.
  • If an error goes straight to the customer, to a contract, or to an invoice figure, the risk is high. It costs money, it costs a customer, or it costs reputation.
  • If an error touches personal data or something regulated, the risk is high for real, with possible legal consequences.

To dig deeper into how to assess this sensibly you have the analysis of AI risks in the company, which breaks down the types of risk one by one. Here we keep the idea that drives the matrix: risk is not the probability of failure, it is the cost of failure.

The four quadrants: start, make conditional, discard

When you cross the two axes you get four zones, and each one has a different decision. This is the heart of the matrix.

1.00

The logic of each quadrant:

  • High impact, low risk (start here). It delivers value and, if it fails, someone catches it before it reaches the customer. This is your first project. Not the flashiest, the most sensible.
  • High impact, high risk (make conditional with oversight). Worth it for the value, but don’t let it loose without a safety net. Put a person to review each output before it goes out, and reduce the scope until you trust it.
  • Low impact, low risk (optional). It does no harm, but it changes nothing either. Filler. Do it if you have spare time, never before the green quadrant.
  • Low impact, high risk (discard). Little to gain and much to lose. Park this without regret.

Put into a table, with illustrative examples (invented to explain, not real cases):

QuadrantDecisionIllustrative example
High impact / low riskStart nowSummarizing hundreds of survey responses internally so your team reads them in minutes, not days. If the summary fails, your team sees it, not the customer.
High impact / high riskMake conditional with oversightDrafting commercial proposals. A big time saving, but an invented figure in an offer is a serious problem. A person validates before sending.
Low impact / low riskOptionalGenerating ideas for the name of an internal campaign. Fun, harmless, irrelevant to the bottom line.
Low impact / high riskDiscardA bot that answers customer legal queries on its own with no review. Low volume, serious consequences if it gets it wrong.

Notice the pattern. Risk does not decide on its own whether you do something or not. It decides how much human oversight you put on top of it. A high-risk project is not forbidden: it is conditional on someone watching it.

How to place your projects on the matrix

Take your three, four, or five AI ideas and score each one from one to five on the two axes. You don’t need laboratory precision, you need relative order: which one weighs more than which.

For the impact axis, ask yourself for each idea:

  • How many people or how much money does it affect if it works?
  • Is it a recurring saving or a one-off?
  • Could you explain it to your committee in one sentence with a number in it?

For the risk axis:

  • Who sees the result before it takes effect: an employee or the customer?
  • Does an error cost a bit of work or does it cost money, a customer, or a fine?
  • Is there personal data or anything regulated involved?

With the two scores you place each idea in its quadrant. And here comes the uncomfortable part: almost always the project you were most excited about falls in the high-risk zone, and the one you thought was dull turns out to be the high-impact, low-risk one. That is exactly the job of the matrix. Taking the decision out of your gut and putting it in front of you in cold blood.

Placing your projects well is judgment, and judgment can be trained. It is what we work on step by step in the AI without hype course: learning to look at AI for what it does and for what it can get wrong, not for what it promises.

One new concept every week

What the matrix does not solve

The matrix is a starting filter, not a crystal ball. It helps to be clear about what it does not do, so you don’t ask it for what it cannot give.

It does not remove risk. A project landing in the low-risk quadrant means a failure is cheap to fix, not that it won’t fail. Human oversight is still needed.

It does not replace a small pilot. Prioritizing tells you where to begin. The next step is to test it small and measure, and that is another discipline: you have it in from idea to AI pilot. The matrix picks the candidate; the pilot confirms whether it really works.

It is not a final decision or legal advice. It is a snapshot of the moment. Your priorities change, a new tool appears, or a rule gets clarified, and a project jumps quadrant. If there is data regulation or sensitive sectors involved, the matrix helps you sort things out, but the final decision needs someone who knows the law.

This exercise is one piece within a broader map of AI use cases in companies. Prioritizing well is what keeps that map from staying a list of good intentions.

Checklist to prioritize your AI projects

  • You have listed every AI idea competing for budget
  • Each idea has a business-impact score with a number behind it (hours, money, or customers)
  • Each idea has a risk score based on the cost of the error, not its probability
  • You know who sees each result before it takes effect: employee or customer
  • Your first project sits in the high-impact, low-risk quadrant
  • The high-risk projects you keep have human oversight assigned
  • You have parked, guilt-free, anything low-impact and high-risk

Frequently asked questions

Where do I start if all my projects look high-risk?

Cut the scope of the one with the most impact until the risk drops. Almost any high-risk project has a small, controlled version: instead of the AI answering the customer on its own, have it prepare a draft that a person reviews. That reduced version usually lands in the low-risk quadrant and lets you start and learn without exposing yourself.

Does the risk-impact matrix work for a small company or only for large ones?

It works just as well or better for a small company, because when the budget is small, picking the wrong first project hurts more. The method is the same regardless of size: fewer ideas on the table make prioritization faster, not less useful. A small company doesn’t need a consultancy to draw a square and place four ideas inside it.

How often should I review the matrix?

Review it when something changes that moves a project between quadrants: you finish a pilot, a new tool appears, or a rule gets clarified. As a reference, every few months is a reasonable rhythm for most companies. It is a snapshot that gets updated, not a paper you sign and file away in a drawer.

Isn’t starting with high-impact, low-risk work just settling for the boring stuff forever?

It is starting with the boring stuff, not staying there. The low-risk quadrant is the entry door: when that first project works, your team learns, your leadership believes it, and you earn permission to move on to high-impact, high-risk projects with oversight. The flashy work arrives sooner if you build on a base that already works.