-
Notifications
You must be signed in to change notification settings - Fork 0
2026 04 26 ai lowcode risk tier classification controls
How should Artificial Intelligence (AI) and low-code use cases be classified into risk tiers, and how should governance controls vary across those tiers?
What structured risk classification framework is appropriate for AI and low-code use cases in enterprise environments, specifically, how should categories such as informational, decision-support, and autonomous action systems be defined and bounded, and how should required governance controls, oversight intensity, and approval thresholds be mapped to each risk tier?
In scope:
- Defining risk tier categories suited to enterprise AI and low-code use cases (e.g. informational, decision-support, autonomous action, and any intermediate tiers)
- Criteria for classifying a use case into a risk tier (reversibility of action, regulatory exposure, data sensitivity, scope of automated decision, human override availability)
- Mapping from risk tier to required governance controls (approval thresholds, oversight intensity, monitoring requirements, human review frequency)
- Existing risk classification frameworks from regulatory bodies (European Union (EU) AI Act risk classification, National Institute of Standards and Technology (NIST) Artificial Intelligence Risk Management Framework (AI RMF) 1.0, International Organization for Standardization (ISO) / International Electrotechnical Commission (IEC) 42001) and how they can be adapted for enterprise-internal classification
- How risk tier assignment should evolve when a use case changes scope or capability over time
Out of scope:
- Technical implementation of risk tier controls (covered by Q3/Q16)
- Per-regulation compliance mapping (covered by Q15)
- Vendor-specific limitations on implementing tier-appropriate controls (covered by Q11)
- Organisational factors affecting compliance with tier assignment (covered by Q14)
Constraints:
- Must produce a classification scheme that is operable by business analysts, not just risk specialists
- Must be compatible with at least one major external regulatory framework (EU AI Act or NIST AI RMF 1.0)
- Sources must be assessable for applicability to a regulated enterprise (financial services context preferred)
-
[inference; source: https://davidamitchell.github.io/Research/research/2026-04-24-business-led-low-code-agent-governance.html; https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-ai-rmf-10; https://handbook.apra.gov.au/ppg/cpg-230] A uniform control set across all Artificial Intelligence (AI) and low-code use cases would over-control read-only informational tools and under-control write-capable or autonomy-heavy systems, because the reviewed frameworks all expect governance effort to scale with context, risk tolerance, and operational materiality.
-
[inference; source: https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-governance-enforcement-architecture.html; https://davidamitchell.github.io/Research/research/2026-04-26-deployment-pipeline-citizen-development-governed-gate.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-observability-telemetry-governance.html] A tiered classification scheme is therefore the prerequisite for later choices about decision rights, release gates, telemetry depth, and lifecycle controls, because those mechanisms only become proportionate once the enterprise has decided which use cases can merely inform, which can influence, and which can act.
-
[fact; source: https://davidamitchell.github.io/Research/research/2026-04-26-deployment-pipeline-citizen-development-governed-gate.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-observability-telemetry-governance.html] This item is prerequisite to Q1, because approval rights vary by tier, Q9, because human review intensity varies by tier, and Q8, because cost or benefit analysis depends on knowing which controls are required for a given class of use case.
Cross-references:
- Q1:
2026-04-26-ai-lowcode-decision-rights-accountability-liability - Q9:
2026-04-26-human-in-the-loop-ai-automated-workflows - Q8:
2026-04-26-ai-governance-cost-performance-delivery-impact - Q16:
2026-04-26-ai-agent-control-plane-architecture-enterprise - Q15:
2026-04-26-ai-lowcode-regulatory-compliance-alignment
- Survey existing classification frameworks: Review the EU AI Act (prohibited, high-risk, limited risk, minimal risk), NIST AI RMF 1.0 (risk characterisation dimensions), ISO/IEC 42001, and any enterprise-specific tier models published by major financial services regulators (Australian Prudential Regulation Authority (APRA), United Kingdom (UK) Financial Conduct Authority (FCA) / Prudential Regulation Authority (PRA), Basel Committee). Assess applicability to internal enterprise use cases (not just externally-facing AI systems).
- Define tier boundaries: Based on the survey, propose a working set of risk tiers with explicit boundary criteria (what makes a use case fall into each tier, including edge cases at tier boundaries).
- Map controls to tiers: For each tier, specify what governance controls are required, approval authority, documentation standard, monitoring frequency, human review requirements, incident escalation, and decommissioning criteria.
- Evaluate operability: Assess whether the proposed classification can be applied by a business analyst with minimal specialist knowledge, that is, whether it is a usable decision framework rather than only a theoretical taxonomy.
- Cross-reference with regulatory obligations: Identify which tier boundaries align with regulatory trigger points (e.g., the EU AI Act's high-risk classification thresholds, APRA Prudential Standard (CPS) 230 operational risk materiality).
- Synthesis: Produce a practical risk tier classification decision tree and control matrix suitable for use as an enterprise governance artefact.
- European Commission AI Act overview — - official overview of prohibited, high-risk, transparency, and minimal-risk classes, plus applicability timeline
- AI Act Service Desk, Article 9 — - official text for continuous lifecycle risk management and targeted mitigation for high-risk AI systems
- AI Act Service Desk, Article 14 — - official text for human oversight measures commensurate with risk, autonomy, and context of use
- AI Act Service Desk, Article 26 — - official deployer duties for monitoring, logging, and competent human oversight
- NIST AI RMF 1.0 publication page — - official statement that the framework is voluntary, use-case agnostic, and intended to be operationalized at varying degrees
- NIST AI RMF Core — - authoritative Govern and Map categories for risk tolerance, human-AI configurations, impact magnitude, and go or no-go framing
- NIST AI RMF Playbook — - current official playbook entry page used in place of the seeded dead link
- ISO/IEC 42001:2023 — - public summary of the Artificial Intelligence Management System standard
- APRA Prudential Standard (CPS) 230 — - official prudential standard for operational-risk materiality, critical operations, internal controls, and monitoring
- APRA Prudential Practice Guide (CPG) 230 — - official APRA guidance on proportionality, stronger practices for significant financial institutions, and operational-risk profiling
- Bank of England Discussion Paper 5/22, Artificial Intelligence and Machine Learning — - official UK supervisory discussion paper on AI benefits, risk amplification, and governance challenges
- Basel Committee newsletter on artificial intelligence and machine learning — - Basel Committee statement that governance, transparency, and resilience should be commensurate with the risk of the activity being supported
- Financial Stability Institute (FSI) Insights 63, Regulating AI in the financial sector — - official synthesis that most financial authorities rely on existing frameworks plus stronger governance for higher-risk uses
- Business-led low-code agent governance — - prior completed repository item on proportional low-code governance and shadow Information Technology (IT) pressure
- Where should governance enforcement points be implemented within enterprise architecture? — - prior completed repository item on control placement across enterprise architecture
- Deployment pipeline as the enforceable control gate for citizen-developed agents — - prior completed repository item on promotion controls for action-capable systems
- What lifecycle management model is required for AI models, prompts, and low-code applications? — - prior completed repository item on re-tiering triggers, promotion states, and retirement controls
- What observability and telemetry model is required to govern AI and low-code systems at scale? — - prior completed repository item on evidence and monitoring depth by control surface
- Business-led low-code agent governance
- Where should governance enforcement points be implemented within enterprise architecture?
- Deployment pipeline as the enforceable control gate for citizen-developed agents
(Full output from running the research skill, retained verbatim in the completed item. Sections 0 to 5 are the investigation, and section 6 seeds the Findings section below.)
- [fact; source: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai; https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-ai-rmf-10; https://handbook.apra.gov.au/ppg/cpg-230] Research question restated: what internal risk-tiering model should an enterprise use for AI and low-code use cases so that informational systems, decision-support systems, and action-capable systems are classified consistently and governed with controls proportionate to their autonomy, impact, and regulatory exposure?
- [fact; source: https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-9; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://handbook.apra.gov.au/standard/cps-230] Scope confirmed: the investigation covers external classification frameworks, internal tier-boundary criteria, control mapping by tier, operability by business analysts, and re-tiering when a use case changes capability or business context.
- [fact; source: https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-ai-rmf-10; https://www.bankofengland.co.uk/prudential-regulation/publication/2022/october/artificial-intelligence; https://www.bis.org/fsi/publ/insights63.htm] Constraint confirmed: the answer must remain practical for enterprise intake, must map to at least one major external framework, and must not assume that financial-services supervisors will accept a vendor-specific or technology-only taxonomy.
- [fact; source: https://davidamitchell.github.io/Research/research/2026-04-24-business-led-low-code-agent-governance.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-governance-enforcement-architecture.html; https://davidamitchell.github.io/Research/research/2026-04-26-deployment-pipeline-citizen-development-governed-gate.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-lifecycle-management.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-observability-telemetry-governance.html] Prior work cross-reference: adjacent completed items already established that low-code value depends on bounded maker enablement, that controls must attach to concrete enforcement points, that action-capable systems need a governed release gate, that promoted artefacts need lifecycle state, and that governance needs attributable telemetry, so this item narrows the problem to the tiering logic that determines when each of those controls becomes mandatory.
- [fact; source: https://www.nist.gov/itl/ai-risk-management-framework/nist-ai-rmf-playbook; https://www.bankofengland.co.uk/prudential-regulation/publication/2022/october/artificial-intelligence] Access note: the seeded NIST Playbook URL
https://airc.nist.gov/Docs/1and the seeded Financial Conduct Authority (FCA) PDF URL returned dead links in this runtime, so the current official NIST and Bank of England pages were used for downstream claims. - Output format: knowledge.
- Root question: What tier model lets an enterprise scale controls for AI and low-code use cases without collapsing into either one-size-fits-all bureaucracy or under-governed autonomy?
-
A. External-framework baseline
- A1. What does the European Union (EU) AI Act classify directly, and what obligations attach to its higher-risk categories?
- A2. What does the NIST Artificial Intelligence Risk Management Framework (AI RMF) say about context, risk tolerance, impact magnitude, and human-AI configuration?
- A3. What does ISO/IEC 42001 add as a management-system baseline?
- A4. What do APRA, the Bank of England, and Basel materials say about proportionality, materiality, and governance in regulated firms?
-
B. Boundary design
- B1. Which criteria best separate informational, decision-support, bounded-action, and autonomous-action systems?
- B2. Which criteria are modifiers rather than primary axes, for example data sensitivity or regulatory trigger points?
- B3. When should a use case be classified as no-go rather than as a higher tier?
-
C. Control mapping
- C1. Which controls should apply to every tier?
- C2. Which controls should appear only once a system can influence a material decision?
- C3. Which controls should appear only once a system can take direct action?
- C4. Which controls should appear only for critical or high-autonomy action?
-
D. Operability
- D1. Can a business analyst classify a use case using a short intake sequence?
- D2. What evidence must be captured so that the classification can be reviewed later?
-
E. Change over time
- E1. What events should force re-tiering?
- E2. Should the enterprise use the highest-triggered tier, or average multiple factors together?
-
- [fact; source: https://www.nist.gov/itl/ai-risk-management-framework/nist-ai-rmf-playbook] Access note: seeded NIST Playbook link replaced with the current official NIST playbook page.
- [fact; source: https://www.bankofengland.co.uk/prudential-regulation/publication/2022/october/artificial-intelligence] Access note: seeded FCA PDF link replaced with the current official Bank of England Discussion Paper 5/22 page.
-
- [fact; source: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai] The European Commission's AI Act overview defines four legal risk groupings, unacceptable risk, high-risk, transparency risk, and minimal or no risk, and reserves strict ex ante obligations for high-risk systems while banning unacceptable practices outright.
- [fact; source: https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-9] Article 9 requires a high-risk system's risk-management process to be continuous across the lifecycle, to consider intended purpose and reasonably foreseeable misuse, and to adopt targeted mitigation measures until residual risk is acceptable.
- [fact; source: https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-14] Article 14 says human-oversight measures must be commensurate with the risks, level of autonomy, and context of use, and that overseers must be able to understand limitations, detect anomalies, override outputs, or halt the system safely.
- [fact; source: https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-26] Article 26 requires deployers of high-risk systems to assign competent human oversight, monitor operation, suspend use when risk emerges, and keep automatically generated logs for at least six months when those logs are under their control.
- [inference; source: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai; https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-9; https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-14; https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-26] The AI Act therefore supplies legal trigger points and mandatory controls for certain categories, but it does not offer a complete internal enterprise taxonomy for routine internal uses such as drafting, summarization, bounded workflow automation, or internal decision support.
- [fact; source: https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-ai-rmf-10] NIST AI RMF 1.0 describes itself as voluntary, rights-preserving, non-sector specific, and use-case agnostic, and states that organizations can operationalize it in varying degrees and capacities.
- [fact; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/] The NIST AI RMF Core says risk management should be continuous across the lifecycle and lists Govern outcomes for risk tolerance, policies, accountability, inventory, ongoing review, and safe decommissioning.
- [fact; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/] The Map outcomes require organizations to document intended purpose, context-specific laws and expectations, organizational risk tolerances, knowledge limits, human oversight processes, targeted application scope, and the likelihood and magnitude of identified impacts.
- [fact; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/] The NIST AI RMF Core also says that after the Map function an organization should have enough contextual knowledge to make an initial go or no-go decision about whether to design, develop, or deploy the system.
- [inference; source: https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-ai-rmf-10; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/] NIST provides the structure for an internal classification model, because it explicitly separates intended purpose, knowledge limits, human-AI configuration, impact magnitude, and risk tolerance, but it leaves the actual tier labels and approval thresholds to the organization.
- [fact; source: https://www.nist.gov/itl/ai-risk-management-framework/nist-ai-rmf-playbook] The NIST AI RMF Playbook says organizations may borrow as many or as few suggestions as apply to their industry use case or interests, which confirms that the framework is intended to be tailored rather than copied as a rigid checklist.
- [fact; source: https://www.iso.org/standard/81230.html] ISO/IEC 42001 is described by ISO as an Artificial Intelligence Management System standard for establishing, implementing, maintaining, and continually improving policies, objectives, and processes for responsible development, provision, or use of AI systems.
- [fact; source: https://www.iso.org/standard/81230.html] ISO's public summary also says the standard addresses risk and opportunity management, traceability, transparency, and reliability across an organization's AI use rather than prescribing detailed tier labels for specific applications.
- [inference; source: https://www.iso.org/standard/81230.html] ISO/IEC 42001 supports the need for consistent intake, documentation, review, and continual improvement, but like NIST it does not remove the need for an enterprise-specific operational tier model.
- [fact; source: https://handbook.apra.gov.au/standard/cps-230] APRA CPS 230 says an entity's operational-risk approach must be appropriate to its size, business mix, and complexity, and requires identification, assessment, and management of operational risk with effective internal controls, monitoring, and remediation.
- [fact; source: https://handbook.apra.gov.au/ppg/cpg-230] APRA CPG 230 says all regulated entities should mature their practices to match the scale of their risks and role in the financial system, and that significant financial institutions should have stronger practices commensurate with the size and complexity of their operations.
- [fact; source: https://handbook.apra.gov.au/ppg/cpg-230] APRA's guidance defines critical operations and material arrangements by whether disruption would have a material adverse impact, which gives a direct enterprise lens for deciding when a use case crosses from ordinary productivity into materially governed operational risk.
- [fact; source: https://www.bankofengland.co.uk/prudential-regulation/publication/2022/october/artificial-intelligence] Discussion Paper 5/22 says AI may amplify existing risks to consumers, firms, market integrity, and financial stability, and frames the regulatory problem as largely one of clarifying how the existing framework applies to AI and where governance or decision-making gaps remain.
- [fact; source: https://www.bis.org/publ/bcbs_nl27.htm] The Basel Committee newsletter says banks seek transparency and interpretability commensurate with the risk of the banking activity being supported and identifies governance, resilience, and data governance as focal concerns for supervisory analysis.
- [fact; source: https://www.bis.org/fsi/publ/insights63.htm] FSI Insights 63 says most financial authorities rely on existing frameworks to address most AI-related risks while expecting stronger governance, expertise, model-risk management, data governance, and third-party oversight where risk is higher.
- [inference; source: https://handbook.apra.gov.au/ppg/cpg-230; https://www.bankofengland.co.uk/prudential-regulation/publication/2022/october/artificial-intelligence; https://www.bis.org/publ/bcbs_nl27.htm; https://www.bis.org/fsi/publ/insights63.htm] Financial-services supervisors therefore support proportionality and materiality as the scaling logic, not a single universal set of controls for every AI or low-code use case.
-
- [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-14; https://handbook.apra.gov.au/ppg/cpg-230] The strongest primary boundary variables are action authority and consequence, because the reviewed sources repeatedly focus on human-AI configuration, oversight, impact magnitude, and materiality rather than on model type or interface style.
- [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-9; https://handbook.apra.gov.au/standard/cps-230] Data sensitivity, legal trigger points, critical-operation dependence, and reversibility are modifier variables that can escalate a use case upward, but they do not by themselves distinguish an informational tool from an action-capable one.
- [inference; source: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai; https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-9; https://handbook.apra.gov.au/standard/cps-230] A separate no-go overlay is needed because some use cases should be refused outright, either because the law prohibits them or because residual risk remains outside organizational tolerance even after mitigation.
- [inference; source: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://www.bis.org/fsi/publ/insights63.htm] The best-fit internal operating model is therefore four positive tiers, informational, decision-support, bounded action, and autonomous or critical action, plus a no-go overlay for prohibited or out-of-appetite uses.
-
- [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai] No-go or prohibited: a use case falls into the no-go overlay when it maps to a prohibited legal category, or when the organization cannot make residual risk acceptable through design, mitigation, oversight, and governance.
- [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-ai-rmf-10; https://davidamitchell.github.io/Research/research/2026-04-24-business-led-low-code-agent-governance.html] Tier 1, informational: the system is read-only in effect, does not directly change enterprise state, does not materially determine customer or employee outcomes, and any error is low-cost and easily reversible through ordinary human work.
- [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-14; https://www.bankofengland.co.uk/prudential-regulation/publication/2022/october/artificial-intelligence] Tier 2, decision-support: the system materially influences human decisions, or operates on sensitive data or important operational contexts, but a competent human remains the legally and operationally effective decision-maker for each consequential outcome.
- [inference; source: https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-14; https://davidamitchell.github.io/Research/research/2026-04-26-deployment-pipeline-citizen-development-governed-gate.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-governance-enforcement-architecture.html] Tier 3, bounded action: the system can write, trigger, publish, or otherwise change enterprise state within a narrow and pre-approved blast radius, and the organization can define scope, rollback, override, and monitoring controls tightly enough to keep residual risk inside tolerance.
- [inference; source: https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-14; https://handbook.apra.gov.au/ppg/cpg-230; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-observability-telemetry-governance.html] Tier 4, autonomous or critical action: the system can take multi-step or cross-system action, affect critical operations or rights-significant outcomes, or create harms that are difficult to reverse quickly, so continuous supervision and formal governance become necessary conditions of deployment.
-
- [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://www.iso.org/standard/81230.html] Every tier should require an owner, an inventory record, an intended-purpose statement, approved data or connector scope, and a periodic review trigger, because even low-risk systems still need accountability and lifecycle discipline.
- [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-observability-telemetry-governance.html] Tier 1 should add basic testing, user transparency, and standard telemetry, but it does not require dedicated risk-committee approval because the system remains read-only in effect and low-cost to reverse.
- [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-14; https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-26] Tier 2 should require documented limitations, human-review assignment, evidence logging, and periodic validation against observed outcomes, because the core risk is automation bias or over-reliance rather than direct machine execution.
- [inference; source: https://davidamitchell.github.io/Research/research/2026-04-26-deployment-pipeline-citizen-development-governed-gate.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-governance-enforcement-architecture.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-lifecycle-management.html] Tier 3 should require a deployment gate, segregated environments, least-privilege machine identity, rollback mechanics, and action-level telemetry, because once a system can change enterprise state, design-time review alone is not an enforceable control.
- [inference; source: https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-9; https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-14; https://handbook.apra.gov.au/ppg/cpg-230; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-observability-telemetry-governance.html] Tier 4 should require formal approval by accountable business, technology, and risk leaders, independent validation, staged rollout, continuous monitoring, safe-halt capability, and more frequent recertification, because its failure modes approach critical operational-risk territory.
-
- [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://www.nist.gov/itl/ai-risk-management-framework/nist-ai-rmf-playbook] A business analyst can apply the tier model if intake begins with a short sequence of factual questions, what the system can do, what it can affect, which data it uses, who can override it, and how reversible errors are, because those are the same contextual fields NIST requires organizations to document.
- [inference; source: https://handbook.apra.gov.au/ppg/cpg-230; https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai] The classification process should use highest-triggered-tier logic rather than averaging answers, because APRA-style materiality and AI Act trigger points are threshold concepts and are weakened if a single severe dimension can be diluted by several benign ones.
-
- [fact; source: https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-9; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/] Both the AI Act and NIST AI RMF treat risk assessment as continuous across the lifecycle rather than as a one-time approval event.
- [fact; source: https://handbook.apra.gov.au/ppg/cpg-230] APRA's guidance says boards should understand material operational risks that arise from new ventures and that entities should update practices as operations grow and evolve.
- [inference; source: https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-9; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://handbook.apra.gov.au/ppg/cpg-230; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-lifecycle-management.html] Re-tiering should therefore be mandatory whenever intended purpose, action authority, user population, integrated systems, data sensitivity, or dependency on a critical operation changes, because those changes alter the system's context, impact, and residual risk even if the user interface still looks similar.
- [fact; source: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://handbook.apra.gov.au/ppg/cpg-230] The reviewed sources agree on proportionality, documentation, human oversight, and monitoring as core governance ideas.
- [inference; source: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/] The main design gap is that none of the reviewed frameworks gives a fully usable internal taxonomy for everyday enterprise-internal use cases that sit below formal legal high-risk thresholds but above harmless drafting.
- [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-14; https://handbook.apra.gov.au/ppg/cpg-230] Action authority and consequence are the best primary axes because they recur across human oversight, impact magnitude, and operational materiality.
- [inference; source: https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-9; https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai] Legal trigger points should operate as overlays that can escalate a use case to no-go or to the highest control band without forcing the enterprise to force every internal use case into a statutory label.
- [inference; source: https://davidamitchell.github.io/Research/research/2026-04-26-deployment-pipeline-citizen-development-governed-gate.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-observability-telemetry-governance.html] The control map must change sharply once a system can act, because deployment gating, rollback, and action telemetry become mandatory only after the system can alter enterprise state.
- [fact; source: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://handbook.apra.gov.au/ppg/cpg-230] No reviewed official source argued for identical controls across all AI and low-code use cases.
- [inference; source: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/] The main conceptual tension is that the AI Act uses legal categories while NIST uses contextual risk-management categories, and that tension is resolved by treating the AI Act as a legal overlay and NIST as the operational design scaffold.
- [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://handbook.apra.gov.au/ppg/cpg-230] A borderline system that only recommends but materially shapes credit, fraud, workforce, or critical-operation decisions belongs in Tier 2 or higher, because consequence can be high even when the machine does not directly execute the final action.
- [fact; source: https://www.iso.org/standard/81230.html] The public ISO page confirms management-system principles but does not expose the full normative text, so the synthesis limits ISO-based claims to its published summary.
- [inference; source: https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-governance-enforcement-architecture.html; https://davidamitchell.github.io/Research/research/2026-04-26-deployment-pipeline-citizen-development-governed-gate.html] Technical lens: the largest control jump occurs at the moment a system gains direct write or trigger capability, because that is where approval, least privilege, release gating, and rollback move from optional hygiene to enforceable safety mechanisms.
- [inference; source: https://handbook.apra.gov.au/standard/cps-230; https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-26; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-regulatory-compliance-alignment.html] Regulatory lens: financial-services supervision cares less about whether a system is marketed as an assistant or an agent than about whether it affects material operations, requires accountable oversight, and generates retrievable evidence.
- [inference; source: https://davidamitchell.github.io/Research/research/2026-04-24-business-led-low-code-agent-governance.html; https://davidamitchell.github.io/Research/research/2026-04-26-systems-capability-debt-agentic-ai-risk-synthesis.html] Economic and organizational lens: forcing all use cases into the highest control band would increase friction and likely push demand into shadow tooling, which means proportionality is not only efficient but also control-preserving.
- [inference; source: https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-14; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/] Behavioral lens: nominal human involvement is not enough to keep a system in a lower tier, because oversight only counts when the reviewer can understand limitations, detect anomalies, and truly override the output.
- [inference; source: https://www.bankofengland.co.uk/prudential-regulation/publication/2022/october/artificial-intelligence; https://www.bis.org/fsi/publ/insights63.htm] Historical lens: supervisors are still mostly adapting existing governance frameworks rather than creating entirely new AI-only control stacks, which makes an internal proportional tier model more durable than a platform-specific checklist.
(This section seeds the Findings below.)
Executive summary:
- [inference; source: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://handbook.apra.gov.au/ppg/cpg-230] The most workable enterprise classification for AI and low-code use cases is a four-tier operating model, informational, decision-support, bounded action, and autonomous or critical action, with a separate no-go overlay for prohibited or out-of-appetite uses, because the reviewed frameworks all scale controls by impact, autonomy, and context rather than by one universal rule set.
- [inference; source: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai; https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-9; https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-14; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/] The AI Act supplies legal trigger points for prohibited and high-risk cases, but it does not provide a complete internal taxonomy for routine enterprise-internal use cases, so firms need an internal tier model that maps to those trigger points rather than copying its labels verbatim.
- [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-14; https://handbook.apra.gov.au/standard/cps-230] The decisive boundary questions are whether the system can take direct action, whether it affects critical operations or rights-significant outcomes, whether humans can competently override it, and whether errors are reversible at low cost.
- [inference; source: https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-9; https://davidamitchell.github.io/Research/research/2026-04-26-deployment-pipeline-citizen-development-governed-gate.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-observability-telemetry-governance.html] Governance should therefore escalate from registration and standard controls at Tier 1 to documented human review at Tier 2, deployment gating and least-privilege machine authority at Tier 3, and formal approval, continuous monitoring, and safe-halt design at Tier 4.
Key findings:
- High confidence. [inference; source: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://handbook.apra.gov.au/ppg/cpg-230] No reviewed framework provides a ready-made internal enterprise taxonomy for every AI and low-code use case, so regulated firms need an internal operating tier model that adapts legal and risk-management principles into day-to-day intake decisions.
- High confidence. [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-14; https://handbook.apra.gov.au/ppg/cpg-230] The best primary classifier is the combination of action authority and consequence, because the strongest reviewed signals are autonomy, human oversight, impact magnitude, and operational materiality rather than vendor, interface, or model type.
- High confidence. [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-ai-rmf-10; https://davidamitchell.github.io/Research/research/2026-04-24-business-led-low-code-agent-governance.html] Informational systems should remain in the lowest positive tier only when they are effectively read-only, do not materially shape consequential decisions, and produce errors that ordinary human work can detect and reverse cheaply.
- High confidence. [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-14; https://www.bankofengland.co.uk/prudential-regulation/publication/2022/october/artificial-intelligence] Decision-support systems enter a higher tier as soon as they materially influence credit, workforce, fraud, or critical-operation judgments, because effective human review and limitation documentation then become control necessities rather than optional good practice.
- Medium confidence. [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-14; https://davidamitchell.github.io/Research/research/2026-04-26-deployment-pipeline-citizen-development-governed-gate.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-governance-enforcement-architecture.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-lifecycle-management.html] Bounded-action systems deserve a distinct tier because once a system can write, trigger, publish, or modify records inside a pre-approved scope, oversight logic from NIST and the AI Act combines with prior completed architecture work to make deployment gates, least privilege, rollback, and action telemetry the minimum credible controls.
- High confidence. [inference; source: https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-9; https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-14; https://handbook.apra.gov.au/ppg/cpg-230; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-observability-telemetry-governance.html] Autonomous or critical-action systems require the highest positive tier, because multi-step action against critical operations or rights-significant outcomes demands formal approval, independent validation, continuous monitoring, and safe-stop capability.
- High confidence. [inference; source: https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-9; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://handbook.apra.gov.au/ppg/cpg-230; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-lifecycle-management.html] Tier assignment cannot be a one-time event, because changes in intended purpose, autonomy, connected systems, data sensitivity, or business criticality alter context and residual risk even when the interface remains unchanged.
- Medium confidence. [inference; source: https://davidamitchell.github.io/Research/research/2026-04-24-business-led-low-code-agent-governance.html; https://davidamitchell.github.io/Research/research/2026-04-26-systems-capability-debt-agentic-ai-risk-synthesis.html; https://handbook.apra.gov.au/ppg/cpg-230] Over-classifying every use case as high risk would likely increase friction and shadow tooling, so a proportional model is not merely efficient but also more likely to preserve real governance coverage across the estate.
Evidence map:
Assumptions:
- [assumption; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://www.nist.gov/itl/ai-risk-management-framework/nist-ai-rmf-playbook] The specific tier labels, informational, decision-support, bounded action, and autonomous or critical action, are enterprise design choices rather than mandated external terms. Justification: the reviewed frameworks provide principles and trigger criteria but do not prescribe one canonical internal label set for all enterprise use cases.
- [assumption; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://handbook.apra.gov.au/ppg/cpg-230] A business analyst can apply the model reliably if the intake process forces explicit answers about action authority, impact, data sensitivity, overrideability, and reversibility. Justification: the frameworks require those facts to be documented, but they do not prove that every organization's intake form will capture them cleanly without local design work.
Analysis:
- [inference; source: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://handbook.apra.gov.au/ppg/cpg-230] The synthesis weights NIST most heavily for internal classification mechanics, because NIST explicitly decomposes context, risk tolerance, human oversight, impact magnitude, and go or no-go decisions, while the AI Act and APRA provide stronger legal and prudential escalation triggers.
- [inference; source: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai; https://www.bis.org/fsi/publ/insights63.htm; https://www.bankofengland.co.uk/prudential-regulation/publication/2022/october/artificial-intelligence] The AI Act is treated as a mandatory overlay rather than as the whole taxonomy, because its legal classes are essential for prohibited and high-risk cases but are too coarse for routine internal enterprise uses that still need differentiated controls.
- [inference; source: https://davidamitchell.github.io/Research/research/2026-04-26-deployment-pipeline-citizen-development-governed-gate.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-governance-enforcement-architecture.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-observability-telemetry-governance.html] The sharpest control boundary is the transition from influence to execution, because that is the point where release controls, least-privilege machine authority, rollback, and action telemetry become the only credible ways to constrain harm.
- [inference; source: https://davidamitchell.github.io/Research/research/2026-04-24-business-led-low-code-agent-governance.html; https://davidamitchell.github.io/Research/research/2026-04-26-systems-capability-debt-agentic-ai-risk-synthesis.html] The model also balances control against adoption reality, because an enterprise that assigns every use case to the highest tier is likely to recreate the shadow-tooling dynamics that previous completed items identified as a governance failure mode.
- [inference; source: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai; https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-9; https://handbook.apra.gov.au/ppg/cpg-230] Tier 0, no-go: reject any use case that falls into a prohibited legal category or still sits outside risk appetite after mitigation and oversight design.
- [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-ai-rmf-10; https://davidamitchell.github.io/Research/research/2026-04-24-business-led-low-code-agent-governance.html] Tier 1, informational: allow use cases that are read-only in effect, low consequence, and easily reversible under standard ownership, inventory, approved data scope, basic testing, transparency, and standard telemetry controls.
- [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-14; https://www.bankofengland.co.uk/prudential-regulation/publication/2022/october/artificial-intelligence] Tier 2, decision-support: require documented limitations, an assigned human reviewer, evidence logging, and periodic validation once outputs materially shape consequential human decisions.
- [inference; source: https://davidamitchell.github.io/Research/research/2026-04-26-deployment-pipeline-citizen-development-governed-gate.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-governance-enforcement-architecture.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-lifecycle-management.html] Tier 3, bounded action: require a deployment gate, segregated environments, least privilege, rollback, and action-level telemetry once a system can change state inside a pre-approved blast radius.
- [inference; source: https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-9; https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-14; https://handbook.apra.gov.au/ppg/cpg-230; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-observability-telemetry-governance.html] Tier 4, autonomous or critical action: require formal approval, independent validation, staged rollout, continuous monitoring, and safe-halt capability for multi-step or high-impact action.
Risks, gaps, uncertainties:
- [fact; source: https://www.iso.org/standard/81230.html] The full normative text of ISO/IEC 42001 was not accessible in this session, so ISO-backed claims are limited to the official public summary rather than clause-level interpretation.
- [fact; source: https://www.bankofengland.co.uk/prudential-regulation/publication/2022/october/artificial-intelligence; https://www.bis.org/fsi/publ/insights63.htm] UK and Basel supervisory materials support proportionality and governance scaling, but they provide less detailed tier-boundary language than the AI Act or the NIST AI RMF Core.
- [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-governance-enforcement-architecture.html] Borderline cases between Tier 2 and Tier 3 will usually turn on whether a system merely recommends an action or can actually commit, publish, trigger, or write that action into an enterprise system.
- [fact; source: https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-26; https://handbook.apra.gov.au/ppg/cpg-230] None of the reviewed official sources specifies universal numeric approval thresholds, review cadences, or sample sizes by tier, so those thresholds still need local policy design.
Open questions:
- [inference; source: https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-14; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/] What evidence should count as proof that human oversight is genuinely effective rather than nominal for Tier 2 and Tier 4 systems?
- [inference; source: https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-observability-telemetry-governance.html; https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-26] What minimum telemetry set is sufficient to prove that a system has stayed within its approved tier in production rather than drifting into a higher-risk operating pattern?
- [inference; source: https://davidamitchell.github.io/Research/research/2026-04-26-deployment-pipeline-citizen-development-governed-gate.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-lifecycle-management.html] Which promotion and re-certification cadence should attach to Tier 3 and Tier 4 systems once the enterprise converts the tier model into an operating procedure?
- [inference; source: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://handbook.apra.gov.au/ppg/cpg-230] Recursive review did not surface evidence that would overturn the proportional four-tier model with a no-go overlay, and the remaining uncertainty concerns local approval thresholds rather than the tier structure itself.
(Populated from §6 Synthesis above.)
- [inference; source: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://handbook.apra.gov.au/ppg/cpg-230] The most workable enterprise classification for AI and low-code use cases is a four-tier operating model, informational, decision-support, bounded action, and autonomous or critical action, with a separate no-go overlay for prohibited or out-of-appetite uses, because the reviewed frameworks all scale controls by impact, autonomy, and context rather than by one universal rule set.
- [inference; source: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai; https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-9; https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-14; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/] The AI Act supplies legal trigger points for prohibited and high-risk cases, but it does not provide a complete internal taxonomy for routine enterprise-internal use cases, so firms need an internal tier model that maps to those trigger points rather than copying its labels verbatim.
- [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-14; https://handbook.apra.gov.au/standard/cps-230] The decisive boundary questions are whether the system can take direct action, whether it affects critical operations or rights-significant outcomes, whether humans can competently override it, and whether errors are reversible at low cost.
- [inference; source: https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-9; https://davidamitchell.github.io/Research/research/2026-04-26-deployment-pipeline-citizen-development-governed-gate.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-observability-telemetry-governance.html] Governance should therefore escalate from registration and standard controls at Tier 1 to documented human review at Tier 2, deployment gating and least-privilege machine authority at Tier 3, and formal approval, continuous monitoring, and safe-halt design at Tier 4.
- High confidence. [inference; source: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://handbook.apra.gov.au/ppg/cpg-230] No reviewed framework provides a ready-made internal enterprise taxonomy for every AI and low-code use case, so regulated firms need an internal operating tier model that adapts legal and risk-management principles into day-to-day intake decisions.
- High confidence. [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-14; https://handbook.apra.gov.au/ppg/cpg-230] The best primary classifier is the combination of action authority and consequence, because the strongest reviewed signals are autonomy, human oversight, impact magnitude, and operational materiality rather than vendor, interface, or model type.
- High confidence. [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-ai-rmf-10; https://davidamitchell.github.io/Research/research/2026-04-24-business-led-low-code-agent-governance.html] Informational systems should remain in the lowest positive tier only when they are effectively read-only, do not materially shape consequential decisions, and produce errors that ordinary human work can detect and reverse cheaply.
- High confidence. [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-14; https://www.bankofengland.co.uk/prudential-regulation/publication/2022/october/artificial-intelligence] Decision-support systems enter a higher tier as soon as they materially influence credit, workforce, fraud, or critical-operation judgments, because effective human review and limitation documentation then become control necessities rather than optional good practice.
- Medium confidence. [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-14; https://davidamitchell.github.io/Research/research/2026-04-26-deployment-pipeline-citizen-development-governed-gate.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-governance-enforcement-architecture.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-lifecycle-management.html] Bounded-action systems deserve a distinct tier because once a system can write, trigger, publish, or modify records inside a pre-approved scope, oversight logic from NIST and the AI Act combines with prior completed architecture work to make deployment gates, least privilege, rollback, and action telemetry the minimum credible controls.
- High confidence. [inference; source: https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-9; https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-14; https://handbook.apra.gov.au/ppg/cpg-230; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-observability-telemetry-governance.html] Autonomous or critical-action systems require the highest positive tier, because multi-step action against critical operations or rights-significant outcomes demands formal approval, independent validation, continuous monitoring, and safe-stop capability.
- High confidence. [inference; source: https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-9; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://handbook.apra.gov.au/ppg/cpg-230; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-lifecycle-management.html] Tier assignment cannot be a one-time event, because changes in intended purpose, autonomy, connected systems, data sensitivity, or business criticality alter context and residual risk even when the interface remains unchanged.
- Medium confidence. [inference; source: https://davidamitchell.github.io/Research/research/2026-04-24-business-led-low-code-agent-governance.html; https://davidamitchell.github.io/Research/research/2026-04-26-systems-capability-debt-agentic-ai-risk-synthesis.html; https://handbook.apra.gov.au/ppg/cpg-230] Over-classifying every use case as high risk would likely increase friction and shadow tooling, so a proportional model is not merely efficient but also more likely to preserve real governance coverage across the estate.
- [assumption; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://www.nist.gov/itl/ai-risk-management-framework/nist-ai-rmf-playbook] Assumption: The specific tier labels, informational, decision-support, bounded action, and autonomous or critical action, are enterprise design choices rather than mandated external terms. Justification: the reviewed frameworks provide principles and trigger criteria but do not prescribe one canonical internal label set for all enterprise use cases.
- [assumption; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://handbook.apra.gov.au/ppg/cpg-230] Assumption: A business analyst can apply the model reliably if the intake process forces explicit answers about action authority, impact, data sensitivity, overrideability, and reversibility. Justification: the frameworks require those facts to be documented, but they do not prove that every organization's intake form will capture them cleanly without local design work.
- [inference; source: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://handbook.apra.gov.au/ppg/cpg-230] The synthesis weights NIST most heavily for internal classification mechanics, because NIST explicitly decomposes context, risk tolerance, human oversight, impact magnitude, and go or no-go decisions, while the AI Act and APRA provide stronger legal and prudential escalation triggers.
- [inference; source: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai; https://www.bis.org/fsi/publ/insights63.htm; https://www.bankofengland.co.uk/prudential-regulation/publication/2022/october/artificial-intelligence] The AI Act is treated as a mandatory overlay rather than as the whole taxonomy, because its legal classes are essential for prohibited and high-risk cases but are too coarse for routine internal enterprise uses that still need differentiated controls.
- [inference; source: https://davidamitchell.github.io/Research/research/2026-04-26-deployment-pipeline-citizen-development-governed-gate.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-governance-enforcement-architecture.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-observability-telemetry-governance.html] The sharpest control boundary is the transition from influence to execution, because that is the point where release controls, least-privilege machine authority, rollback, and action telemetry become the only credible ways to constrain harm.
- [inference; source: https://davidamitchell.github.io/Research/research/2026-04-24-business-led-low-code-agent-governance.html; https://davidamitchell.github.io/Research/research/2026-04-26-systems-capability-debt-agentic-ai-risk-synthesis.html] The model also balances control against adoption reality, because an enterprise that assigns every use case to the highest tier is likely to recreate the shadow-tooling dynamics that previous completed items identified as a governance failure mode.
- [inference; source: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai; https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-9; https://handbook.apra.gov.au/ppg/cpg-230] Tier 0, no-go: reject any use case that falls into a prohibited legal category or still sits outside risk appetite after mitigation and oversight design.
- [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-ai-rmf-10; https://davidamitchell.github.io/Research/research/2026-04-24-business-led-low-code-agent-governance.html] Tier 1, informational: allow use cases that are read-only in effect, low consequence, and easily reversible under standard ownership, inventory, approved data scope, basic testing, transparency, and standard telemetry controls.
- [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-14; https://www.bankofengland.co.uk/prudential-regulation/publication/2022/october/artificial-intelligence] Tier 2, decision-support: require documented limitations, an assigned human reviewer, evidence logging, and periodic validation once outputs materially shape consequential human decisions.
- [inference; source: https://davidamitchell.github.io/Research/research/2026-04-26-deployment-pipeline-citizen-development-governed-gate.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-governance-enforcement-architecture.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-lifecycle-management.html] Tier 3, bounded action: require a deployment gate, segregated environments, least privilege, rollback, and action-level telemetry once a system can change state inside a pre-approved blast radius.
- [inference; source: https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-9; https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-14; https://handbook.apra.gov.au/ppg/cpg-230; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-observability-telemetry-governance.html] Tier 4, autonomous or critical action: require formal approval, independent validation, staged rollout, continuous monitoring, and safe-halt capability for multi-step or high-impact action.
- [fact; source: https://www.iso.org/standard/81230.html] The full normative text of ISO/IEC 42001 was not accessible in this session, so ISO-backed claims are limited to the official public summary rather than clause-level interpretation.
- [fact; source: https://www.bankofengland.co.uk/prudential-regulation/publication/2022/october/artificial-intelligence; https://www.bis.org/fsi/publ/insights63.htm] UK and Basel supervisory materials support proportionality and governance scaling, but they provide less detailed tier-boundary language than the AI Act or the NIST AI RMF Core.
- [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-governance-enforcement-architecture.html] Borderline cases between Tier 2 and Tier 3 will usually turn on whether a system merely recommends an action or can actually commit, publish, trigger, or write that action into an enterprise system.
- [fact; source: https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-26; https://handbook.apra.gov.au/ppg/cpg-230] None of the reviewed official sources specifies universal numeric approval thresholds, review cadences, or sample sizes by tier, so those thresholds still need local policy design.
- [inference; source: https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-14; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/] What evidence should count as proof that human oversight is genuinely effective rather than nominal for Tier 2 and Tier 4 systems?
- [inference; source: https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-observability-telemetry-governance.html; https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-26] What minimum telemetry set is sufficient to prove that a system has stayed within its approved tier in production rather than drifting into a higher-risk operating pattern?
- [inference; source: https://davidamitchell.github.io/Research/research/2026-04-26-deployment-pipeline-citizen-development-governed-gate.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-lifecycle-management.html] Which promotion and re-certification cadence should attach to Tier 3 and Tier 4 systems once the enterprise converts the tier model into an operating procedure?
(Fill in when completing, what was produced as a result of this research?)
- Type: knowledge
- Description: Enterprise risk-tier model for AI and low-code use cases, with a no-go overlay, explicit tier boundaries, and proportional control expectations for informational, decision-support, bounded-action, and autonomous or critical-action systems.
- Links:
- https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai
- https://airc.nist.gov/airmf-resources/airmf/5-sec-core/
- https://handbook.apra.gov.au/ppg/cpg-230
Navigation
By Tag
bureaucracy
change-management
coase
constraint-analysis
control-model
decision-rights
delegation
- Q4: Decision rights that should move closer to execution
- Q5: Control model for the best throughput-risk trade-off
delivery-risk
- Operating model synthesis for split-authority delivery systems
- Q6: Leading indicators of instability in split-authority flow systems
demand-segmentation
enterprise
exception-handling
execution
flow
flow-design
flow-metrics
governance
- Operating model synthesis for split-authority delivery systems
- Q1: Dominant flow constraint in split-authority delivery systems
- Q2: Demand segmentation for fast-path vs controlled-path flow
- Q4: Decision rights that should move closer to execution
- Conditions under which internal governance controls minimise coordination costs in regulated enterprises
- Failure mechanisms of internal governance controls: bureaucratic inefficiency and informal circumvention in regulated enterprises
- Barriers to governance reform, leadership failure modes, and reform mechanisms in regulated enterprises
governance-patterns
incentives
- Failure mechanisms of internal governance controls: bureaucratic inefficiency and informal circumvention in regulated enterprises
- Barriers to governance reform, leadership failure modes, and reform mechanisms in regulated enterprises
instability
institutional-economics
- Conditions under which internal governance controls minimise coordination costs in regulated enterprises
- Failure mechanisms of internal governance controls: bureaucratic inefficiency and informal circumvention in regulated enterprises
- Barriers to governance reform, leadership failure modes, and reform mechanisms in regulated enterprises
leading-indicators
operating-model
organisation
- Conditions under which internal governance controls minimise coordination costs in regulated enterprises
- Failure mechanisms of internal governance controls: bureaucratic inefficiency and informal circumvention in regulated enterprises
- Barriers to governance reform, leadership failure modes, and reform mechanisms in regulated enterprises
organisational-design
queue-design
queueing
regulated-enterprise
- Conditions under which internal governance controls minimise coordination costs in regulated enterprises
- Failure mechanisms of internal governance controls: bureaucratic inefficiency and informal circumvention in regulated enterprises
- Barriers to governance reform, leadership failure modes, and reform mechanisms in regulated enterprises
routing
throughput
throughput-risk
transaction-costs
- Conditions under which internal governance controls minimise coordination costs in regulated enterprises
- Failure mechanisms of internal governance controls: bureaucratic inefficiency and informal circumvention in regulated enterprises
triage
- Q2: Demand segmentation for fast-path vs controlled-path flow
- Q3: Routing design that isolates exceptions from routine flow
williamson