Skip to content

2026 04 26 ai lowcode risk tier classification controls

github-actions[bot] edited this page Apr 30, 2026 · 2 revisions

How should Artificial Intelligence (AI) and low-code use cases be classified into risk tiers, and how should governance controls vary across those tiers?

Research Question

What structured risk classification framework is appropriate for AI and low-code use cases in enterprise environments, specifically, how should categories such as informational, decision-support, and autonomous action systems be defined and bounded, and how should required governance controls, oversight intensity, and approval thresholds be mapped to each risk tier?

Scope

In scope:

  • Defining risk tier categories suited to enterprise AI and low-code use cases (e.g. informational, decision-support, autonomous action, and any intermediate tiers)
  • Criteria for classifying a use case into a risk tier (reversibility of action, regulatory exposure, data sensitivity, scope of automated decision, human override availability)
  • Mapping from risk tier to required governance controls (approval thresholds, oversight intensity, monitoring requirements, human review frequency)
  • Existing risk classification frameworks from regulatory bodies (European Union (EU) AI Act risk classification, National Institute of Standards and Technology (NIST) Artificial Intelligence Risk Management Framework (AI RMF) 1.0, International Organization for Standardization (ISO) / International Electrotechnical Commission (IEC) 42001) and how they can be adapted for enterprise-internal classification
  • How risk tier assignment should evolve when a use case changes scope or capability over time

Out of scope:

  • Technical implementation of risk tier controls (covered by Q3/Q16)
  • Per-regulation compliance mapping (covered by Q15)
  • Vendor-specific limitations on implementing tier-appropriate controls (covered by Q11)
  • Organisational factors affecting compliance with tier assignment (covered by Q14)

Constraints:

  • Must produce a classification scheme that is operable by business analysts, not just risk specialists
  • Must be compatible with at least one major external regulatory framework (EU AI Act or NIST AI RMF 1.0)
  • Sources must be assessable for applicability to a regulated enterprise (financial services context preferred)

Context

  • [inference; source: https://davidamitchell.github.io/Research/research/2026-04-24-business-led-low-code-agent-governance.html; https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-ai-rmf-10; https://handbook.apra.gov.au/ppg/cpg-230] A uniform control set across all Artificial Intelligence (AI) and low-code use cases would over-control read-only informational tools and under-control write-capable or autonomy-heavy systems, because the reviewed frameworks all expect governance effort to scale with context, risk tolerance, and operational materiality.

  • [inference; source: https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-governance-enforcement-architecture.html; https://davidamitchell.github.io/Research/research/2026-04-26-deployment-pipeline-citizen-development-governed-gate.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-observability-telemetry-governance.html] A tiered classification scheme is therefore the prerequisite for later choices about decision rights, release gates, telemetry depth, and lifecycle controls, because those mechanisms only become proportionate once the enterprise has decided which use cases can merely inform, which can influence, and which can act.

  • [fact; source: https://davidamitchell.github.io/Research/research/2026-04-26-deployment-pipeline-citizen-development-governed-gate.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-observability-telemetry-governance.html] This item is prerequisite to Q1, because approval rights vary by tier, Q9, because human review intensity varies by tier, and Q8, because cost or benefit analysis depends on knowing which controls are required for a given class of use case.

Cross-references:

  • Q1: 2026-04-26-ai-lowcode-decision-rights-accountability-liability
  • Q9: 2026-04-26-human-in-the-loop-ai-automated-workflows
  • Q8: 2026-04-26-ai-governance-cost-performance-delivery-impact
  • Q16: 2026-04-26-ai-agent-control-plane-architecture-enterprise
  • Q15: 2026-04-26-ai-lowcode-regulatory-compliance-alignment

Approach

  1. Survey existing classification frameworks: Review the EU AI Act (prohibited, high-risk, limited risk, minimal risk), NIST AI RMF 1.0 (risk characterisation dimensions), ISO/IEC 42001, and any enterprise-specific tier models published by major financial services regulators (Australian Prudential Regulation Authority (APRA), United Kingdom (UK) Financial Conduct Authority (FCA) / Prudential Regulation Authority (PRA), Basel Committee). Assess applicability to internal enterprise use cases (not just externally-facing AI systems).
  2. Define tier boundaries: Based on the survey, propose a working set of risk tiers with explicit boundary criteria (what makes a use case fall into each tier, including edge cases at tier boundaries).
  3. Map controls to tiers: For each tier, specify what governance controls are required, approval authority, documentation standard, monitoring frequency, human review requirements, incident escalation, and decommissioning criteria.
  4. Evaluate operability: Assess whether the proposed classification can be applied by a business analyst with minimal specialist knowledge, that is, whether it is a usable decision framework rather than only a theoretical taxonomy.
  5. Cross-reference with regulatory obligations: Identify which tier boundaries align with regulatory trigger points (e.g., the EU AI Act's high-risk classification thresholds, APRA Prudential Standard (CPS) 230 operational risk materiality).
  6. Synthesis: Produce a practical risk tier classification decision tree and control matrix suitable for use as an enterprise governance artefact.

Sources

Related


Research Skill Output

(Full output from running the research skill, retained verbatim in the completed item. Sections 0 to 5 are the investigation, and section 6 seeds the Findings section below.)

§0 Initialise

  • [fact; source: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai; https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-ai-rmf-10; https://handbook.apra.gov.au/ppg/cpg-230] Research question restated: what internal risk-tiering model should an enterprise use for AI and low-code use cases so that informational systems, decision-support systems, and action-capable systems are classified consistently and governed with controls proportionate to their autonomy, impact, and regulatory exposure?
  • [fact; source: https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-9; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://handbook.apra.gov.au/standard/cps-230] Scope confirmed: the investigation covers external classification frameworks, internal tier-boundary criteria, control mapping by tier, operability by business analysts, and re-tiering when a use case changes capability or business context.
  • [fact; source: https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-ai-rmf-10; https://www.bankofengland.co.uk/prudential-regulation/publication/2022/october/artificial-intelligence; https://www.bis.org/fsi/publ/insights63.htm] Constraint confirmed: the answer must remain practical for enterprise intake, must map to at least one major external framework, and must not assume that financial-services supervisors will accept a vendor-specific or technology-only taxonomy.
  • [fact; source: https://davidamitchell.github.io/Research/research/2026-04-24-business-led-low-code-agent-governance.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-governance-enforcement-architecture.html; https://davidamitchell.github.io/Research/research/2026-04-26-deployment-pipeline-citizen-development-governed-gate.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-lifecycle-management.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-observability-telemetry-governance.html] Prior work cross-reference: adjacent completed items already established that low-code value depends on bounded maker enablement, that controls must attach to concrete enforcement points, that action-capable systems need a governed release gate, that promoted artefacts need lifecycle state, and that governance needs attributable telemetry, so this item narrows the problem to the tiering logic that determines when each of those controls becomes mandatory.
  • [fact; source: https://www.nist.gov/itl/ai-risk-management-framework/nist-ai-rmf-playbook; https://www.bankofengland.co.uk/prudential-regulation/publication/2022/october/artificial-intelligence] Access note: the seeded NIST Playbook URL https://airc.nist.gov/Docs/1 and the seeded Financial Conduct Authority (FCA) PDF URL returned dead links in this runtime, so the current official NIST and Bank of England pages were used for downstream claims.
  • Output format: knowledge.

§1 Question Decomposition

  • Root question: What tier model lets an enterprise scale controls for AI and low-code use cases without collapsing into either one-size-fits-all bureaucracy or under-governed autonomy?
  • A. External-framework baseline
    • A1. What does the European Union (EU) AI Act classify directly, and what obligations attach to its higher-risk categories?
    • A2. What does the NIST Artificial Intelligence Risk Management Framework (AI RMF) say about context, risk tolerance, impact magnitude, and human-AI configuration?
    • A3. What does ISO/IEC 42001 add as a management-system baseline?
    • A4. What do APRA, the Bank of England, and Basel materials say about proportionality, materiality, and governance in regulated firms?
  • B. Boundary design
    • B1. Which criteria best separate informational, decision-support, bounded-action, and autonomous-action systems?
    • B2. Which criteria are modifiers rather than primary axes, for example data sensitivity or regulatory trigger points?
    • B3. When should a use case be classified as no-go rather than as a higher tier?
  • C. Control mapping
    • C1. Which controls should apply to every tier?
    • C2. Which controls should appear only once a system can influence a material decision?
    • C3. Which controls should appear only once a system can take direct action?
    • C4. Which controls should appear only for critical or high-autonomy action?
  • D. Operability
    • D1. Can a business analyst classify a use case using a short intake sequence?
    • D2. What evidence must be captured so that the classification can be reviewed later?
  • E. Change over time
    • E1. What events should force re-tiering?
    • E2. Should the enterprise use the highest-triggered tier, or average multiple factors together?

§2 Investigation

  • Source access and replacement notes

    • [fact; source: https://www.nist.gov/itl/ai-risk-management-framework/nist-ai-rmf-playbook] Access note: seeded NIST Playbook link replaced with the current official NIST playbook page.
    • [fact; source: https://www.bankofengland.co.uk/prudential-regulation/publication/2022/october/artificial-intelligence] Access note: seeded FCA PDF link replaced with the current official Bank of England Discussion Paper 5/22 page.
  • A. What the reviewed external frameworks actually provide

    • [fact; source: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai] The European Commission's AI Act overview defines four legal risk groupings, unacceptable risk, high-risk, transparency risk, and minimal or no risk, and reserves strict ex ante obligations for high-risk systems while banning unacceptable practices outright.
    • [fact; source: https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-9] Article 9 requires a high-risk system's risk-management process to be continuous across the lifecycle, to consider intended purpose and reasonably foreseeable misuse, and to adopt targeted mitigation measures until residual risk is acceptable.
    • [fact; source: https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-14] Article 14 says human-oversight measures must be commensurate with the risks, level of autonomy, and context of use, and that overseers must be able to understand limitations, detect anomalies, override outputs, or halt the system safely.
    • [fact; source: https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-26] Article 26 requires deployers of high-risk systems to assign competent human oversight, monitor operation, suspend use when risk emerges, and keep automatically generated logs for at least six months when those logs are under their control.
    • [inference; source: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai; https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-9; https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-14; https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-26] The AI Act therefore supplies legal trigger points and mandatory controls for certain categories, but it does not offer a complete internal enterprise taxonomy for routine internal uses such as drafting, summarization, bounded workflow automation, or internal decision support.
    • [fact; source: https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-ai-rmf-10] NIST AI RMF 1.0 describes itself as voluntary, rights-preserving, non-sector specific, and use-case agnostic, and states that organizations can operationalize it in varying degrees and capacities.
    • [fact; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/] The NIST AI RMF Core says risk management should be continuous across the lifecycle and lists Govern outcomes for risk tolerance, policies, accountability, inventory, ongoing review, and safe decommissioning.
    • [fact; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/] The Map outcomes require organizations to document intended purpose, context-specific laws and expectations, organizational risk tolerances, knowledge limits, human oversight processes, targeted application scope, and the likelihood and magnitude of identified impacts.
    • [fact; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/] The NIST AI RMF Core also says that after the Map function an organization should have enough contextual knowledge to make an initial go or no-go decision about whether to design, develop, or deploy the system.
    • [inference; source: https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-ai-rmf-10; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/] NIST provides the structure for an internal classification model, because it explicitly separates intended purpose, knowledge limits, human-AI configuration, impact magnitude, and risk tolerance, but it leaves the actual tier labels and approval thresholds to the organization.
    • [fact; source: https://www.nist.gov/itl/ai-risk-management-framework/nist-ai-rmf-playbook] The NIST AI RMF Playbook says organizations may borrow as many or as few suggestions as apply to their industry use case or interests, which confirms that the framework is intended to be tailored rather than copied as a rigid checklist.
    • [fact; source: https://www.iso.org/standard/81230.html] ISO/IEC 42001 is described by ISO as an Artificial Intelligence Management System standard for establishing, implementing, maintaining, and continually improving policies, objectives, and processes for responsible development, provision, or use of AI systems.
    • [fact; source: https://www.iso.org/standard/81230.html] ISO's public summary also says the standard addresses risk and opportunity management, traceability, transparency, and reliability across an organization's AI use rather than prescribing detailed tier labels for specific applications.
    • [inference; source: https://www.iso.org/standard/81230.html] ISO/IEC 42001 supports the need for consistent intake, documentation, review, and continual improvement, but like NIST it does not remove the need for an enterprise-specific operational tier model.
    • [fact; source: https://handbook.apra.gov.au/standard/cps-230] APRA CPS 230 says an entity's operational-risk approach must be appropriate to its size, business mix, and complexity, and requires identification, assessment, and management of operational risk with effective internal controls, monitoring, and remediation.
    • [fact; source: https://handbook.apra.gov.au/ppg/cpg-230] APRA CPG 230 says all regulated entities should mature their practices to match the scale of their risks and role in the financial system, and that significant financial institutions should have stronger practices commensurate with the size and complexity of their operations.
    • [fact; source: https://handbook.apra.gov.au/ppg/cpg-230] APRA's guidance defines critical operations and material arrangements by whether disruption would have a material adverse impact, which gives a direct enterprise lens for deciding when a use case crosses from ordinary productivity into materially governed operational risk.
    • [fact; source: https://www.bankofengland.co.uk/prudential-regulation/publication/2022/october/artificial-intelligence] Discussion Paper 5/22 says AI may amplify existing risks to consumers, firms, market integrity, and financial stability, and frames the regulatory problem as largely one of clarifying how the existing framework applies to AI and where governance or decision-making gaps remain.
    • [fact; source: https://www.bis.org/publ/bcbs_nl27.htm] The Basel Committee newsletter says banks seek transparency and interpretability commensurate with the risk of the banking activity being supported and identifies governance, resilience, and data governance as focal concerns for supervisory analysis.
    • [fact; source: https://www.bis.org/fsi/publ/insights63.htm] FSI Insights 63 says most financial authorities rely on existing frameworks to address most AI-related risks while expecting stronger governance, expertise, model-risk management, data governance, and third-party oversight where risk is higher.
    • [inference; source: https://handbook.apra.gov.au/ppg/cpg-230; https://www.bankofengland.co.uk/prudential-regulation/publication/2022/october/artificial-intelligence; https://www.bis.org/publ/bcbs_nl27.htm; https://www.bis.org/fsi/publ/insights63.htm] Financial-services supervisors therefore support proportionality and materiality as the scaling logic, not a single universal set of controls for every AI or low-code use case.
  • B. What the evidence implies for enterprise-internal tier boundaries

    • [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-14; https://handbook.apra.gov.au/ppg/cpg-230] The strongest primary boundary variables are action authority and consequence, because the reviewed sources repeatedly focus on human-AI configuration, oversight, impact magnitude, and materiality rather than on model type or interface style.
    • [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-9; https://handbook.apra.gov.au/standard/cps-230] Data sensitivity, legal trigger points, critical-operation dependence, and reversibility are modifier variables that can escalate a use case upward, but they do not by themselves distinguish an informational tool from an action-capable one.
    • [inference; source: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai; https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-9; https://handbook.apra.gov.au/standard/cps-230] A separate no-go overlay is needed because some use cases should be refused outright, either because the law prohibits them or because residual risk remains outside organizational tolerance even after mitigation.
    • [inference; source: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://www.bis.org/fsi/publ/insights63.htm] The best-fit internal operating model is therefore four positive tiers, informational, decision-support, bounded action, and autonomous or critical action, plus a no-go overlay for prohibited or out-of-appetite uses.
  • C. Proposed enterprise tier definitions

    • [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai] No-go or prohibited: a use case falls into the no-go overlay when it maps to a prohibited legal category, or when the organization cannot make residual risk acceptable through design, mitigation, oversight, and governance.
    • [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-ai-rmf-10; https://davidamitchell.github.io/Research/research/2026-04-24-business-led-low-code-agent-governance.html] Tier 1, informational: the system is read-only in effect, does not directly change enterprise state, does not materially determine customer or employee outcomes, and any error is low-cost and easily reversible through ordinary human work.
    • [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-14; https://www.bankofengland.co.uk/prudential-regulation/publication/2022/october/artificial-intelligence] Tier 2, decision-support: the system materially influences human decisions, or operates on sensitive data or important operational contexts, but a competent human remains the legally and operationally effective decision-maker for each consequential outcome.
    • [inference; source: https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-14; https://davidamitchell.github.io/Research/research/2026-04-26-deployment-pipeline-citizen-development-governed-gate.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-governance-enforcement-architecture.html] Tier 3, bounded action: the system can write, trigger, publish, or otherwise change enterprise state within a narrow and pre-approved blast radius, and the organization can define scope, rollback, override, and monitoring controls tightly enough to keep residual risk inside tolerance.
    • [inference; source: https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-14; https://handbook.apra.gov.au/ppg/cpg-230; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-observability-telemetry-governance.html] Tier 4, autonomous or critical action: the system can take multi-step or cross-system action, affect critical operations or rights-significant outcomes, or create harms that are difficult to reverse quickly, so continuous supervision and formal governance become necessary conditions of deployment.
  • D. Minimum controls mapped to each tier

    • [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://www.iso.org/standard/81230.html] Every tier should require an owner, an inventory record, an intended-purpose statement, approved data or connector scope, and a periodic review trigger, because even low-risk systems still need accountability and lifecycle discipline.
    • [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-observability-telemetry-governance.html] Tier 1 should add basic testing, user transparency, and standard telemetry, but it does not require dedicated risk-committee approval because the system remains read-only in effect and low-cost to reverse.
    • [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-14; https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-26] Tier 2 should require documented limitations, human-review assignment, evidence logging, and periodic validation against observed outcomes, because the core risk is automation bias or over-reliance rather than direct machine execution.
    • [inference; source: https://davidamitchell.github.io/Research/research/2026-04-26-deployment-pipeline-citizen-development-governed-gate.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-governance-enforcement-architecture.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-lifecycle-management.html] Tier 3 should require a deployment gate, segregated environments, least-privilege machine identity, rollback mechanics, and action-level telemetry, because once a system can change enterprise state, design-time review alone is not an enforceable control.
    • [inference; source: https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-9; https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-14; https://handbook.apra.gov.au/ppg/cpg-230; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-observability-telemetry-governance.html] Tier 4 should require formal approval by accountable business, technology, and risk leaders, independent validation, staged rollout, continuous monitoring, safe-halt capability, and more frequent recertification, because its failure modes approach critical operational-risk territory.
  • E. Operability by business analysts

    • [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://www.nist.gov/itl/ai-risk-management-framework/nist-ai-rmf-playbook] A business analyst can apply the tier model if intake begins with a short sequence of factual questions, what the system can do, what it can affect, which data it uses, who can override it, and how reversible errors are, because those are the same contextual fields NIST requires organizations to document.
    • [inference; source: https://handbook.apra.gov.au/ppg/cpg-230; https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai] The classification process should use highest-triggered-tier logic rather than averaging answers, because APRA-style materiality and AI Act trigger points are threshold concepts and are weakened if a single severe dimension can be diluted by several benign ones.
  • F. When a use case must be re-tiered

    • [fact; source: https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-9; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/] Both the AI Act and NIST AI RMF treat risk assessment as continuous across the lifecycle rather than as a one-time approval event.
    • [fact; source: https://handbook.apra.gov.au/ppg/cpg-230] APRA's guidance says boards should understand material operational risks that arise from new ventures and that entities should update practices as operations grow and evolve.
    • [inference; source: https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-9; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://handbook.apra.gov.au/ppg/cpg-230; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-lifecycle-management.html] Re-tiering should therefore be mandatory whenever intended purpose, action authority, user population, integrated systems, data sensitivity, or dependency on a critical operation changes, because those changes alter the system's context, impact, and residual risk even if the user interface still looks similar.

§3 Reasoning

  • [fact; source: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://handbook.apra.gov.au/ppg/cpg-230] The reviewed sources agree on proportionality, documentation, human oversight, and monitoring as core governance ideas.
  • [inference; source: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/] The main design gap is that none of the reviewed frameworks gives a fully usable internal taxonomy for everyday enterprise-internal use cases that sit below formal legal high-risk thresholds but above harmless drafting.
  • [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-14; https://handbook.apra.gov.au/ppg/cpg-230] Action authority and consequence are the best primary axes because they recur across human oversight, impact magnitude, and operational materiality.
  • [inference; source: https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-9; https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai] Legal trigger points should operate as overlays that can escalate a use case to no-go or to the highest control band without forcing the enterprise to force every internal use case into a statutory label.
  • [inference; source: https://davidamitchell.github.io/Research/research/2026-04-26-deployment-pipeline-citizen-development-governed-gate.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-observability-telemetry-governance.html] The control map must change sharply once a system can act, because deployment gating, rollback, and action telemetry become mandatory only after the system can alter enterprise state.

§4 Consistency Check

  • [fact; source: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://handbook.apra.gov.au/ppg/cpg-230] No reviewed official source argued for identical controls across all AI and low-code use cases.
  • [inference; source: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/] The main conceptual tension is that the AI Act uses legal categories while NIST uses contextual risk-management categories, and that tension is resolved by treating the AI Act as a legal overlay and NIST as the operational design scaffold.
  • [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://handbook.apra.gov.au/ppg/cpg-230] A borderline system that only recommends but materially shapes credit, fraud, workforce, or critical-operation decisions belongs in Tier 2 or higher, because consequence can be high even when the machine does not directly execute the final action.
  • [fact; source: https://www.iso.org/standard/81230.html] The public ISO page confirms management-system principles but does not expose the full normative text, so the synthesis limits ISO-based claims to its published summary.

§5 Depth and Breadth Expansion

  • [inference; source: https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-governance-enforcement-architecture.html; https://davidamitchell.github.io/Research/research/2026-04-26-deployment-pipeline-citizen-development-governed-gate.html] Technical lens: the largest control jump occurs at the moment a system gains direct write or trigger capability, because that is where approval, least privilege, release gating, and rollback move from optional hygiene to enforceable safety mechanisms.
  • [inference; source: https://handbook.apra.gov.au/standard/cps-230; https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-26; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-regulatory-compliance-alignment.html] Regulatory lens: financial-services supervision cares less about whether a system is marketed as an assistant or an agent than about whether it affects material operations, requires accountable oversight, and generates retrievable evidence.
  • [inference; source: https://davidamitchell.github.io/Research/research/2026-04-24-business-led-low-code-agent-governance.html; https://davidamitchell.github.io/Research/research/2026-04-26-systems-capability-debt-agentic-ai-risk-synthesis.html] Economic and organizational lens: forcing all use cases into the highest control band would increase friction and likely push demand into shadow tooling, which means proportionality is not only efficient but also control-preserving.
  • [inference; source: https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-14; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/] Behavioral lens: nominal human involvement is not enough to keep a system in a lower tier, because oversight only counts when the reviewer can understand limitations, detect anomalies, and truly override the output.
  • [inference; source: https://www.bankofengland.co.uk/prudential-regulation/publication/2022/october/artificial-intelligence; https://www.bis.org/fsi/publ/insights63.htm] Historical lens: supervisors are still mostly adapting existing governance frameworks rather than creating entirely new AI-only control stacks, which makes an internal proportional tier model more durable than a platform-specific checklist.

§6 Synthesis

(This section seeds the Findings below.)

Executive summary:

  • [inference; source: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://handbook.apra.gov.au/ppg/cpg-230] The most workable enterprise classification for AI and low-code use cases is a four-tier operating model, informational, decision-support, bounded action, and autonomous or critical action, with a separate no-go overlay for prohibited or out-of-appetite uses, because the reviewed frameworks all scale controls by impact, autonomy, and context rather than by one universal rule set.
  • [inference; source: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai; https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-9; https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-14; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/] The AI Act supplies legal trigger points for prohibited and high-risk cases, but it does not provide a complete internal taxonomy for routine enterprise-internal use cases, so firms need an internal tier model that maps to those trigger points rather than copying its labels verbatim.
  • [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-14; https://handbook.apra.gov.au/standard/cps-230] The decisive boundary questions are whether the system can take direct action, whether it affects critical operations or rights-significant outcomes, whether humans can competently override it, and whether errors are reversible at low cost.
  • [inference; source: https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-9; https://davidamitchell.github.io/Research/research/2026-04-26-deployment-pipeline-citizen-development-governed-gate.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-observability-telemetry-governance.html] Governance should therefore escalate from registration and standard controls at Tier 1 to documented human review at Tier 2, deployment gating and least-privilege machine authority at Tier 3, and formal approval, continuous monitoring, and safe-halt design at Tier 4.

Key findings:

  1. High confidence. [inference; source: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://handbook.apra.gov.au/ppg/cpg-230] No reviewed framework provides a ready-made internal enterprise taxonomy for every AI and low-code use case, so regulated firms need an internal operating tier model that adapts legal and risk-management principles into day-to-day intake decisions.
  2. High confidence. [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-14; https://handbook.apra.gov.au/ppg/cpg-230] The best primary classifier is the combination of action authority and consequence, because the strongest reviewed signals are autonomy, human oversight, impact magnitude, and operational materiality rather than vendor, interface, or model type.
  3. High confidence. [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-ai-rmf-10; https://davidamitchell.github.io/Research/research/2026-04-24-business-led-low-code-agent-governance.html] Informational systems should remain in the lowest positive tier only when they are effectively read-only, do not materially shape consequential decisions, and produce errors that ordinary human work can detect and reverse cheaply.
  4. High confidence. [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-14; https://www.bankofengland.co.uk/prudential-regulation/publication/2022/october/artificial-intelligence] Decision-support systems enter a higher tier as soon as they materially influence credit, workforce, fraud, or critical-operation judgments, because effective human review and limitation documentation then become control necessities rather than optional good practice.
  5. Medium confidence. [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-14; https://davidamitchell.github.io/Research/research/2026-04-26-deployment-pipeline-citizen-development-governed-gate.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-governance-enforcement-architecture.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-lifecycle-management.html] Bounded-action systems deserve a distinct tier because once a system can write, trigger, publish, or modify records inside a pre-approved scope, oversight logic from NIST and the AI Act combines with prior completed architecture work to make deployment gates, least privilege, rollback, and action telemetry the minimum credible controls.
  6. High confidence. [inference; source: https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-9; https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-14; https://handbook.apra.gov.au/ppg/cpg-230; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-observability-telemetry-governance.html] Autonomous or critical-action systems require the highest positive tier, because multi-step action against critical operations or rights-significant outcomes demands formal approval, independent validation, continuous monitoring, and safe-stop capability.
  7. High confidence. [inference; source: https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-9; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://handbook.apra.gov.au/ppg/cpg-230; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-lifecycle-management.html] Tier assignment cannot be a one-time event, because changes in intended purpose, autonomy, connected systems, data sensitivity, or business criticality alter context and residual risk even when the interface remains unchanged.
  8. Medium confidence. [inference; source: https://davidamitchell.github.io/Research/research/2026-04-24-business-led-low-code-agent-governance.html; https://davidamitchell.github.io/Research/research/2026-04-26-systems-capability-debt-agentic-ai-risk-synthesis.html; https://handbook.apra.gov.au/ppg/cpg-230] Over-classifying every use case as high risk would likely increase friction and shadow tooling, so a proportional model is not merely efficient but also more likely to preserve real governance coverage across the estate.

Evidence map:

Claim Source Confidence Notes
[inference] No reviewed framework provides a complete internal enterprise taxonomy, so firms need an internal tier model. https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://handbook.apra.gov.au/ppg/cpg-230 high EU, NIST, and APRA provide principles and trigger points, not a full internal operating taxonomy.
[inference] Action authority plus consequence is the strongest primary classifier. https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-14; https://handbook.apra.gov.au/ppg/cpg-230 high Human oversight, impact magnitude, and materiality recur across all three sources.
[inference] Tier 1 should be limited to read-only, low-consequence, easily reversible systems. https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-ai-rmf-10; https://davidamitchell.github.io/Research/research/2026-04-24-business-led-low-code-agent-governance.html high Based on NIST context and risk-tolerance framing plus prior low-code governance evidence.
[inference] Tier 2 begins when outputs materially shape consequential human decisions. https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-14; https://www.bankofengland.co.uk/prudential-regulation/publication/2022/october/artificial-intelligence high Oversight and materiality matter even without direct machine execution.
[inference] Tier 3 should be reserved for bounded state-changing actions that still fit inside a controlled blast radius. https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-14; https://davidamitchell.github.io/Research/research/2026-04-26-deployment-pipeline-citizen-development-governed-gate.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-governance-enforcement-architecture.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-lifecycle-management.html medium Primary sources justify the action and oversight threshold, while prior completed items support the specific control pattern.
[inference] Tier 4 is required for autonomous or critical-action systems that can create high-cost or hard-to-reverse harms. https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-9; https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-14; https://handbook.apra.gov.au/ppg/cpg-230; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-observability-telemetry-governance.html high Lifecycle mitigation, oversight, materiality, and telemetry obligations converge here.
[inference] Tier assignment must be revisited when scope, capability, or business context changes. https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-9; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://handbook.apra.gov.au/ppg/cpg-230; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-lifecycle-management.html high All cited sources treat risk as iterative across the lifecycle.
[inference] Proportional tiering is more governance-preserving than classifying all systems at the highest tier. https://davidamitchell.github.io/Research/research/2026-04-24-business-led-low-code-agent-governance.html; https://davidamitchell.github.io/Research/research/2026-04-26-systems-capability-debt-agentic-ai-risk-synthesis.html; https://handbook.apra.gov.au/ppg/cpg-230 medium Strong prior-work support, but direct empirical quantification is limited.

Assumptions:

  • [assumption; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://www.nist.gov/itl/ai-risk-management-framework/nist-ai-rmf-playbook] The specific tier labels, informational, decision-support, bounded action, and autonomous or critical action, are enterprise design choices rather than mandated external terms. Justification: the reviewed frameworks provide principles and trigger criteria but do not prescribe one canonical internal label set for all enterprise use cases.
  • [assumption; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://handbook.apra.gov.au/ppg/cpg-230] A business analyst can apply the model reliably if the intake process forces explicit answers about action authority, impact, data sensitivity, overrideability, and reversibility. Justification: the frameworks require those facts to be documented, but they do not prove that every organization's intake form will capture them cleanly without local design work.

Analysis:

  • [inference; source: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://handbook.apra.gov.au/ppg/cpg-230] The synthesis weights NIST most heavily for internal classification mechanics, because NIST explicitly decomposes context, risk tolerance, human oversight, impact magnitude, and go or no-go decisions, while the AI Act and APRA provide stronger legal and prudential escalation triggers.
  • [inference; source: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai; https://www.bis.org/fsi/publ/insights63.htm; https://www.bankofengland.co.uk/prudential-regulation/publication/2022/october/artificial-intelligence] The AI Act is treated as a mandatory overlay rather than as the whole taxonomy, because its legal classes are essential for prohibited and high-risk cases but are too coarse for routine internal enterprise uses that still need differentiated controls.
  • [inference; source: https://davidamitchell.github.io/Research/research/2026-04-26-deployment-pipeline-citizen-development-governed-gate.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-governance-enforcement-architecture.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-observability-telemetry-governance.html] The sharpest control boundary is the transition from influence to execution, because that is the point where release controls, least-privilege machine authority, rollback, and action telemetry become the only credible ways to constrain harm.
  • [inference; source: https://davidamitchell.github.io/Research/research/2026-04-24-business-led-low-code-agent-governance.html; https://davidamitchell.github.io/Research/research/2026-04-26-systems-capability-debt-agentic-ai-risk-synthesis.html] The model also balances control against adoption reality, because an enterprise that assigns every use case to the highest tier is likely to recreate the shadow-tooling dynamics that previous completed items identified as a governance failure mode.
  • [inference; source: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai; https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-9; https://handbook.apra.gov.au/ppg/cpg-230] Tier 0, no-go: reject any use case that falls into a prohibited legal category or still sits outside risk appetite after mitigation and oversight design.
  • [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-ai-rmf-10; https://davidamitchell.github.io/Research/research/2026-04-24-business-led-low-code-agent-governance.html] Tier 1, informational: allow use cases that are read-only in effect, low consequence, and easily reversible under standard ownership, inventory, approved data scope, basic testing, transparency, and standard telemetry controls.
  • [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-14; https://www.bankofengland.co.uk/prudential-regulation/publication/2022/october/artificial-intelligence] Tier 2, decision-support: require documented limitations, an assigned human reviewer, evidence logging, and periodic validation once outputs materially shape consequential human decisions.
  • [inference; source: https://davidamitchell.github.io/Research/research/2026-04-26-deployment-pipeline-citizen-development-governed-gate.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-governance-enforcement-architecture.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-lifecycle-management.html] Tier 3, bounded action: require a deployment gate, segregated environments, least privilege, rollback, and action-level telemetry once a system can change state inside a pre-approved blast radius.
  • [inference; source: https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-9; https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-14; https://handbook.apra.gov.au/ppg/cpg-230; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-observability-telemetry-governance.html] Tier 4, autonomous or critical action: require formal approval, independent validation, staged rollout, continuous monitoring, and safe-halt capability for multi-step or high-impact action.

Risks, gaps, uncertainties:

  • [fact; source: https://www.iso.org/standard/81230.html] The full normative text of ISO/IEC 42001 was not accessible in this session, so ISO-backed claims are limited to the official public summary rather than clause-level interpretation.
  • [fact; source: https://www.bankofengland.co.uk/prudential-regulation/publication/2022/october/artificial-intelligence; https://www.bis.org/fsi/publ/insights63.htm] UK and Basel supervisory materials support proportionality and governance scaling, but they provide less detailed tier-boundary language than the AI Act or the NIST AI RMF Core.
  • [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-governance-enforcement-architecture.html] Borderline cases between Tier 2 and Tier 3 will usually turn on whether a system merely recommends an action or can actually commit, publish, trigger, or write that action into an enterprise system.
  • [fact; source: https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-26; https://handbook.apra.gov.au/ppg/cpg-230] None of the reviewed official sources specifies universal numeric approval thresholds, review cadences, or sample sizes by tier, so those thresholds still need local policy design.

Open questions:

  • [inference; source: https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-14; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/] What evidence should count as proof that human oversight is genuinely effective rather than nominal for Tier 2 and Tier 4 systems?
  • [inference; source: https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-observability-telemetry-governance.html; https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-26] What minimum telemetry set is sufficient to prove that a system has stayed within its approved tier in production rather than drifting into a higher-risk operating pattern?
  • [inference; source: https://davidamitchell.github.io/Research/research/2026-04-26-deployment-pipeline-citizen-development-governed-gate.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-lifecycle-management.html] Which promotion and re-certification cadence should attach to Tier 3 and Tier 4 systems once the enterprise converts the tier model into an operating procedure?

§7 Recursive Review

  • [inference; source: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://handbook.apra.gov.au/ppg/cpg-230] Recursive review did not surface evidence that would overturn the proportional four-tier model with a no-go overlay, and the remaining uncertainty concerns local approval thresholds rather than the tier structure itself.

Findings

(Populated from §6 Synthesis above.)

Executive Summary

  • [inference; source: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://handbook.apra.gov.au/ppg/cpg-230] The most workable enterprise classification for AI and low-code use cases is a four-tier operating model, informational, decision-support, bounded action, and autonomous or critical action, with a separate no-go overlay for prohibited or out-of-appetite uses, because the reviewed frameworks all scale controls by impact, autonomy, and context rather than by one universal rule set.
  • [inference; source: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai; https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-9; https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-14; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/] The AI Act supplies legal trigger points for prohibited and high-risk cases, but it does not provide a complete internal taxonomy for routine enterprise-internal use cases, so firms need an internal tier model that maps to those trigger points rather than copying its labels verbatim.
  • [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-14; https://handbook.apra.gov.au/standard/cps-230] The decisive boundary questions are whether the system can take direct action, whether it affects critical operations or rights-significant outcomes, whether humans can competently override it, and whether errors are reversible at low cost.
  • [inference; source: https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-9; https://davidamitchell.github.io/Research/research/2026-04-26-deployment-pipeline-citizen-development-governed-gate.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-observability-telemetry-governance.html] Governance should therefore escalate from registration and standard controls at Tier 1 to documented human review at Tier 2, deployment gating and least-privilege machine authority at Tier 3, and formal approval, continuous monitoring, and safe-halt design at Tier 4.

Key Findings

  1. High confidence. [inference; source: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://handbook.apra.gov.au/ppg/cpg-230] No reviewed framework provides a ready-made internal enterprise taxonomy for every AI and low-code use case, so regulated firms need an internal operating tier model that adapts legal and risk-management principles into day-to-day intake decisions.
  2. High confidence. [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-14; https://handbook.apra.gov.au/ppg/cpg-230] The best primary classifier is the combination of action authority and consequence, because the strongest reviewed signals are autonomy, human oversight, impact magnitude, and operational materiality rather than vendor, interface, or model type.
  3. High confidence. [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-ai-rmf-10; https://davidamitchell.github.io/Research/research/2026-04-24-business-led-low-code-agent-governance.html] Informational systems should remain in the lowest positive tier only when they are effectively read-only, do not materially shape consequential decisions, and produce errors that ordinary human work can detect and reverse cheaply.
  4. High confidence. [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-14; https://www.bankofengland.co.uk/prudential-regulation/publication/2022/october/artificial-intelligence] Decision-support systems enter a higher tier as soon as they materially influence credit, workforce, fraud, or critical-operation judgments, because effective human review and limitation documentation then become control necessities rather than optional good practice.
  5. Medium confidence. [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-14; https://davidamitchell.github.io/Research/research/2026-04-26-deployment-pipeline-citizen-development-governed-gate.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-governance-enforcement-architecture.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-lifecycle-management.html] Bounded-action systems deserve a distinct tier because once a system can write, trigger, publish, or modify records inside a pre-approved scope, oversight logic from NIST and the AI Act combines with prior completed architecture work to make deployment gates, least privilege, rollback, and action telemetry the minimum credible controls.
  6. High confidence. [inference; source: https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-9; https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-14; https://handbook.apra.gov.au/ppg/cpg-230; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-observability-telemetry-governance.html] Autonomous or critical-action systems require the highest positive tier, because multi-step action against critical operations or rights-significant outcomes demands formal approval, independent validation, continuous monitoring, and safe-stop capability.
  7. High confidence. [inference; source: https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-9; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://handbook.apra.gov.au/ppg/cpg-230; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-lifecycle-management.html] Tier assignment cannot be a one-time event, because changes in intended purpose, autonomy, connected systems, data sensitivity, or business criticality alter context and residual risk even when the interface remains unchanged.
  8. Medium confidence. [inference; source: https://davidamitchell.github.io/Research/research/2026-04-24-business-led-low-code-agent-governance.html; https://davidamitchell.github.io/Research/research/2026-04-26-systems-capability-debt-agentic-ai-risk-synthesis.html; https://handbook.apra.gov.au/ppg/cpg-230] Over-classifying every use case as high risk would likely increase friction and shadow tooling, so a proportional model is not merely efficient but also more likely to preserve real governance coverage across the estate.

Evidence Map

Claim Source Confidence Notes
[inference] No reviewed framework provides a complete internal enterprise taxonomy, so firms need an internal tier model. https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://handbook.apra.gov.au/ppg/cpg-230 high EU, NIST, and APRA provide principles and trigger points, not a full internal operating taxonomy.
[inference] Action authority plus consequence is the strongest primary classifier. https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-14; https://handbook.apra.gov.au/ppg/cpg-230 high Human oversight, impact magnitude, and materiality recur across all three sources.
[inference] Tier 1 should be limited to read-only, low-consequence, easily reversible systems. https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-ai-rmf-10; https://davidamitchell.github.io/Research/research/2026-04-24-business-led-low-code-agent-governance.html high Based on NIST context and risk-tolerance framing plus prior low-code governance evidence.
[inference] Tier 2 begins when outputs materially shape consequential human decisions. https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-14; https://www.bankofengland.co.uk/prudential-regulation/publication/2022/october/artificial-intelligence high Oversight and materiality matter even without direct machine execution.
[inference] Tier 3 should be reserved for bounded state-changing actions that still fit inside a controlled blast radius. https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-14; https://davidamitchell.github.io/Research/research/2026-04-26-deployment-pipeline-citizen-development-governed-gate.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-governance-enforcement-architecture.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-lifecycle-management.html medium Primary sources justify the action and oversight threshold, while prior completed items support the specific control pattern.
[inference] Tier 4 is required for autonomous or critical-action systems that can create high-cost or hard-to-reverse harms. https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-9; https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-14; https://handbook.apra.gov.au/ppg/cpg-230; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-observability-telemetry-governance.html high Lifecycle mitigation, oversight, materiality, and telemetry obligations converge here.
[inference] Tier assignment must be revisited when scope, capability, or business context changes. https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-9; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://handbook.apra.gov.au/ppg/cpg-230; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-lifecycle-management.html high All cited sources treat risk as iterative across the lifecycle.
[inference] Proportional tiering is more governance-preserving than classifying all systems at the highest tier. https://davidamitchell.github.io/Research/research/2026-04-24-business-led-low-code-agent-governance.html; https://davidamitchell.github.io/Research/research/2026-04-26-systems-capability-debt-agentic-ai-risk-synthesis.html; https://handbook.apra.gov.au/ppg/cpg-230 medium Strong prior-work support, but direct empirical quantification is limited.

Assumptions

  • [assumption; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://www.nist.gov/itl/ai-risk-management-framework/nist-ai-rmf-playbook] Assumption: The specific tier labels, informational, decision-support, bounded action, and autonomous or critical action, are enterprise design choices rather than mandated external terms. Justification: the reviewed frameworks provide principles and trigger criteria but do not prescribe one canonical internal label set for all enterprise use cases.
  • [assumption; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://handbook.apra.gov.au/ppg/cpg-230] Assumption: A business analyst can apply the model reliably if the intake process forces explicit answers about action authority, impact, data sensitivity, overrideability, and reversibility. Justification: the frameworks require those facts to be documented, but they do not prove that every organization's intake form will capture them cleanly without local design work.

Analysis

  • [inference; source: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://handbook.apra.gov.au/ppg/cpg-230] The synthesis weights NIST most heavily for internal classification mechanics, because NIST explicitly decomposes context, risk tolerance, human oversight, impact magnitude, and go or no-go decisions, while the AI Act and APRA provide stronger legal and prudential escalation triggers.
  • [inference; source: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai; https://www.bis.org/fsi/publ/insights63.htm; https://www.bankofengland.co.uk/prudential-regulation/publication/2022/october/artificial-intelligence] The AI Act is treated as a mandatory overlay rather than as the whole taxonomy, because its legal classes are essential for prohibited and high-risk cases but are too coarse for routine internal enterprise uses that still need differentiated controls.
  • [inference; source: https://davidamitchell.github.io/Research/research/2026-04-26-deployment-pipeline-citizen-development-governed-gate.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-governance-enforcement-architecture.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-observability-telemetry-governance.html] The sharpest control boundary is the transition from influence to execution, because that is the point where release controls, least-privilege machine authority, rollback, and action telemetry become the only credible ways to constrain harm.
  • [inference; source: https://davidamitchell.github.io/Research/research/2026-04-24-business-led-low-code-agent-governance.html; https://davidamitchell.github.io/Research/research/2026-04-26-systems-capability-debt-agentic-ai-risk-synthesis.html] The model also balances control against adoption reality, because an enterprise that assigns every use case to the highest tier is likely to recreate the shadow-tooling dynamics that previous completed items identified as a governance failure mode.
  • [inference; source: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai; https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-9; https://handbook.apra.gov.au/ppg/cpg-230] Tier 0, no-go: reject any use case that falls into a prohibited legal category or still sits outside risk appetite after mitigation and oversight design.
  • [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-ai-rmf-10; https://davidamitchell.github.io/Research/research/2026-04-24-business-led-low-code-agent-governance.html] Tier 1, informational: allow use cases that are read-only in effect, low consequence, and easily reversible under standard ownership, inventory, approved data scope, basic testing, transparency, and standard telemetry controls.
  • [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-14; https://www.bankofengland.co.uk/prudential-regulation/publication/2022/october/artificial-intelligence] Tier 2, decision-support: require documented limitations, an assigned human reviewer, evidence logging, and periodic validation once outputs materially shape consequential human decisions.
  • [inference; source: https://davidamitchell.github.io/Research/research/2026-04-26-deployment-pipeline-citizen-development-governed-gate.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-governance-enforcement-architecture.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-lifecycle-management.html] Tier 3, bounded action: require a deployment gate, segregated environments, least privilege, rollback, and action-level telemetry once a system can change state inside a pre-approved blast radius.
  • [inference; source: https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-9; https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-14; https://handbook.apra.gov.au/ppg/cpg-230; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-observability-telemetry-governance.html] Tier 4, autonomous or critical action: require formal approval, independent validation, staged rollout, continuous monitoring, and safe-halt capability for multi-step or high-impact action.

Risks, Gaps, and Uncertainties

  • [fact; source: https://www.iso.org/standard/81230.html] The full normative text of ISO/IEC 42001 was not accessible in this session, so ISO-backed claims are limited to the official public summary rather than clause-level interpretation.
  • [fact; source: https://www.bankofengland.co.uk/prudential-regulation/publication/2022/october/artificial-intelligence; https://www.bis.org/fsi/publ/insights63.htm] UK and Basel supervisory materials support proportionality and governance scaling, but they provide less detailed tier-boundary language than the AI Act or the NIST AI RMF Core.
  • [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-governance-enforcement-architecture.html] Borderline cases between Tier 2 and Tier 3 will usually turn on whether a system merely recommends an action or can actually commit, publish, trigger, or write that action into an enterprise system.
  • [fact; source: https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-26; https://handbook.apra.gov.au/ppg/cpg-230] None of the reviewed official sources specifies universal numeric approval thresholds, review cadences, or sample sizes by tier, so those thresholds still need local policy design.

Open Questions

  • [inference; source: https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-14; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/] What evidence should count as proof that human oversight is genuinely effective rather than nominal for Tier 2 and Tier 4 systems?
  • [inference; source: https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-observability-telemetry-governance.html; https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-26] What minimum telemetry set is sufficient to prove that a system has stayed within its approved tier in production rather than drifting into a higher-risk operating pattern?
  • [inference; source: https://davidamitchell.github.io/Research/research/2026-04-26-deployment-pipeline-citizen-development-governed-gate.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-lifecycle-management.html] Which promotion and re-certification cadence should attach to Tier 3 and Tier 4 systems once the enterprise converts the tier model into an operating procedure?

Output

(Fill in when completing, what was produced as a result of this research?)

Navigation

Home

By Tag

bureaucracy

change-management

coase

constraint-analysis

control-model

decision-rights

delegation

delivery-risk

demand-segmentation

enterprise

exception-handling

execution

flow

flow-design

flow-metrics

governance

governance-patterns

incentives

instability

institutional-economics

leading-indicators

operating-model

organisation

organisational-design

queue-design

queueing

regulated-enterprise

routing

throughput

throughput-risk

transaction-costs

triage

williamson

Clone this wiki locally