Classifying AI system risk
By Sam Rivera, Founder, SentinelPanda · June 19, 2026 · 1 min read · AI Governance
A spam filter and a hiring model are not the same risk. AI governance, like security, is risk-based — classify first, then spend effort where the stakes are.
Why classify
AI governance is risk-based: a low-stakes recommendation feature and a system making decisions about people's jobs, credit, or health demand very different oversight. Classification lets you apply proportionate controls — light touch for minimal-risk AI, serious governance for high-risk — instead of treating everything the same.
The EU AI Act tiers
The EU AI Act formalises this with risk tiers: prohibited practices (banned outright), high-risk systems (heavy obligations — risk management, data governance, human oversight, documentation), limited-risk systems (transparency obligations, e.g. telling users they are interacting with AI), and minimal-risk (largely unregulated). Knowing your tier tells you your obligations.
How to classify your own
For each system in your inventory, assess: what decisions does it influence, whose rights or safety are affected, and how autonomous is it. Systems affecting access to employment, finance, healthcare, or fundamental rights sit high; internal productivity tools usually sit low. Document the rationale.
Classification drives the program
The classification then drives everything downstream — which systems need impact assessments, human oversight, and monitoring. Get it wrong low and you under-govern a risky system; wrong high and you waste effort. SentinelPanda ties each inventoried AI system to its risk classification and the controls that follow.