Skip to Content
Counsel Collective

AI

The Question the Risk Register Cannot Answer

In Conversation · Risk & Compliance

The Question the RiskRegister Cannot Answer


Fifteen years inside risk, then a firm of his own inside a month. Devon Euring on why AI, Web3 and crypto broke the assumptions under traditional governance, and the question he now puts to every executive table.

A Counsel Collective Feature · August 2026

Devon Euring, Author and Chief Risk Officer of Asterisk Defense

Devon Euring left a corporate risk seat in May and had a firm by the end of the month. What he is building rests on a claim most governance frameworks were never designed to test: not what could go wrong, but who owns it when it does.

The gap was measured in weeks.

Devon Euring left iHeartMedia in May. By the end of the same month, Asterisk Defense had gone from something he was carrying around to a firm with a name, a service model and a direction. He is candid that the compression was possible only because he was not starting from nothing. What the exit actually gave him was something he says he had not had in a long time.

Distance.

“And with that distance, I started asking a different question,” he says. “Not, ‘What role am I going to take next?’ But ‘After everything I’ve learned, what am I actually supposed to build?’”

He had spent more than fifteen years inside risk, compliance, fraud, cybersecurity and operational risk, building programs and sitting in rooms where consequential decisions got made. Long enough to watch a specific mismatch widen. AI, blockchain, digital assets, deepfakes and autonomous systems were accelerating, and organizations were still trying to govern them with risk models built for a slower world.

The pattern he kept seeing had a shape to it. Innovation was being asked how fast it could build. Risk was brought in afterward and asked how to control what had already been built.

“That model felt backwards to me.”

The architecture problem

The moment it crystallized was, by his account, an unremarkable executive conversation. Identify the risk. Assign likelihood and impact. Map the controls. Determine residual exposure. Decide whether to mitigate, accept, transfer or avoid.

Devon Euring presenting to a room
Onstage. Speaking is the channel he credits first for changing his opportunities.

Nothing wrong with the process. The problem was that the technology had changed the nature of the question.

With traditional systems, Euring says, you could reasonably define the boundaries, the users, the expected behaviors and the owner. AI does not offer you that, and neither do Web3 and crypto. You get autonomy, decentralized ownership, behavior that shifts, third party dependencies, and decisions executing at machine speed.

He walks through the version that keeps him up. An AI system makes a recommendation. An employee relies on it. The recommendation triggers an automated workflow. The workflow produces a customer, financial, security or compliance outcome. Then the question that has no owner in the org chart: who holds the resulting risk. The model developer, the business owner, the person who approved the AI, the employee who trusted the output, the vendor, or the executive who accepted the residual risk.

“A traditional framework can give you a risk score. It cannot automatically give you accountability.”

Compliance can catch up to regulation. It cannot always catch up to consequence.Devon Euring, Risk Rewritten

Blockchain and digital assets break the same assumption from a different angle. Governance tends to presume an identifiable organization, a system owner, an intermediary, a control point. Decentralized environments can dissolve all four while smart contracts execute on their own and pseudonymous participants move assets across borders. “Yet we were still trying to put these environments neatly into red, amber, and green boxes.”

His conclusion is the sentence the rest of his work hangs from. “We weren’t simply dealing with new risks. We were dealing with a new architecture of risk.”

Out of that comes a distinction he now makes constantly, between auditability and defensibility. An organization can show him the logs, the model output, the policy, the control and the approval trail. “That proves you recorded what happened. It doesn’t necessarily prove that what happened was responsible or that someone meaningfully owned the decision.”

He is not arguing the discipline is finished. “I don’t believe traditional risk management is obsolete. I believe its assumptions have to be rewritten.”

The book came first

Risk Rewritten: Enterprise Risk as Proactive Leadership published in 2026, before the firm existed, and Euring is direct about the sequence. “In retrospect, the book became the blueprint before I knew I was going to build the company.”

Devon Euring holding a copy of Risk Rewritten
With Risk Rewritten, which published in 2026, before the firm existed.

He wrote it out of a frustration he had carried for years. Organizations rarely lacked frameworks, policies, controls or capable people. What they lacked was a way to make risk strategic. Risk kept ending up as the department of no, or as the function invited in after the decisions were already made, measured on whether boxes were checked rather than whether the company was deciding better.

He named it deliberately. Not a textbook explaining how traditional risk management works, but a challenge to the assumption underneath it, including the reflex that more controls automatically mean better risk management.

“My thesis is that the future of risk is not about becoming better at stopping things. It’s about becoming better at enabling the right things without becoming blind to their consequences.”

Asked for the version he would give a board member who still believes compliance can catch up later, he gives it in one paragraph and closes with the line that does the work: “Compliance can catch up to regulation. It cannot always catch up to consequence.”

Writing it also cost him something he thinks the industry avoids. “It’s easy to critique a framework from inside a boardroom. It’s different to say, ‘Here is what I believe should replace that thinking, here is how I would build it, and here are the principles I’m willing to stand behind publicly.’”

Visibility is your new resume

The second thread in Euring’s work is a line he uses with the professionals he mentors, and it is not about personal branding.

Devon Euring signing a copy of Risk Rewritten
Signing the book. He calls writing, speaking and publishing creating intellectual evidence.

“Your title and résumé tell people where you’ve worked; your visibility tells them how you think.”

Risk professionals are trained to identify every reason an idea might fail. Sometimes we apply that same risk assessment to ourselves until we’ve effectively controlled our own potential out of existence.Devon Euring

Risk and compliance people, he says, were conditioned to work behind the curtain. Be measured. Do not say too much. Let the business take the spotlight. For a long stretch, doing exceptional work quietly could carry an entire career. He does not think that holds anymore, because of what the function is now being handed: AI, cyber, digital assets, geopolitical exposure, financial crime, privacy, third party ecosystems. None of that is back office. If risk leaders are going to shape those conversations, they have to be visible enough to be in them.

What he means by visibility is narrower and harder than posting. He calls it creating intellectual evidence. Writing, speaking, publishing, teaching, challenging an idea in public, so that people can understand his judgment before they ever sit across a table from him. The book, the stages, the Risk Rebel work, the LinkedIn writing are not adjacent to his credibility. They are the record of it.

The timing matters to him because credentials are getting easier to produce. More people can earn a certification or shape a résumé to a job description. “What’s much harder to manufacture is a sustained body of original thought, demonstrated judgment, and a reputation people associate with your name.”

He is careful not to turn this into an argument for volume. Risk professionals, of all people, understand context, consequence and reputational exposure. “The goal isn’t to have an opinion about everything. It’s to become known for having something meaningful to say about the things you actually understand.”

Pressed on which channel has actually changed his opportunities, he names speaking first, on stages like AI4, because a stage will not let you hide behind a résumé. People hear how you connect ideas and how you handle a question you did not prepare for. But he credits LinkedIn as the multiplier, the thing that keeps the conversation going after he leaves the room. The result still catches him off guard at conferences. “Sometimes I’m meeting someone for the first time, but they don’t feel like they’re meeting me for the first time.”

And a caution he applies to himself. “Visibility without usefulness eventually becomes noise.” He does not measure it in followers or impressions. “I measure it in trust transfer.” Did an idea change how someone thought. Did it start a conversation that would not have happened. Did someone hand him a bigger problem because they had already seen evidence of his judgment.

What he tells the people coming up

The advice sounds, at first, like the opposite of what he did himself.

Devon Euring in conversation with attendees at a conference
At a conference. He says people often arrive already knowing how he thinks.

“Don’t confuse becoming visible with leaving corporate. You don’t have to become an entrepreneur to build a name, and you don’t have to become controversial to develop a point of view.”

Build vertically, he tells them, because the certification and the promotion and the larger team still matter. Then build horizontally too. Relationships outside the company. Industry conversations. Mentoring. Speaking and writing. Adjacent technologies. Communities where you are not the expert. A body of thought that does not depend on the logo next to your name.

That last part is the lesson he took out of his own exit. “When I left iHeartMedia, I lost a title and an organization, but I didn’t lose my experience, relationships, ideas, reputation, or ability to create value. In fact, that transition forced me to recognize which parts of my career were truly mine.”

So the instruction is timing. “Build your professional equity while you still have the corporate seat, not after you lose it or decide you’re ready to leave. Your employer should benefit from your growth, but your growth should never exist exclusively inside your employer.”

He does not tell people to get louder. He tells them to get more willing to stand behind what they have learned, and he is unsparing about why that is hard in this particular function. “Risk professionals are trained to identify every reason an idea might fail. Sometimes we apply that same risk assessment to ourselves until we’ve effectively controlled our own potential out of existence.”

He had to sit with a version of that himself. Building the firm, publishing the book, putting the Risk Rebel philosophy behind his own name meant accepting an exposure he could not control for. People can disagree. Ideas get challenged. Things you build can fail. His answer is that invisibility carries exposure too, and nobody prices it: the risk that your experience never becomes influence, that your ideas stay locked inside organizations, that someone else defines your professional identity for you.

When someone asks him whether to stay corporate or bet on themselves, he refuses the question as posed. Betting on yourself does not require quitting. Build the intellectual property, the relationships, the reputation and the confidence that give you choices, and if the leap ever comes, you are not starting from zero.

Asked for the single line that connects the firm, the book and the argument about visibility, Euring answers in one sentence.

“Don’t wait for the future to give you permission to become what you already know it requires.”

Devon Euring

About

Devon Euring

Author & Chief Risk Officer, Asterisk Defense

Devon Euring is Author and Chief Risk Officer of Asterisk Defense, the governance, risk and compliance firm he founded in Dallas in 2026 after more than fifteen years inside risk, compliance, fraud, cybersecurity and operational risk, most recently at iHeartMedia. He is the author of Risk Rewritten: Enterprise Risk as Proactive Leadership, and speaks and mentors widely on governing AI, Web3 and digital assets.

A Counsel Collective Feature · Risk & Compliance · 2026
Counsel Collective
Logo
Shopping cart