Understanding AI System Classification and Risk Assessment in AI Governance

André Buser
5 min readJul 9, 2024

In the evolving field of artificial intelligence (AI) governance, two important concepts can get mixed up: AI System Classification and AI System Risk Assessment. This confusion can lead to problems in managing the related AI risks. This article aims to explain these concepts and how they relate to each other, using insights from major AI governance frameworks.

Why the Confusion?

People can mix up AI system classification and risk assessment because both deal with understanding AI system impacts. However, they serve different purposes and happen at different times in the governance process.

AI System Classification: The First Step

AI system classification comes first in the governance process. It involves putting AI systems into categories based on set criteria, related to the system’s purpose, how it’s used, and its potential impact.

Main Features of AI System Classification

Different Approaches to Classification

  1. EU AI Act: Groups AI systems into risk levels like prohibited, high-risk, limited-risk, and minimal-risk.
  2. OECD AI System Classification

--

--

André Buser

IS Auditor & Data Scientist: 14 yrs exp. Helps manage tech/data risks. Focus: Responsible AI & Data Ethics in GRC. Bridges innovation and governance in AI.