The Voice of Business

Talk to Us

Risk classification

Sorting each AI use case by what happens if it goes wrong, who is affected, and whether it touches personal data, a regulated decision or client-facing output nobody checks. It is what makes a policy proportionate rather than a blanket rule.

What it means in practice

The governance article describes three levels: an internal draft or summary moves fast with a light review, content a client sees unreviewed needs a checked step, and a hiring decision, regulated communication or client deliverable needs a named human checkpoint. It also says the EU AI Act applies by use case, not by company size, so each use case is classified against the Act as well.

How we use it

The governance article puts classification after the AI tool inventory, and the audit article says an audit maps the processes in scope against the Act’s own risk scale rather than inventing its own. It feeds the rules in AI governance and the checkpoints. The method is in AI governance for small and mid-sized businesses.

FAQ

Questions about Risk classification

What is risk classification?

It is sorting each AI use case by what happens if it goes wrong, who is affected, and whether it touches personal data, a regulated decision or unchecked client-facing output. The sort turns a blanket policy into proportionate rules.

Does it depend on the size of the business?

No. The governance article says the EU AI Act applies by use case, not by company size, so a small organisation running a high-risk use case carries the same core obligations as a large one.

What it means for a business

A drafting assistant and a system that screens job applications are not the same problem. Classification gives the first a light review and the second a named checkpoint that is actually staffed.

Ready to put this to work?

Tell us where your team is with AI and we will tell you honestly what would make the biggest difference.