Safety & Design
AI risk assessment
A process for finding and reducing ways an AI system could cause harm, including privacy, bias, and safety, before and after it ships.
- Businesses
- Educators and school leaders
- Policymakers and staff
What parents should know
An AI risk assessment is a repeating process, not a sticker. You name how the system could hurt people, you reduce what you can, and you look again after launch. NIST's AI Risk Management Framework is the public reference this page uses. It is guidance, not a HeyOtto certification.
On this page
What is an AI risk assessment?
The assessment lists the people who could be harmed, the data the system sees, and the decisions it influences. For a children's chatbot that list includes a wrong answer treated as fact, a private chat seen by the wrong adult, a biased reply about a group of students, and a distress message that nobody notices. Severity and how often it could happen are both part of the note.
NIST's framework organizes this work so a team can govern, map, measure, and manage AI risk. You do not need NIST's vocabulary to ask the questions. You do need a written answer and a person who updates it when the model or the audience changes.
Why an AI risk assessment matters
Shipping without that note means the first review is a parent complaint or a news story. Schools and buyers are right to ask for the note. They are also right to ask what the product refuses to claim, such as a guarantee that no one can bypass a filter.
HeyOtto can describe controls that exist: parent-readable chats, topic limits, no ads, and a distress alert that does not call emergency services by itself. Those are inputs to a risk assessment. They are not the assessment.
How it shows up in practice
- A vendor questionnaire asks who can see student prompts and whether they train the model.
- A bias check looks at how the tool talks about groups of students, not only at whether it blocks a slur.
- A new tool, such as image generation, gets its own line instead of inheriting the chat review.
- A residual risk is written down, including that filters can fail.
How HeyOtto helps
An AI risk assessment names harms and the controls that reduce them. HeyOtto does not claim a NIST certification. A parent can read chats, set topic limits, and get an alert with crisis resources if a child is in distress. There are no ads, and chats are not sold or used to train other models.
- Parents can read the chats.
- Topic limits and tool permissions are per child.
- Under 13, verifiable parental consent is part of setup.
For schools
Request a demoFAQs
Is NIST's framework a law?
No. It is a voluntary framework from the National Institute of Standards and Technology. Citing it does not make a product certified.
What risks matter most for kids?
Privacy of the chat, age-inappropriate content, a reply that is confidently wrong, and distress that does not reach an adult. Bias matters too, especially in school uses.
Can an assessment prove a jailbreak is impossible?
No. A serious assessment says filters can fail and says what a parent can still see. HeyOtto does not claim jailbreaks never work.
Sources
Last reviewed September 26, 2026. This entry is reviewed twice a year.
