practice

AI Risk Tiering

Classifying AI systems by potential harm so that governance effort is proportionate, rather than applying the same controls to every use.

ai-governanceriskcompliance

Tiering is the mechanism that keeps AI governance from being either useless or paralysing. Without it, organisations apply a single heavy process to everything, which stops low-risk experimentation and drives high-risk work into the shadows.

The dimensions that determine tier: consequence of a wrong output — an inconvenience, a financial loss, a denied service, a safety event; autonomy — whether a human reviews each decision, reviews exceptions, or is absent entirely; population affected and whether it includes vulnerable groups; regulatory exposure in the domain; and reversibility of the resulting action.

The EU AI Act formalises a version of this, and its structure is worth knowing regardless of jurisdiction because it is shaping expectations broadly: prohibited practices, high-risk systems carrying substantial obligations around data governance, documentation, human oversight and robustness, limited-risk systems with transparency duties, and minimal-risk uses left largely alone.

The architectural point is that the tier should drive design requirements, not just paperwork. A high-tier system needs decision logging sufficient to explain an individual outcome, a human override path that genuinely works, monitoring for drift and disparate impact, and a documented fallback when the model is unavailable. Deciding the tier late means retrofitting all of it.

The governance failure to avoid: tiering by technology rather than by use. The same model can be minimal risk in one application and high risk in another, and it is the application that determines the obligations.