to have an alert key and there are risk associated with him having it.
A bogus alert is of fairly low risk; any misuse of the alert key will immediately cause an alert key revocation alert to be released; which will override any alerts and effectively disable the alert system. Several of us in core were proposing to remove the alert system entirely but there was some push-back.
I'd like to replace it with a generic mechanism that lets anyone with stationary coins over a threshold value broadcast small amounts of data per week to all participating nodes on a parallel p2p network... this would help discourage people from trying to stuff messaging things into the Bitcoin blockchain just to use our network for messages, and would provide a uniform mechanism for any client author to perform alerts... plus it would be a public utility encouraging people to hold Bitcoin (and hold it in their own possession, potentially). (And for Core, we'd make alerts use Script, like elements alpha does so it could use multisig.); but this is currently pretty far down on the priority list for me right now.