Not every AI system needs the same governance
Match internal AI review to the consequences, scope and recovery paths of the use. Begin with consequence and reversibility, alongside legal classification and other material risks.
Keep sources linked to the record used for review. The diagram does not represent automatic approval.
A policy may cover internal drafting and decisions with substantial effects on people. These uses need a common inventory and baseline controls, with assessment depth, approval and monitoring matched to their risks.
Review whether the process directs attention to uses with greater potential harm. A uniform full assessment consumes capacity, while a lighter route needs criteria that prevent material risks being overlooked. Record the routing decision.
Define proportionate triage before individual proposals are assessed. Explain the evidence and authority each route requires and which changes trigger reassessment. Proportionality depends on explicit criteria and accountable decisions.
The two questions that do most of the work
Regulatory classification is its own exercise and it is not this one. Where the EU AI Act applies, its own tests decide what is high risk, and Article 6 with Annex III is where that starts. What follows is the internal triage that has to exist underneath it, because most of an organisation’s AI estate sits outside any regulatory category and still needs somebody to decide how much attention it gets.
Two questions, asked of every system, answerable in a sentence each.
What happens to a person if this is wrong? Not to the process — to a person. An inaccurate summary of a meeting is an inconvenience. An inaccurate summary of a clinical consultation is not.
Can it be taken back? A draft a person edits before sending is reversible. A message that has been sent, a payment made, a record amended, an application declined and never revisited — those are not, or not without a further act by somebody who may never know it is needed.
| Cannot be undone | Can be undone | |
|---|---|---|
| Significant | Full assessment, and a person decides Impact assessment, a named decision-maker per case, disaggregated outcome monitoring, a stopping condition. | Assessment, plus a working route back The reversal path is tested rather than assumed, and the person affected is told how to use it. |
| Slight | Proportionate check, with limits A rate limit, a log, and a confirmation step on the action that cannot be undone. | Register it, and apply standard controls Inventory, data handling and access controls, with further review where law or context requires it. |
A low-consequence, recoverable use may suit standard controls, subject to legal and contextual requirements. Repeated record changes can create aggregate harm even when individual effects are small. Review scale and downstream consequences.
Where the threshold has to live
A matrix on a slide changes nothing. What changes behaviour is the threshold being a gate that a system passes through, with the answers recorded, before it reaches production.
Reserve specialist review for uses that need it while maintaining baseline controls and escalation. A lighter route still needs evidence supporting its classification and the authority to reconsider that decision.
The third line is the one that decays first. Systems move. An assistant that drafted internal notes gets connected to the outbound mail server, and nothing in a normal change process asks whether the classification still holds. Tying reclassification to material change — a new tool, a new data source, a new population, a new action — is what keeps the register true.
What the reversibility question does to a design
Asking it early tends to change the system rather than the paperwork, which is the point.
Drafts, confirmation steps, hold periods and tested recovery paths may reduce consequences. Verify the benefit and residual risk before changing the internal route. None automatically changes legal classification or removes assessment duties.
That is the strongest reason to run this triage during design rather than at a launch gate. At a gate, the classification is a verdict on work that is finished. During design, it is an input, and the cheapest response to an uncomfortable answer is usually to change the system.
What this does not tell you
This triage is not a legal classification and it does not substitute for one. Where the AI Act, sector regulation or data protection law applies, their categories govern, and a system that this matrix puts in the bottom right can still be high risk under the Act. Interpretation for your organisation belongs with your counsel — we identify the likely role and classification and show where the evidence gaps are, and the legal position stays with you.
The two questions are a starting point. Add scale, data sensitivity, exposure, contestability and the needs of affected people where relevant. A technically recoverable effect may still cause harm that cannot be corrected in time.
Test the triage on a representative set of recent systems. Check the route against the evidence and exercise material-change review. Revise criteria that miss relevant distinctions and assess the effect on existing approvals.