Start a conversation Contact
← Research

Not every AI system needs the same governance

Organisations apply one control set to everything they call AI, which is simultaneously too heavy for a summariser and too light for an agent with write access. A written threshold fixes both, and it takes two questions.

The AI policy applies to AI systems. The definition of an AI system in it is broad, because the people who wrote it were being careful, and the consequence is that the same impact assessment, sign-off and review cycle now attaches to a tool that drafts internal meeting notes and to a system that decides whether somebody gets an appointment.

What happens next is predictable. The heavy process is applied properly to the first few systems, the queue lengthens, teams learn that the way to ship is to describe the work as something other than AI, and the governance function ends up with visibility of exactly the systems that were least worth its attention.

The claim: proportionality is not a softening of governance, it is what makes governance operable — and it requires a threshold written down before anybody argues about a specific system.

The two questions that do most of the work

Regulatory classification is its own exercise and it is not this one. Where the EU AI Act applies, its own tests decide what is high risk, and Article 6 with Annex III is where that starts. What follows is the internal triage that has to exist underneath it, because most of an organisation’s AI estate sits outside any regulatory category and still needs somebody to decide how much attention it gets.

Two questions, asked of every system, answerable in a sentence each.

What happens to a person if this is wrong? Not to the process — to a person. An inaccurate summary of a meeting is an inconvenience. An inaccurate summary of a clinical consultation is not.

Can it be taken back? A draft a person edits before sending is reversible. A message that has been sent, a payment made, a record amended, an application declined and never revisited — those are not, or not without a further act by somebody who may never know it is needed.

How much governance a system needs, from two answers Fig. 01

Consequence to a person

Cannot be undone Can be undone
Significant Full assessment, and a person decides Impact assessment, a named decision-maker per case, disaggregated outcome monitoring, a stopping condition. Assessment, plus a working route back The reversal path is tested rather than assumed, and the person affected is told how to use it.
Slight Proportionate check, with limits A rate limit, a log, and a confirmation step on the action that cannot be undone. Register it, and apply standard controls Inventory entry, data handling, access. No bespoke assessment.

Reversibility

The bottom-right quadrant is where most of an estate lives, and treating it as though it were the top-left is the single largest cause of governance backlogs. The bottom-left is the one that gets missed: low individual consequence, but no way back, repeated at volume. A system that quietly amends records is not dangerous in any single instance and is very difficult to unpick after a year.

Where the threshold has to live

A matrix on a slide changes nothing. What changes behaviour is the threshold being a gate that a system passes through, with the answers recorded, before it reaches production.

The fourth line is the commercial argument for proportionality and it is worth making to a board directly. A control process applied indiscriminately is applied badly, because the people running it have no capacity left for the cases that matter. Narrowing what gets the full treatment is not a reduction in assurance. It is the only way the full treatment continues to mean anything.

The third line is the one that decays first. Systems move. An assistant that drafted internal notes gets connected to the outbound mail server, and nothing in a normal change process asks whether the classification still holds. Tying reclassification to material change — a new tool, a new data source, a new population, a new action — is what keeps the register true.

What the reversibility question does to a design

Asking it early tends to change the system rather than the paperwork, which is the point.

A design that cannot be governed proportionately at the reversible end is often one step away from being able to. Insert a confirmation. Make the action a draft. Add a cooling-off window in which the effect can be withdrawn. Log enough that a reversal is possible at all. Each of those moves a system from a quadrant that demands heavy assurance into one that does not, and each is cheaper as a design decision than as a control.

That is the strongest reason to run this triage during design rather than at a launch gate. At a gate, the classification is a verdict on work that is finished. During design, it is an input, and the cheapest response to an uncomfortable answer is usually to change the system.

What this does not tell you

This triage is not a legal classification and it does not substitute for one. Where the AI Act, sector regulation or data protection law applies, their categories govern, and a system that this matrix puts in the bottom right can still be high risk under the Act. Interpretation for your organisation belongs with your counsel — we identify the likely role and classification and show where the evidence gaps are, and the legal position stays with you.

It is also deliberately crude. Two axes will not capture scale, contestability, the vulnerability of the population affected, or the reversibility of an effect that is technically undoable and practically not. A mature operating model adds those. It should not start with them, because a threshold nobody can apply in ten minutes is a threshold that gets applied by whoever has time.

The reader who should act is whoever owns the AI policy. Take the ten most recently deployed systems and place them. If they all land in one quadrant, the threshold is not discriminating — and if the heavy ones are not the ones getting the heavy process, that is the finding that justifies rewriting the policy this quarter rather than next year.

Filed under · Governance · Governance · Classification · Operating model Inference Institute · 19 Aug 2026

Bring us the question

Reading this because it is on your desk right now?

That is the conversation we are best at. Thirty minutes, a written summary, no obligation.