FL Fredrik Lindstrom


The "levels of AI" chart fills its tiers with demos. Speech recognition. Chatbots. Spotting a defect on a production line. None of those is the reason a regulator will ever call. The decisions that carry exposure are the dull ones: who gets credit, who gets shortlisted, who gets triaged first.

Regulatory exposure tracks the consequence of the decision, not the sophistication of the technique. A rules engine that determines benefits eligibility carries more weight than a transformer that summarises a meeting. And the column that keeps getting left off these charts is the one that matters most on the day something goes wrong: can you undo it.

This is not a maturity scale. Organisations run all six at once and add more of them as they mature. Nobody graduates off tier 1.

Six AI capability tiers with what each one decides, its EU AI Act exposure and whether the decision can be undone. Tiers one to four are techniques — rules and logic, classical machine learning, deep learning, generative AI. Tiers five and six, workflows and agentic systems, are architectures that wrap any tier above rather than further rungs.
Download the chart PDF, one page, 11.3 × 14.1 in, 203 KB. Text is selectable and prints for board packs.

The six tiers

Tiers 1 to 4 are a technique axis. Tiers 5 and 6 are an architecture axis — they wrap any tier above rather than continuing the ladder.

AI capability tiers with what each decides, EU AI Act exposure and reversibility
Tier / What it decides EU AI Act exposure Can you undo it?
1 Rules & logic Benefits eligibility · Sanctions screening · Overdraft limits Often falls outside the Act's definition of an AI system Yes Read the rule
2 Classical ML Credit scoring · Insurance pricing · Fraud detection Annex III high-risk. Fraud detection is carved out Partly Weights inspectable
3 Deep learning CV screening · Imaging triage · Defect rejection Annex III, or Annex I where embedded in a device Hard No readable reason
4 Generative AI Claim summaries · Candidate shortlists · Draft denials Art. 50 transparency, plus Annex III if it decides Hard Fluent either way
Architecture — wraps any tier above
5 Workflows Routes the claim · Chains score-then-check · Escalates exceptions Where Art. 14 human oversight can actually be designed in By design You wrote the path
6 Agentic Sends the denial · Closes the ticket · Moves the money Inherits the classification of the action it takes No It chose the path

Simplest to build is not lightest to govern.

Post-Omnibus timing: Annex III stand-alone high-risk from 2 Dec 2027 · embedded and safety-component from 2 Aug 2028 · Art. 50 from 2 Dec 2026.


Where to go next

The tier 5 / tier 6 boundary is the one that changes who is accountable, and it is the same distinction drawn in the corrected AI taxonomy — where workflows and agents sit outside the containment nesting rather than inside it.

Cyber terms for the boardroom does the same job for cybersecurity — thirteen terms defined for oversight, each with the question to put to management.

The Governance Memo carries this work monthly for boards and CISOs — one breach post-mortem and two or three governance items.