Risk-Proportional Governance

Three-Tier AI Impact Classification

Not all AI applications carry the same risk. Governance resources should be allocated proportionally — fast-tracking routine uses while ensuring high-impact decisions receive robust oversight.

The strongest governance frameworks already reflect this logic. The EU AI Act differentiates obligations by risk. NIST AI RMF encourages context-specific governance. OECD principles point toward proportionate oversight rather than one-size-fits-all controls.

Tier 1
Routine Automation
Lightweight
Characteristics
AI that automates internal administrative tasks with no direct citizen or customer impact.
Document summarization Scheduling optimization Data entry automation
Governance Approach
Department-level approval, standard data quality checks, periodic review.
Efficiency & Service Data Quality
Tier 2
Decision Support
Moderate
Characteristics
AI that informs human decisions affecting citizens, customers, or resource allocation.
Workload prioritization Permit review support Trend analysis
Governance Approach
Documented human-in-the-loop requirements, transparency about AI's role, data privacy impact review.
Data Privacy & Security Human Decision-Making Transparency
Tier 3
High-Impact Decisions
Robust
Characteristics
AI that directly affects citizen or customer outcomes, rights, or access to services.
Eligibility determinations Risk assessments Automated decision comms
Governance Approach
Human oversight at the decision point, transparency to affected citizens, data quality validation, and a mechanism for concerns about automated decisions.
All Five Governance Pillars Apply
Low impact
High impact

Why this matters: When Tier 1 use cases can move quickly under lightweight controls, teams are less likely to bypass governance altogether. That is one of the most effective ways to reduce shadow AI. Governance becomes something people work within — not something they route around.

Provenance: Developed through global comparative governance research at the Center for AI and Digital Policy (CAIDP). Part of the MPBP Framework for operationalizing AI governance.