1,612 risks. Where KTP has grip.
Every baseline risk in MIT's AI Risk Repository, scored against the nine KTP enforcement primitives. Mean pressure score 41.0. The distribution is bimodal: a low-relevance peak and a high-relevance peak, with an honest middle. The cleanest cell in the matrix is Privacy & Security, which maps entirely to Boundary enforcement (see architecture for where that enforcement lives).
One caveat on what this measures. The scorecard scores the can axis: capacity and safety failures, the kind that turn into incidents, like data exfiltration or tool misuse. It does not yet score the should axis: actions that are authorized and safe but wrong for the moment, like a disclosure during a regulated quiet period. Those leave no signal in the matrix below. Appropriateness is the second scoring dimension, and the next axis this scorecard will grow.