Methods, limits, what comes next.
KTP does not solve all AI risk. That is why it is credible. The v0.2 Scorecard is a deterministic first-pass review expansion, not human adjudication or empirical validation. This page says what that means, and what it does not.
§01provenance
| run date | 2026-05-04 |
| row count | 1,612 baseline risks |
| baseline input | KTP_RPT_Enriched_Master_v0_1.csv |
| source: MIT AI Risk Repository | airisk.mit.edu |
| source: MIT AI Risk Mitigations | airisk.mit.edu/ai-risk-mitigations |
| source: MIT AI Incident Tracker | airisk.mit.edu/ai-incident-tracker |
| source: Kinetic Trust Protocol | kinetic-trust-protocol.net |
The MIT AI Risk Repository is the external risk universe; the Scorecard is KTP's audited response. Neither was generated by the other. The match is the test.
§02limitations (verbatim)
“v0.2 is a deterministic first-pass review expansion, not human adjudication or empirical validation.”
That sentence is doing real work. It says: every score in the 1,612-row matrix was assigned by a deterministic ruleset against the MIT risk text, not by a panel of human reviewers and not by comparison to real incidents. The scoring is reproducible. It is not yet validated.
Read the Scorecard accordingly: as a first map of where KTP could plausibly apply, where it explicitly does not, and where its claims are still at the conceptual or mechanistic tier rather than the scenario-supported one. The 170 P0 risks flagged for human adjudication, the 819 candidates for incident backtest, and the 337 generated test cases are exactly the work the v0.3+ passes will do.
§03failure modes
Naming the failure modes is what allows defense-in-depth. These are the seven explicit ways a KTP-class architecture can fail to govern an action. Read them as what the surrounding controls must handle, not as what makes KTP a bad bet. For where the enforcement surfaces are designed, see architecture.
§04what v0.3+ will add
The next passes turn the deterministic first-pass into something adjudicated, backtested, and run.
§05the bounded public claim
“KTP directly addresses the subset of AI risks that depend on autonomous action, tool use, data movement, delegation, transaction, or boundary crossing. For other risks, KTP may provide accountability, telemetry, or governance evidence, but not direct mitigation.”
“KTP is useful, but the verb framing risks collapsing too much complexity into action labels. AI risk does not always present as a clean action event. Some harms are cumulative, statistical, latent, delegated, or structural. If KTP claims to make AI risk governable by controlling verbs, it may overstate its reach. To be credible, KTP must distinguish between risks it can directly constrain, risks it can only observe, risks it can route to governance, and risks outside its scope.”
“Correct. KTP is not a theory of all AI risk. It is a control methodology for the action layer of AI risk. Its value is not universal coverage. Its value is disciplined translation: when a risk becomes an attempted motion, KTP asks whether that motion should be allowed, constrained, delayed, logged, challenged, routed, or denied.”
§06the governability ladder
The word governable does too much work on its own. Governable can mean observable, attributable, constrainable, interruptible, reversible, or pre-authorized. These are not the same thing. The ladder makes the difference explicit.
| L0 | not visible | The action happens without leaving a trace the environment can see. |
| L1 | observable | The action is logged. Something happened, and the record exists. |
| L2 | attributable | The action can be traced back to a specific actor, agent, or trajectory. |
| L3 | constrainable | The action's scope, rate, or parameters can be limited at the moment of execution. |
| L4 | interruptible | The action can be stopped mid-flight, by policy or by escalation. |
| L5 | reversible / containable | The consequence can be rolled back, or its blast radius is bounded by design. |
| L6 | pre-authorized / pre-denied by policy | The decision is made before the action is attempted; the environment refuses or permits without negotiation. |
KTP does not make every risk preventable. It moves risks up the governability ladder.