THE SHORT ANSWER

Assess what the AI does, which data it uses, who is affected, plausible failure and abuse, the severity and reversibility of harm, human review, accountable ownership and monitoring. Classify the use provisionally, choose controls and reassess after material change.

Start with eight connected questions

  1. What is the AI doing?
  2. What data does it use?
  3. Who is affected?
  4. What happens when it is wrong or misused?
  5. Can the outcome be reversed?
  6. Who reviews it?
  7. Who is accountable?
  8. How will performance and harm be monitored?

Consider likelihood, severity and controllability

A frequent minor error and a rare catastrophic error require different decisions. Also consider whether people can detect, stop, challenge and reverse the outcome before harm spreads.

Use a provisional business tier

Educational risk tiers
TierSignalsNext step
LowerNon-sensitive, reversible, internal, closely reviewedDocument and test the basic workflow
ModerateExternal communication, recommendations or meaningful operational impactFormal owner, evaluation and monitoring
HigherSensitive data, high-impact decisions, autonomy or hard-to-reverse harmSpecialist review and stronger evidence before proceeding

This model is a planning aid, not a statutory classification or legal conclusion.

End with a decision and residual risk

  • Proceed with specified controls
  • Run a limited experiment
  • Redesign the use
  • Escalate for specialist review
  • Do not proceed
  • Retire an existing system

Record assumptions, evidence gaps, control owners and the trigger for reassessment.

Evidence & context: National Institute of Standards and Technology · NIST

Sources & further reading

  1. Artificial Intelligence Risk Management Framework (AI RMF 1.0)

    National Institute of Standards and Technology. Voluntary, rights-preserving guidance organized around GOVERN, MAP, MEASURE and MANAGE. NIST was revising AI RMF 1.0 when checked on 28 September 2026, so organizations should verify the current version before formal adoption.

  2. Generative Artificial Intelligence Profile (NIST AI 600-1)

    NIST. Risk-management guidance, including confabulation. It does not establish a universal error rate.

  3. OECD AI Principles

    OECD.AI. Intergovernmental principles updated in May 2024 covering inclusive benefit, human rights and fairness, transparency, robustness and accountability. They are high-level guidance rather than a complete operational control set.

Examples and exercises are illustrative unless attributed to a source. No independent expert review is claimed.

A correction, a counterexample or an experience worth sharing?

Join the conversation ↗