Caption: Michael, K. (2026). Risk intelligence in the age of Generative AI. International Journal of Contemporary Intelligence Issues, 3(1), 38–51. https://search.informit.org/doi/10.3316/informit.T2026083100008001471207603

Photo by Google DeepMind

Abstract

This paper argues that meaningful convergence is occurring between risk management and the intelligence cycle, yielding an emergent practice termed risk intelligence. Drawing on security convergence theory, enterprise risk management frameworks, and intelligence studies literature, the paper traces how organisational, process, product, and information-level convergence have progressively dissolved the boundaries between these two disciplines. The paper maps the structural parallels between the risk management process and the intelligence cycle, culminating in the concept of Risk Management Based Intelligence (RMBI). It then situates Generative Artificial Intelligence (GenAI) as both a catalyst and a complicating variable in this convergence: while GenAI dramatically accelerates data synthesis, translation, and predictive analysis, it simultaneously introduces new uncertainties around source transparency, hallucination, adversarial disinformation, and the erosion of human analytical judgement. Six evolutionary trends shaping the intelligence community are identified, from the big data revolution to the prospect of human-machine teaming. The paper concludes that the promise of risk intelligence as a unified business process is real but will remain unrealised without sustained investment in analyst professionalisation, governance frameworks, and the principled integration of GenAI tools that keep humans meaningfully in the loop. 

Keywords: Risk Intelligence; Intelligence Cycle; Generative AI 

1.0 Introduction

This paper argues that a process of convergence is underway between two historically separate disciplines—risk management and intelligence—and that their integration is giving rise to what is now termed risk intelligence. The security environment has undergone steep and, by some accounts, revolutionary change in the way the intelligence community (IC) functions (Borodzicz, 2005). That change is characterised by a cultural shift away from siloed, stovepipe thinking toward transparent information sharing across organisational boundaries (U.S. Government Accountability Office, 1998, p. 28).

The paper proceeds as follows. Section 2 defines security convergence and identifies its principal forms. Section 3 describes the risk management process and its relationship to national security. Section 4 outlines the intelligence cycle. Section 5 examines the integration of risk analysis into that cycle and introduces risk intelligence as a business process. Section 6 addresses Generative AI (GenAI) as a technology catalyst—and source of significant new uncertainty—for intelligence practitioners. Section 7 concludes.

Four research questions animate the paper: (1) How can security convergence be characterised across its multiple forms? (2) What is risk intelligence as a business process within a national security context? (3) What technological waves have impacted the intelligence community over the past two decades? (4) What are the benefits and risks of adopting GenAI techniques within the risk intelligence cycle—particularly for professional intelligence officers?

2.0 Security convergence

The term convergence has its roots in mathematics and the natural sciences dating back to the late sixteenth century (Borodzicz, 2005, p. 13). In its modern application it describes evolutionary trends in technological development and the symbiosis that emerges between products and processes. At the enterprise level, convergence is observable as discrete business units coming together to enhance security and competitive advantage (Booz Allen, 2005, p. 6). At the state level, it manifests as agencies that begin to resemble one another collaborating to meet performance criteria, reduce duplication, and ultimately deliver more effective national security outcomes. ASIS International defines security convergence as "the identification of security risks and interdependencies between business functions and processes within the enterprise and the development of managed business process solutions to address those risks and interdependencies" (Booz Allen, 2005, p. 6).

Johnson and Spivey (2008, p. 31) related this to enterprise security risk management (ESRM), emphasising the combined management of physical and logical security as a "holistic risk management process that aligns organisational drivers affecting strategy, processes, people, technology and knowledge to protect key assets..." ESRM functions only through cross-functional collaboration—security and safety, legal and risk management, business continuity—working in concert.

2.1 Types of security convergence

This paper engages convergence at four levels. First, convergence of security organisations at the national and enterprise level, including companies offering solutions to the IC and government agencies working together more effectively than as stand-alone entities (Pathak, 2005, p. 569). Second, convergence of security processes and standards, involving the identification of risks and interdependencies and the development of managed solutions across business functions (Peterson, 2006, p. 3). Third, convergence of security products and services—different companies' people and IT systems working together to deliver convergent outputs (Layton, 2008, p. 2). Fourth, convergence of information: sources and quality content drawn upon across technical, human, and open-source intelligence disciplines (Peterson, 2006, p. 3).

Convergence is described as ideal for "managing uncorrelated risk through a systematic, coordinated process" (Williams, 1999, p. 14). However, the complexity of transforming dozens of agencies into an effective collaborative whole should not be understated (Wrightson and Caldwell, 2005, p. 8). Policies and processes once created in silos do not yield easily to collective sense-making (Podowitz and Tretick, 2008, p. 1). At the enterprise level convergence is compliance-driven; within government, it often required major intelligence failures before meaningful reform was initiated.

2.2 Security as a value-add capability

The convergence phenomenon reflects a fundamental shift in mindset—security is now understood as a "value add" to the overall mission of organisations and agencies alike (Booz Allen, 2005, p. 4). It is a recognition that security cannot be achieved in isolation. No event demonstrated this more starkly than September 11, 2001, which exposed the failure of intelligence agencies to share information regarding potential terrorist targets. An inquiry into FBI practices concluded that the main problems were severely inadequate ICT systems, an inability to integrate HUMINT and TECHINT for all-source analysis, and deficiencies in analyst recruitment and training (Gill, 2004, p. 475).

Enabling high technologies, new compliance regimes, and the primacy of information-based assets have collectively blurred traditional functional boundaries and intensified the impetus toward convergence (Booz Allen, 2005, p. 8). Security convergence has driven change across people and their roles, processes and standards, and enabling technology. Despite this long trajectory, no force has propelled change in the IC as powerfully as GenAI, which is directly reshaping the role of the individual intelligence analyst. As Usher et al. (2024) noted, the Large Language Models (LLMs) likely to be available within the next three years "will probably far surpass the capabilities of systems we use today and will be able to solve complex problems, take action to collect and sort data, and deliver well-reasoned assessments at scale and at speed."

3.0 The risk management process

Merkow and Breithaupt (2006, p. 27) argued that "security equals risk management," a position endorsed by Borodzicz (2005, p. 50). Risk, properly conceived, is enterprise-wide and industry-agnostic: different fields—IT, insurance, finance—have at times claimed ownership over risk management, yet risk pervades every sector (Dhillon, 2007, p. 157; Miccolis, 1996, p. 46). Traditionally, risk was understood in terms of physical assets—"the potential that a given threat will exploit vulnerabilities of an asset or group of assets and thereby cause harm" (ENISA, 2008, p. 4). Today, risk management is concerned with the organisation's strategic-level initiatives encompassing both physical and logical assets (Slay and Koronios, 2006, p. 2), and the business of risk has changed significantly in the AI era (Menzies et al., 2024).

Enterprise risk management (ERM) brings business functions closer together within a common risk-based framework for better decision-making (Miccolis, 1996, p. 48). The standard risk management cycle—regardless of whether it derives from the OECD, ISO, national standards bodies, or individual organisations—encompasses four core steps: (1) assess risk and determine needs; (2) implement appropriate policies and related controls; (3) promote awareness; and (4) monitor and evaluate policy and control effectiveness (Peltier, 2001, pp. 17–19). The current international standard is ISO 31000:2018 (ISO, 2018).

In a national security context, risk management can be defined as "a strategy for helping policymakers make decisions about assessing risks, allocating resources, and taking actions under conditions of uncertainty" (Wrightson and Caldwell, 2005, p. 8). This framing directly prefigures its integration with the intelligence cycle, explored in the next section.

4.0 The intelligence cycle

The intelligence cycle (Johnson, 1986) can be defined as "the process by which information and data is collected, evaluated, stored, analyzed, and then produced or placed in some form for dissemination to the intelligence consumer for use. The cycle consists of: consumer, collector, evaluation, analysis, production, dissemination, consumption, consumer" (U.S. Government Accountability Office, 1998, p. 27). The New Zealand Qualifications Authority (NZQA, 2003) defines intelligence as the collective functions involved in "planning, gathering and analyzing information of potential value to decision makers, and to the production of intelligence." The goal is to "produce guidance based on available information within a time frame that allows for purposeful action" (Willis, 2007, p. 3).

Modern iterations of the cycle have added an initial requirements phase, enabling policy makers to submit a Request for Information (RFI) to direct the intelligence effort (Directorate of Intelligence, 2008). Data is then collected, processed, analysed, and disseminated. The collection phase draws on varied sources—public, foreign, intercepted communications—combined with open-source intelligence (OSINT) including news media and official documents (Miller, 2008, p. 4).

The processing phase—historically described as the "fusion centre" (U.S. Government Accountability Office, 1998, p. 27)—is where different data sources are reconciled and linkages drawn between structured and unstructured data. It can be argued that this fusion centre has now acquired a front-end interface through Generative Pre-Trained Transformer (GPT) models and large language models. Yet this development introduces a critical complication: because GenAI sources are not explicitly referenced, assessing the overall quality of the output is increasingly difficult. Analysis and production follow, yielding intelligence products categorised by use, such as indications and warning or counterintelligence (Miller, 2008, p. 4). Common analytical techniques—association analysis, temporal and spatial charting, link and financial analysis—remain relevant but can now be semi- or fully automated, dramatically compressing production timelines (U.S. Government Accountability Office, 1998, p. 27).

5.0 Integrating risk analysis into the intelligence cycle

5.1 From linear to network-centric

Both the risk management process and the intelligence cycle are, in practice, not linear but network-centric, meshed, and highly collaborative. The actual steps or phases are not contested; rather, it is the way stakeholders interact that has changed. The shift is toward a network-centric collaboration process using a target-centric approach to interlink collectors, processors, analysts, and policy makers through a centralised means to enable decentralised decision-making (Clark, 2004, pp. 17–18; Barger, 2005, p. 20). The U.S. National Infrastructure Protection Plan (NIPP) exemplifies this, describing "a shift from a strictly hierarchical to a networked model, allowing distribution and access to information both vertically and horizontally, as well as the ability to enable decentralised decision making and actions" (US Department of Homeland Security, 2013, p. 2).

5.2 Risk management based intelligence

The integration of the risk management process and the intelligence cycle have been formalised as Risk Management Based Intelligence (RMBI) (Ylönen and Aven, 2023). Willis (2007, p. 3) argues that risk analysis can sharpen intelligence products and prioritise resource allocation, providing "analytic support for identification of scenarios of greatest concern." The U.S. Government Accountability Office (1998, p. 28) defines RMBI as: "an approach to intelligence analysis that has as its object the calculation of the risk attributable to a threat source ... a means of providing strategic intelligence for planning and policy making especially regarding vulnerabilities and countermeasures ... can be quantitative if a proper database exists ... can be qualitative, subjective and still deliver a reasonably reliable ranking of risk for resource allocation." Critically, the same caveats that apply to risk analysis apply to GenAI-generated intelligence products: neither is fool-proof (Vogel et al., 2024).

From RMBI stems a still closer relationship—symbiosis—observable at organisational, process, product, and information levels (Anderson, 2007, p. 7). It is information convergence, now described as big data, that has most profoundly reshaped the IC's culture (Michael and Miller, 2013). As Peterson (2006, p. 1) argued, the world is converging around the value of information—information is simultaneously the chief asset and the chief risk of the enterprise. Robinson (2007, p. 4) described the creation of "a common data structure for risk and control processes and a common technology architecture"—a common language that fosters communication, coordination, and understanding. Yet the proliferation of disinformation through deepfake technology poses a significant liability to this end-to-end process: any organisation is only as good as the quality of its data.

5.3 Risk intelligence as a business process

Restating Sherman Kent's classical definition of intelligence as a form of knowledge, information convergence can be understood as enabling business processes between members of the IC (Rathmell, 2002, p. 88). Today, risk intelligence (RI) has emerged as a fully-fledged business process (Azvine et al., 2007, p. 155). Consulting firms Deloitte (2025) and KPMG (2025) have each developed RI frameworks. The risk-intelligent organisation bridges silos, speaks a common language, conducts impact assessments, weights vulnerabilities, allocates resources appropriately, and pursues risk for higher reward (Layton, 2008, p. 2).

It was at the turn of the millennium that information and communication technology solutions became available to solve the problem of islands of information through electronic resource planning systems (ERP), many of which contained a business intelligence module to go beyond data warehousing. As Gill (2004, p. 476) pointed out, “the construction of ever-larger databases, data warehousing and data-mining, though of great significance in intelligence, cannot ‘solve’ intelligence problems without a process of targeting, careful evaluation of information and human analytical skills.” GenAI appears to grant individual analysts new-found capabilities, but scrutiny is rapidly shifting from the product to the process: how analysts prompt GenAI tools, and how the accuracy and validity of outputs can be certified (Abbass et al., 2024). Despite advances in data analytics, human-centred capabilities remain indispensable to ensure that humans are not out-of-the-loop when AI is deployed (Michael et al., 2024; Michael et al., 2023).

5.4 Challenges for the risk intelligence process

Several persistent challenges confront the IC. Even setting aside the complexities of organisational convergence, competent analysts who understand data and can navigate increasingly complex technical products remain essential—particularly in the AI era (Usher et al., 2024). Pre-GenAI, Lahneman (2006, p. 3) warned that the IC of 2020 would face "an imbalance between the demand for effective overall intelligence analysis and the outputs of the individually-oriented elements." GenAI has arguably exacerbated this imbalance.

Governance represents perhaps the largest challenge: how to build an integrated intelligence culture, break down the secrecy barrier, and maintain appropriate access controls. Lahneman (2006, p. 10) described the U.S. IC as a "community that isn't"—a series of nearly autonomous organisations, each with its own way of doing business, a fragmentation ill-suited to analysing dispersed threats. Trust in people and systems, enforceable policies, and adequate coordination between agencies and third-party data providers will be paramount (Michael et al., 2024). Without appropriate governance, the risk is a shift from too much information and too little knowledge to too many informational products and no confidence in the knowledge outcomes used to make decisions affecting nation states.

6.0 GenAI: the ultimate technology convergence catalyst—and its uncertainties for professional intelligence officers

Technology has always been the catalyst for change in the IC—through AI, machine learning, and now GenAI (US DOD, 2023; SCSP, 2024). GenAI is exerting pressure on IC agencies to adopt the technology at every stage of the risk intelligence cycle in a layered fashion, building on each successive breakthrough (Dahl and Strachan-Morris, 2024). This acceleration brings strategic opportunities and commensurate risks. Any advantage conferred by GenAI can be replicated by competing institutions and adversarial states—who may also flood OSINT and other intelligence channels with disinformation to undermine the entire risk intelligence process (SCSP, 2024). This has been described as the AI paradox (Michael et al., 2023).

GenAI is currently used for: (1) summarisation and translation; (2) data processing and synthesis; (3) predictive analysis; and (4) report validation, accuracy checking, and bias detection. In the near term, analysts will be deploying GenAI in automated decision-making (ADM) pipelines operating across multiple information sources with minimal human intervention. At that point, the risk of AI-generated intelligence products may far outweigh the value of the insights—particularly in an era of adversarial disinformation campaigns where the quality of underlying data cannot be assured.

6.1 What GenAI uncertainties mean for professional intelligence officers

For the professional intelligence officer, GenAI introduces a distinctive and multi-layered set of uncertainties that differ fundamentally from those associated with earlier information technologies.

The first is epistemic opacity. Unlike a human analyst whose reasoning can be examined and challenged, LLMs do not cite their sources transparently. An intelligence product derived from or assisted by a GenAI tool may reflect biases embedded in the pre-training corpus—biases invisible to the analyst consuming the output. The risk of confident-sounding but factually incorrect claims, commonly termed hallucination, is especially dangerous in high-stakes assessments where errors can have strategic consequences. Professional officers must therefore develop new critical appraisal skills directed not only at incoming raw intelligence but at GenAI-generated synthesis itself.

The second is adversarial exploitation. Adversarial state and non-state actors have rapidly understood that GenAI lowers the cost of producing large volumes of plausible disinformation. Deepfake audio, video, and text can be injected into OSINT streams at scale and speed. For an analyst relying on GenAI to aggregate and summarise open sources, the risk is that disinformation is not merely included but amplified—with the LLM's pattern-matching capabilities potentially lending false coherence to fabricated narratives. The downstream effect is the corruption of the data layer on which RMBI depends (Bajak, 2024).

The third uncertainty concerns the pace of technological change relative to institutional governance. The pacing problem—whereby the deployment of a technology outstrips the governance frameworks designed to regulate it—is acute with GenAI. IC agencies adopting GenAI tools ahead of robust validation, certification, and oversight regimes risk layering AI-driven errors on top of one another across successive assessments. As new capabilities become available, cognitive overload and inadequate testing may further compromise accuracy. Mueller (2011) emphasised the necessity of a "continuous intelligence cycle that drives investigative strategies," but continuity requires consistency of standards; and GenAI disrupts that consistency if inadequately governed.

The fourth uncertainty is the threat to analyst professional identity and skill maintenance (Coulthart et al., 2024). If GenAI tools routinely produce first-draft summaries, pattern analyses, and even finished assessments, there is a genuine risk that the analytical skills—critical thinking, source evaluation, structured analytic techniques—that underpin quality intelligence atrophy from disuse. Professionalisation of the intelligence analyst role, including accreditation standards and ongoing training, is widely recommended as a countermeasure (Azvine et al., 2007, p. 155). Ensuring that GenAI augments rather than supplants human analytical capacity is not simply a technical challenge; it is a professional and institutional one requiring deliberate policy choices.

The fifth concerns certification and accountability. When an intelligence product contributes to a policy decision that proves wrong, the question of accountability is straightforward in a human-analyst model. In a GenAI-assisted or GenAI-generated model, accountability becomes diffuse—spread across the tool developer, the procurement decision-maker, the analyst, and the officer who acted on the product. The shift in attention from product to process noted by Abbass et al. (2024) is precisely a response to this challenge: certification frameworks that audit the prompting process, the data inputs, and the validation steps are needed to maintain accountability chains.

Six broad trends across the last two decades capture the trajectory of the IC's evolving relationship with technology: (1) the big data revolution—gathering and sharing structured and unstructured data at scale (Michael and Miller, 2013; Vogel, 2021); (2) the professionalisation of the intelligence analyst role (Mueller, 2011); (3) the growth of risk intelligence across private, public, and government sectors (US DOD, 2023); (4) commitment to responsible AI adoption as a strategic advantage (US DOD, 2023); (5) acknowledgement that GenAI has a role to play but remains nascent, particularly regarding predictive models and deepfake risks (Bajak, 2024); and (6) the emergence of human-machine teaming for decision-making, requiring greater governance to ensure meaningful human oversight (SCSP, 2024). Together these trends are advancing the data, analytics, and AI ecosystem across the entire information supply chain (Clark, 2023).

7.0 Conclusion

The overarching benefit of convergence in maintaining national security is strategic: remaining one step ahead of adversaries to prevent attacks, minimise surprise, and reduce overhead through the elimination of duplication. Today, convergence is about creating opportunities and emergent benefits that cannot be achieved individually. The trend toward unified risk intelligence programs aims to reduce risks and increase control through quality intelligence.

This paper has charted the convergence of risk management and the intelligence cycle into the emergent discipline of risk intelligence and has situated GenAI as both its most powerful enabler and one of its greatest contemporary risks. GenAI accelerates the risk intelligence cycle at every stage, but introduces epistemic opacity, adversarial exploitation risks, governance challenges, professional skill atrophy, and accountability diffusion that professional intelligence officers are only beginning to grapple with. The promise of risk intelligence as a coherent, integrated business process will remain unfulfilled without sustained investment in governance frameworks, analyst professionalisation, and a principled commitment to human oversight. Whether the technology available today is propelling the IC toward a more secure future, or generating new and unforeseen vulnerabilities, remains an open—and urgent—question.

References

Abbass, H., Michael, K., & Vogel, K.M. (2024). Swarm Metaverse: Understanding Socio-Technical Innovation and Trust Before Certification, ADSTAR: Australian Defence Science, Technology and Research, 18 September 2024. <https://www.adstarsummit.com.au/> Accessed: 3 January 2025.

Anderson, K. (2007). Convergence: A holistic approach to risk management. Network Security, 4–7.

Azvine, B., Cui, Z., Majeed, B., & Spott, M. (2007). Operational Risk Management with Real-Time Business Intelligence. BT Technology Journal, 25(1), 154–167, https://doi.org/10.1007/s10550-007-0017-5.

Bajak, F. (24 May 2024). U.S. intelligence agencies' embrace of generative AI is at once wary and urgent, PBS. <https://www.pbs.org/newshour/world/u-s-intelligence-agencies-embrace-of-generative-ai-is-at-once-wary-and-urgent> Accessed: 3 January 2025.

Barger, D.G. (2005). Toward a Revolution in Intelligence Affairs, RAND Corporation. <http://www.rand.org/pubs/technical_reports/2005/RAND_TR242.pdf> Accessed: 2 February 2008.

Booz Allen. (8 November 2005). Convergence of Enterprise Security Organizations, The Alliance for Enterprise Security Risk Management. <www.asisonline.org/newsroom/alliance.pdf> Accessed: 1 May 2008.

Borodzicz, E.P. (2005). Risk, Crisis and Security Management. New York, Wiley.

Clark, J. (2023). DOD Releases AI Adoption Strategy, U.S. Department of Defense. <https://www.defense.gov/News/News-Stories/Article/Article/3578219/dod-releases-ai-adoption-strategy/> Accessed: 3 January 2024.

Clark, R.M. (2004). Intelligence Analysis: A Target-centric Approach. CQ Press.

Coulthart, S., Hossain, M.S., Sumrall, J., Kampe, C., & Vogel, K.M. (2024). Data-science literacy for future security and intelligence professionals. Journal of Policing, Intelligence and Counter Terrorism, 19(1), 40–60. https://doi.org/10.1080/18335330.2023.2187705

Dahl, E.J., & Strachan-Morris, D. (2024). Predictive intelligence for tomorrow's threats: is predictive intelligence possible? Journal of Policing, Intelligence and Counter Terrorism, 19(4), 423–435. https://doi.org/10.1080/18335330.2024.2404834

Deloitte. (2025). Risk Intelligence, Deloitte, <https://www2.deloitte.com/us/en/pages/risk/solutions/risk-intelligence.html> Accessed: 3 January 2025.

Dhillon, G. (2007). Information Systems Security: Text and Cases. Prospect Press, North Carolina.

Directorate of Intelligence. (2008). The Intelligence Cycle. Federal Bureau of Investigations. <http://www.fbi.gov/intelligence/di_cycle.htm> Accessed: 27 April 2008.

ENISA. (2008). Glossary of Risk Management. ENISA: A European Union Agency. <http://www.enisa.europa.eu/rmra/glossary.html> Accessed: 27 April 2008.

Gill, P. (2004). Intelligence and the Post 9/11 Shift. Intelligence and National Security, 19(3), 467–489.

ISO. (2018). Risk management — Guidelines. ISO. <https://www.iso.org/standard/65694.html> Accessed: 20 December 2008.

Johnson, L.K. (1986). Making the "Intelligence" Cycle Work. International Journal of Intelligence and Counter-Intelligence, 1(4), 1–23. https://doi.org/10.1080/08850608608435033

Johnson, M.P., & Spivey, J.M. (2008). ERM and the Security Profession. Risk Management, 55(1), 30–32, 34–35.

KPMG. (2025). KPMG Risk Intelligence: transform your risk management. KPMG. <https://kpmg.com/us/en/risk-intelligence.html> Accessed: 3 January 2025.

Lahneman, W.J. (2006). The Future of Intelligence Analysis: Volume I, Final Report. Center for International and Security Studies at Maryland. <http://www.cissm.umd.edu/papers/files/future_intel_analysis_final_report1.pdf> Accessed: 27 March 2008.

Layton, M. (2008). Urgent Convergence: Fostering Risk Intelligence in the Technology, Media & Telecommunications Industries. Deloitte. <www.deloitte.com/RiskIntelligence> Available: 27 April 2008.

Menzies, J., Sabert, B., Hassan, R., & Mensah, K. (2024). Artificial intelligence for international business: Its use, challenges, and suggestions for future research and practice. Thunderbird International Business Review, 66(2), 185–200. https://doi.org/10.1002/tie.22370

Merkow, M., & Breithaupt, J. (2006). Information Security Principles and Practice. Sydney, Pearson.

Miccolis, J.A. (1996). Towards a Universal Language of Risk. Risk Management, 43(7), 46.

Michael, K., & Miller, K. (2013). Big Data: New Opportunities and New Challenges. Computer, 46(6), 22–24. doi: 10.1109/MC.2013.196.

Michael, K., Abbas, R., & Roussos, G. (2023). AI in Cybersecurity: The Paradox. IEEE Transactions on Technology and Society, 4(2), 104–109, June 2023, doi: 10.1109/TTS.2023.3280109.

Michael, K., Schoenherr, J.R., & Vogel, K.M. (2024). Failures in the Loop: Human Leadership in AI-Based Decision-Making. IEEE Transactions on Technology and Society, 5(1), 2–13, March 2024, doi: 10.1109/TTS.2024.3378587.

Miller, J.O. (2008). Modeling the U.S. Military Intelligence Process. Department of Defense. <www.dodccrp.org/events/9th_ICCRTS/CD/papers/044.pdf> Accessed: 27 April 2008.

Mueller, R.S. (6 October 2011). Statement Before the House Permanent Select Committee on Intelligence. Federal Bureau of Investigation. <https://archives.fbi.gov/archives/news/testimony/the-state-of-intelligence-reform-10-years-after-911> Accessed 3 January 2025.

New Zealand Qualifications Authority. (2003). Intelligence Analysis: Demonstrate knowledge of the intelligence analysis process. New Zealand Government. <www.nzqa.govt.nz/nqfdocs/units/doc/18503.doc> Accessed 23 December 2024.

US Department for Homeland Security. (2013). National Infrastructure Protection Plan (NIPP) – Partnering for Critical Infrastructure Security and Resilience. US DHS. https://www.cisa.gov/sites/default/files/publications/national-infrastructure-protection-plan-2013-508.pdf, 11 March 2022.

Pathak, J. (2005). Risk management, internal controls and organisational vulnerabilities. Managerial Auditing Journal, 20(6), 569–577. https://doi.org/10.1108/02686900510606065.

Peltier, T.R. (2001). Information Security Risk Analysis. New York, Auerbach Publications. https://doi.org/10.1201/b12444.

Peterson, M. (2006). Information Convergence, Transforming the Information-Centric Enterprise. SNIA Data Management Forum. <www.sresearch.com/articles/SRC-DMF-Article_Information-Convergence_20060112.pdf> Accessed: 27 April 2008.

Podowitz, M., & Tretick, B. (8 January 2008). Compliance, Convergence and How IT Fits. CIO. <http://www.cio.com/article/print/170000> Accessed: 27 April 2008.

Rathmell, A. (2002). Towards Postmodern Intelligence. Intelligence and National Security, 17(3), 87–104. https://doi.org/10.1080/02684520412331306560.

Robinson, J. (2007). Risk Convergence: Future State. Ernst & Young Consulting. <http://www.ey.com> Accessed: 27 April 2008.

Schoenherr, J.R., Abbas, R., Michael, K., Rivas, P., Anderson, T.D. (2023). Designing AI Using a Human-Centered Approach: Explainability and Accuracy Toward Trustworthiness. IEEE Transactions on Technology and Society, 4(1), 9–23, March 2023. doi: 10.1109/TTS.2023.3257627.

SCSP. (April 2024). Intelligence Innovation: Repositioning for Future Technology Competition. Special Competitive Studies Project. <https://www.scsp.ai/wp-content/uploads/2024/04/Intelligence-Innovation.pdf> Accessed: 3 January 2025.

Slay, J., & Koronios, A. (2006). Information Technology and Risk Management. Wiley.

US DOD. (10 August 2023). DOD Announces Establishment of Generative AI Task Force. U.S. Department of Defense. <https://www.defense.gov/News/Releases/Release/Article/3489803/dod-announces-establishment-of-generative-ai-task-force/> Accessed: 3 January 2025.

Usher, W., Caples, A., Kurata, K., & Balakrishnan, N. (3 September 2024). The future of intelligence analysis: US-Australia project on AI and human machine teaming. ASPI: Australian Strategic Policy Institute. <https://www.aspi.org.au/report/future-intelligence-analysis-us-australia-project-ai-and-human-machine-teaming> Accessed: 23 October 2024.

Vogel, K.M. (2021). Big Data, AI, Platforms, and the Future of the U.S. Intelligence Workforce: A Research Agenda. IEEE Technology and Society Magazine, 40(3), 84–92, Sept. 2021, doi: 10.1109/MTS.2021.3104384.

Vogel, K.M., Abbass, H., Michael, K. (2024). The impact of AI on intelligence analysis: tackling issues of collaboration, algorithmic transparency, accountability, and management. ADSTAR: Australian Defence Science, Technology and Research. 19 September 2024. <https://www.adstarsummit.com.au/> Accessed: 3 January 2025.

Williams, T.L. (1999). Convergence. Risk Management, 46(8), 13–14.

Willis, H.H. (2007). Using Risk Analysis to Inform Intelligence Analysis. RAND Corporation. <https://www.rand.org/pubs/working_papers/WR464.html> Accessed: 3 January 2025.

Wrightson, M.T., & Caldwell, S.L. (2005). Risk Management. United States Government Accountability Office.

Ylönen, M., & Aven, T. (2023). A new perspective for the integration of intelligence and risk management in a customs and border control context. Journal of Risk Research, 26(4), 433–449, https://doi.org/10.1080/13669877.2023.2176912.The main paper I recall connecting intelligence (esp. as -led policing) as risk management:

Willem de Lint, “Intelligence in Policing and Security: Reflections on Scholarship,” Policing & Society, Vol. 16, no. 1 (March 2006): 1-6.

Caption: Michael, K. (2026). Risk intelligence in the age of Generative AI. International Journal of Contemporary Intelligence Issues, 3(1), 38–51. https://search.informit.org/doi/10.3316/informit.T2026083100008001471207603

Guest Editor’s Special Issue noted: “Professor Katina Michael maps a convergence that many practitioners have felt but few havenamed: the progressive dissolution of the boundary between risk management and theintelligence cycle, yielding an emergent practice that Professor Michael formalisation as RiskManagement Based Intelligence. Generative AI is discussed as both catalyst andcomplication — accelerating synthesis, translation and prediction while introducing newuncertainties around source transparency, hallucination, adversarial disinformation, and theerosion of human analytic judgement. Six evolutionary trends are traced, and the conclusionis properly conditional: the promise of risk intelligence is real, but unrealisable withoutprofessionalisation, governance, and keeping humans meaningfully in the loop.” (Mariana Zafeirakopoulos in “Intelligence in action: A special double issue from AIPIO 2026”)

Feedback Post Intelligence26

from Brett Peppler noting recent work:

  • What is Risk Intelligence? by Brett Peppler, AIPIO News, October 2021, p. 9f

  • The Pursuit of Risk Intelligence by Brett Peppler, AIPIO News, April 2020, pp. 7-9

  • Risk Intelligence by Domini Stuart, ANZIIF, December 2021, pp. 63-65.

  • Leading the Charge on Global Risk Intelligence, by Brett Peppler, ANZIIF, Nov 2021, pp. 1-4.

  • How to Build an Intelligence-led Risk Culture, by Brett Peppler, April 2024, pp. 1-6.

  • Building Intelligence Capability: A Service Design Approach, by Brett Peppler, IJCII, December 2025,

from Bill J Dixon:

  • Willem de Lint, “Intelligence in Policing and Security: Reflections on Scholarship,” Policing & Society, Vol. 16, no. 1 (March 2006): 1-6

  • Linking policing, policy, risk society and risk management

  • Maguire, Mike (2000). Policing by risks and targets: Some dimensions and implications of intelligence‐led crime control. Policing and Society 9 (4):315-336.

  • Ericson R. and Haggerty K. (1997) Policing the Risk Society. Oxford: Clarendon

Ratcliffe: (Detailed connection with risk management – eg “With greater access to information, police chiefs and executives in policing are now under far more scrutiny than before; as a result, their professional judgements and decisions are tempered by risk management (Flood 2004). This need to manage risk may be one of the most significant changes in law enforcement in recent years (Ericson and Haggerty 1997)”).

Ratcliffe, J.H. 2008, Intelligence-Led Policing, Willan Publishing, Cullompton, Devon

Police as providers of risk information:

Ratcliffe, J. (2002). Intelligence-led policing and the problems of turning rhetoric into practice. Policing and Society, 12(1), 53–66

(UK NIM - Risk analysis is closely linked to threat analysis and, together, they can be used in the identification of priorities during the strategic assessment process. Threat and risk analysis provide a framework for comparing criminal activities and groups against one another.) etc.

 National Policing Improvement Agency (NPIA) 2008, Practice Advice on Analysis, National Policing Improvement Agency, London.

Next
Next

Bringing Attention to the Growing Social Impact of Biomedical Devices