Skip to content

Classifying AI system risk

By Sam Rivera, Founder, SentinelPanda · June 19, 2026 · 1 min read · AI Governance

A spam filter and a hiring model are not the same risk. AI governance, like security, is risk-based — classify first, then spend effort where the stakes are.

Why classify

AI governance is risk-based: a low-stakes recommendation feature and a system making decisions about people's jobs, credit, or health demand very different oversight. Classification lets you apply proportionate controls — light touch for minimal-risk AI, serious governance for high-risk — instead of treating everything the same.

The EU AI Act tiers

The EU AI Act formalises this with risk tiers: prohibited practices (banned outright), high-risk systems (heavy obligations — risk management, data governance, human oversight, documentation), limited-risk systems (transparency obligations, e.g. telling users they are interacting with AI), and minimal-risk (largely unregulated). Knowing your tier tells you your obligations.

How to classify your own

For each system in your inventory, assess: what decisions does it influence, whose rights or safety are affected, and how autonomous is it. Systems affecting access to employment, finance, healthcare, or fundamental rights sit high; internal productivity tools usually sit low. Document the rationale.

Classification drives the program

The classification then drives everything downstream — which systems need impact assessments, human oversight, and monitoring. Get it wrong low and you under-govern a risky system; wrong high and you waste effort. SentinelPanda ties each inventoried AI system to its risk classification and the controls that follow.

EU AI Act high-risk classification Building an AI system inventory AI impact assessments

Run your compliance program in one workspace.