Module 3 · 8 min read

Tiering by Impact, and the Shape of Risk-Tiered Regulation

Classifying AI by the consequence of failure rather than by technical scale, and the conceptual structure that risk-tiered regulation and transparency duties share.

Tiering is where governance either earns its keep or becomes a tax. No firm can apply its most expensive controls to every system that contains a model, so the tier decides where independent validation, continuous monitoring and formal oversight actually go. Get tiering wrong and you spend the budget in the wrong place, which is worse than spending nothing, because it produces the appearance of rigour.

Take two systems. The first is a very large general-purpose language model that drafts summaries of internal meetings. The second is a small gradient-boosted tree that screens rental applications. Instinct pulls towards the first: it is bigger, more sophisticated, harder to predict, and generates open-ended text. That instinct is wrong. A bad meeting summary is an internal inconvenience that a participant will notice and correct. A bad screening decision changes whether a person gets somewhere to live, is rarely visible to the person affected, and is difficult for them to contest. The screening model belongs in the higher tier.

The dimensions that actually drive a tier

  • Consequentiality. Does the output bear on access to employment, housing, credit, insurance, education, healthcare, essential services, benefits or liberty? These domains carry the heaviest weight in every framework worth following.
  • Reversibility. Can a wrong outcome be identified and undone, and at what cost to the person? An irreversible or slowly reversible harm justifies a higher tier at the same error rate.
  • Autonomy. Advisory output that a competent human evaluates sits lower than output that is acted on automatically, and lower again than a system that takes actions in the world through tools.
  • Population and vulnerability. Systems acting on children, patients, applicants, claimants or people in a position of dependence carry more risk than systems acting on informed professionals inside the firm.
  • Scale and repetition. A small bias applied to millions of decisions is a larger harm than a large error applied twice.
  • Contestability and transparency. Can the affected person know a model was involved, understand roughly why, and challenge the outcome? Low contestability raises the tier.
  • Data sensitivity and operating environment. Special category data, safety-relevant physical environments and security-critical contexts each push upwards.

Check yourself

A hospital runs two AI systems. The first drafts discharge summaries that a clinician reads and edits before anything is filed. The second automatically closes low-value insurance claims below a threshold, with no review unless the patient complains. Which belongs in the higher tier?

The conceptual shape of risk-tiered regulation

Regulators have converged on broadly the same logic, and the durable knowledge is the shape rather than any particular text. The most developed regimes are risk-tiered rather than uniform. At the top sits a small set of practices considered unacceptable and prohibited outright. Below that sits a defined set of high-risk uses, typically identified by application domain and by whether the system is a safety component of a regulated product, carrying substantial obligations across the whole lifecycle. Below that sits a band of systems that carry transparency duties because of how they interact with people, whatever their other risk. Everything else is largely left alone.

For the high-risk band the obligations are recognisable to anyone who has run a regulated change process: a documented risk management process maintained across the lifecycle, data governance and data quality expectations, technical documentation, logging and record keeping sufficient to trace decisions, information supplied to those who deploy the system, human oversight designed in rather than asserted, and standards of accuracy, robustness and security appropriate to the purpose. A conformity or assessment step typically precedes placing the system on the market, and post-market monitoring plus serious incident reporting follow it.

A further layer, still settling, addresses broadly capable general-purpose models directly: documentation and information duties owed to downstream integrators, with additional expectations above some capability or systemic-impact threshold. This sits alongside use-based tiering rather than replacing it, so a firm can simultaneously be a deployer of a high-risk application and a downstream integrator of a general-purpose model.

The bands, and who owes what

Select a card to turn it over.

Try it first

A firm headquartered well outside the jurisdiction argues that a risk-tiered AI regime cannot apply to it. Why is that usually wrong?

Transparency and disclosure duties

Transparency obligations are the part of the landscape that most often applies to systems a firm considers low risk. Two duties recur. First, people should be told when they are interacting with an AI system, where that would not otherwise be obvious. Second, synthetic media should be identifiable as generated. So a retailer running a chat agent that convincingly passes as a human adviser, and separately publishing AI-generated product imagery, attracts both.

Two failure patterns are worth naming, because both feel like compliance. Burying the disclosure in the website terms of service defeats the purpose of the duty, which is to inform the person during the interaction, at the moment it matters to them. Disclosing only when a customer directly asks whether they are talking to a machine inverts the duty entirely: the obligation does not wait to be triggered. Note also that transparency to affected individuals is a different duty from technical documentation supplied to a regulator and from information supplied to downstream deployers. Satisfying one does not discharge the others.