Why Risk-Based Classification
Not all AI use carries the same risk. An AI tool that schedules meetings is fundamentally different from one that scores candidates for hiring. Your governance effort should be proportional to risk — light oversight for low-risk uses, heavy oversight for high-risk. This is also the approach the EU AI Act takes, and even if you’re not subject to it today, it was widely expected to become the global template — though 2026 has complicated that: the US is pivoting away from EU-style rules (Colorado repealed its high-risk AI law) and the EU itself delayed its high-risk obligations to Dec 2027. Risk-tiering is still sound governance regardless.
Classification Criteria
Impact on individuals: Does the AI affect employment, compensation, access to opportunities?
Data sensitivity: What data does it access or process?
Autonomy level: Does a human review the output before action is taken?
Reversibility: Can the decision be easily undone if wrong?
Scale: How many people are affected?
Risk Classification Matrix
MINIMAL RISK (Standard oversight)
Meeting scheduling, email drafting assistance,
document formatting, internal search
Governance: General acceptable use policy
Review: Annual
LIMITED RISK (Enhanced oversight)
Report generation, data summarization,
chatbot for general HR Q&A, learning recs
Governance: Approved tool list + usage logging
Review: Semi-annual
HIGH RISK (Strict oversight)
Resume screening, candidate ranking,
performance analysis, compensation modeling,
promotion recommendations, workforce planning
Governance: Bias audit + human-in-the-loop +
adverse impact monitoring + legal review
Review: Quarterly
UNACCEPTABLE (Prohibited)
Automated termination decisions, emotion
detection for evaluation, social scoring,
subliminal manipulation of employees
Governance: Banned. No exceptions.
Regulatory alignment: The EU AI Act explicitly classifies “AI systems used in employment, workers management and access to self-employment” as high-risk. US states are following suit: California CRD regulations (Oct 2025) require meaningful human oversight for automated decision tools, Colorado’s replacement law (SB 26-189, effective Jan 2027) will require transparency and appeal rights, and Texas HB 149 (Jan 2026) adds disclosure requirements. Even if you’re not subject to these yet, aligning with the highest standard future-proofs your policy.