AI risk classification and governance
Classifies a candidate AI use by regulatory risk tier before anyone builds it, so the opportunity list stops containing ideas that cannot lawfully ship.
The printable canvas and the handoff into Claude Code are part of a paid plan. See what a plan includes. It needs the Claude desktop app on this machine, and your team and the prompt library already installed in that project — we cannot see your disk, so open it there.
What it is
Sorts a candidate use of AI into a regulatory risk tier — broadly, unacceptable, high, limited or minimal — before it is built, using the framework the EU AI Act put into force and the ethical failure modes that sit underneath it regardless of jurisdiction: bias, opacity, privacy and misinformation. The tier decides the obligations, so classifying comes before scoping.
- The four tiers
- Unacceptable uses are prohibited outright. High-risk uses — most hiring, credit, and safety-relevant systems — carry documented obligations before deployment. Limited-risk uses need disclosure. Minimal-risk uses carry no obligation beyond ordinary good practice.
- Classification reasoning
- Why this specific use sits where it sits, in terms a non-specialist reader can follow. A tier assigned without shown reasoning cannot be checked or challenged later.
- Bias and fairness exposure
- Whether the training data or the decision the system makes could produce a systematically unfair outcome for a protected group, and what has been done to check.
- Explainability
- Whether the people affected by a decision, and the people accountable for it, can actually understand why the system reached it. A high-risk use with no explainability story is a live liability, not a technicality.
- Data governance
- Where the data came from, what it was permitted to be used for, and whether that permission covers this use.
- Named ownership
- Who is accountable for this classification and for revisiting it if the use case changes. An unowned classification decays the moment the product does.
How you run it
- Write the use case as a specific decision, not a categoryWhat the system actually decides or recommends, for whom, and what happens as a result. 'AI in HR' is not classifiable; 'AI that ranks CVs for shortlisting' is.
- Establish the current regulatory position firstThe tiers, thresholds and obligations that apply in every jurisdiction the business operates or sells into. Regulation is moving; confirm rather than assume.
- Assign the tier and write the reasoning downWhich tier, and the specific features of the use case that put it there. A reader should be able to check the classification against the reasoning.
- Check bias, explainability and data governance for anything above minimalThe three failure modes that sit under most obligations regardless of the exact regulatory tier.
- Name an owner and a revisit triggerWho is accountable, and what change to the use case — new data source, new decision, new geography — would require reclassifying it.
The prompt
Run this tool in your own Claude
The short prompt starts your partner against the library on your disk. The long one carries everything with it and needs nothing installed.
Your playbook
It lands in the earliest stage this tool suits. Move it on the Playbook page.
You’ll need
- A specific candidate AI use case, described concretely rather than as a category
- The jurisdictions the business operates or sells into
- Who currently owns AI risk decisions, if anyone does
You’ll end up with
- Each candidate use classified into a risk tier with the reasoning shown
- The obligations that attach to that tier, in plain terms
- A governance owner named for anything above minimal risk