Lesson 14 / 26
Risk Tiers for Use Cases
Classify AI use cases into tiers so effort and controls match the level of risk.
Proportionate controls
Not every AI feature needs the same scrutiny. A tiering scheme sorts use cases by potential harm: for example prohibited (never allowed), high (decisions about people in areas such as hiring, credit, education or health), limited (interacts with users, needs disclosure) and minimal (internal helpers). Higher tiers get more testing, documentation, human oversight and senior approval. This keeps low-risk innovation fast and puts the effort where harm could be serious. Regulations such as the EU AI Act use a similar tiered idea, which makes internal tiers a good starting point.
A tiering function, run
I ran this. The four example use cases land in four different tiers. Real classification needs legal input and many more criteria; this is a teaching sketch.
def tier(use):
if use.get("social_scoring") or use.get("manipulative"):
return "prohibited"
if use.get("decides_on_people") and use.get("domain") in {"hiring", "credit", "education", "health"}:
return "high"
if use.get("interacts_with_users"):
return "limited"
return "minimal"
tests = [{"social_scoring": True},
{"decides_on_people": True, "domain": "credit"},
{"interacts_with_users": True},
{"internal_summaries": True}]
print([tier(t) for t in tests])
Output:
['prohibited', 'high', 'limited', 'minimal']
Re-tier when the use changes
A meeting summariser (minimal) that starts feeding performance reviews has become a high-impact use. Re-check the tier whenever the purpose, data or audience changes.
Quick check: Why use risk tiers?
- They only apply to hardware
- All use cases get identical rules
- Tiers remove the need for review
- Controls can match the level of risk without slowing every project equally
Answer
Controls can match the level of risk without slowing every project equally — Proportionate governance keeps safe innovation quick and focuses scrutiny on serious cases.