Risk tiers and the regulatory map

Lesson 4 of 5 in AI Inventory, Use-Case Intake, and Risk Triage.

Triage needs a scale to triage onto. Most organisations build an internal scheme of three to five tiers, and most of them consciously borrow the EU AI Act’s architecture — prohibited / high / limited / minimal — because aligning your internal language with the strictest regime you face means classification work done once serves both purposes. The internal version adds what statutes leave out: your own red lines above the legal ones, and explicit controls attached to each tier, because a tier that changes nothing is a label, not a decision.

A working internal tier scheme (EU-template, four tiers)

  1. Tier 0 — No-go — Statutory prohibitions + internal red lines

    Everything on the EU AI Act Article 5 list, plus the organisation’s own refusals (many firms add: no emotion inference on customers, no social scoring of any kind, no fully automated dismissal decisions). Intake gates catch these; only the executive risk committee can hear an appeal — and for the statutory items, not even them.

  2. Tier 1 — High scrutiny — Consequential decisions about people; regulated categories

    Anything making or materially influencing decisions with legal or similarly significant effect — hiring, credit, insurance pricing, housing, health, education — plus whatever maps to EU Annex III areas or state-law "consequential decision" definitions. Full assessment stack, independent validation, committee approval, enhanced monitoring, quarterly attestation.

  3. Tier 2 — Standard review — Meaningful but bounded risk

    Customer-facing systems without consequential-decision effect, internal genAI on sensitive data, systems whose failure is costly but reversible. Fast-lane approval against a checklist, standard documentation, routine monitoring, annual attestation.

  4. Tier 3 — Minimal — Register and move on

    Low-stakes, reversible, human-mediated uses. One registry record, acceptable-use policy applies, no further per-system obligations. The tier that makes wide registry scope affordable — and the reason nobody needs a committee meeting about a grammar checker.

Should the tier come from a score or a category? Scored schemes (Canada’s Algorithmic Impact Assessment is the famous public one — 65 risk questions, points, thresholds; covered in depth in the impact-assessments module) feel objective and produce an audit trail of every answer. Their weakness is arithmetic: a system scoring high on one catastrophic dimension can be averaged back down by twenty benign answers. Categorical schemes ("any consequential decision about individuals → Tier 1, full stop") are blunter but ungameable on exactly the dimensions that matter most. The convergent practice: categorical gates for the things that must never average out, scoring for ordering everything else — and either way, the tier rationale gets written down, because "why was this Tier 2?" is a question you will answer under oath or audit eventually.

The internal tier is half the triage output. The other half is the regulatory mapping: which external regimes attach to this use case. That field drives real obligations with real dates.

The regimes a triage analyst maps against (selected — as of September 2026)
RegimeWhat it capturesStatus & datesWhat triage must record

EU AI Act — Annex III high-risk

Eight use-case areas: employment, credit, essential services, education, biometrics, law enforcement, migration, justice

Annex III obligations now apply from 2 December 2027 (delayed from Aug 2026); Annex I embedded from Aug 2028. Prohibitions live since Feb 2025; Art 50 transparency since Aug 2026

Whether the use case falls in an Annex III area — classify now, because remediation to the Art 8–15 requirements takes longer than the runway

Colorado AI Act (SB24-205)

"Consequential decisions": education, employment, financial or lending, essential government services, healthcare, housing, insurance, legal services

In force since 30 June 2026 (compliance date delayed once, by SB25B-004, from the original Feb 2026)

Whether the system is a "high-risk AI system" making a consequential decision about Colorado residents — deployer duties (risk program, impact assessments, notices) attach

NYC Local Law 144

Automated employment decision tools (AEDTs) used to screen NYC candidates or employees for hire or promotion

Enforced since 5 July 2023

Whether the tool substantially assists the employment decision — annual independent bias audit plus candidate notice required

Sectoral rules

Credit (ECOA adverse-action reasons), insurance (state unfair-discrimination rules), health (FDA for SaMD), employment (EEOC guidance)

Long-standing — these applied to models decades before "AI law" existed

Which sector regulator already owns this decision type; sectoral duties stack on top of AI-specific ones

Generative AI use cases deserve their own triage lens, because the same underlying model lands in four postures with entirely different risk shapes.

Enterprise chatbot

A deployed assistant your organisation offers — internal helpdesk or customer-facing. Customer-facing versions pick up disclosure duties (EU AI Act Art 50: people must know they are talking to a machine, applicable since Aug 2026) and full accountability for outputs — Moffatt v. Air Canada made a company honour the refund policy its chatbot invented. Triage: Tier 2 minimum; Tier 1 if it can commit the organisation or touch consequential decisions.

Copilot on internal data

Embedded assistants over your documents, code, or records. The risk centre of gravity is data: access-permission inheritance (does the copilot read documents the user could not?), confidential data in prompts to external APIs, and output reuse. Triage keys on the sensitivity of the data corpus, not the tool brand.

Embedded genAI feature

GenAI that appeared inside existing SaaS — the summariser in the meeting tool, the "write with AI" button in the CRM. Same embedded-AI problem as before, now with content generation attached: where do prompts go, is customer data used for vendor training, can the feature be disabled tenant-wide? Triage output is often a contractual action item as much as a tier.

Employee BYO-AI

Individual use of consumer tools on work content. Not a system you can tier — a behaviour you can channel. The controls are the acceptable-use policy (what data classes may never leave), a sanctioned alternative that is genuinely good, DLP on the egress paths you can see, and training. Registered in the inventory as a usage category with named policy controls, not as a system record.

Now put it all together. The tree below is the triage analyst’s five-day job compressed into seven questions — walk a few use cases through it and notice how the gating questions from lesson three reappear as the earliest branches.

Triage desk: assign the tier

Interactive decision tree — outcomes:

  • Out of scope

    Conventional software — no registry entry. Note the reasoning in the intake log so the decision is reproducible if the system later gains AI features.

  • Track as automated decision system

    Not AI, but not ignorable: rule-based automation of consequential decisions is how Robodebt happened. Register as an ADS with an owner and a legal-basis check — some regimes (and every ombudsman) reach it regardless of the AI definition.

  • Tier 0 — stopped at the gate

    The request ends here, with documented reasons. Statutory prohibitions (EU Art 5, applicable since February 2025, penalties up to €35M or 7% of worldwide turnover) admit no internal appeal; internal red lines can be appealed to the executive risk committee only.

  • Tier 1 — high scrutiny, regimes mapped

    Full assessment stack, independent validation, committee approval, enhanced monitoring — plus the regulatory flags recorded now: EU Annex III classification (obligations from 2 December 2027, but classification and gap work start immediately), Colorado deployer duties (in force since 30 June 2026), NYC LL144 annual bias audit if it screens NYC candidates, and any sectoral duties, which apply regardless of AI law.

  • Tier 1 — high scrutiny on internal standards

    No named statute today does not mean no risk: consequential decisions about people take the full Tier 1 treatment on internal standards alone. Regime mapping is re-checked at every attestation — the map changes faster than your systems do.

  • Tier 2 — approved only with conditions

    Standard review, but expect mandatory conditions: EU Art 50 disclosure that users face a machine (applicable since August 2026), grounding on approved sources, output monitoring, and clear limits on what the system may promise. Moffatt v. Air Canada is the case to cite when someone asks why — the chatbot’s invented refund policy bound the airline.

  • Tier 2 — standard review, fast lane

    Checklist-based delegated approval within SLA, standard documentation, routine monitoring, annual attestation. The workhorse tier — most genuine business AI lands here.

  • Tier 3 — register and move on

    One registry record, acceptable-use policy applies, done. Proportionality means being genuinely fast here — this outcome existing (and being reachable in a day) is what keeps the front door busier than the back.

Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.