Resource
What each AI tier actually decides
The "levels of AI" chart fills its tiers with demos. Speech recognition. Chatbots. Spotting a defect on a production line. None of those is the reason a regulator will ever call. The decisions that carry exposure are the dull ones: who gets credit, who gets shortlisted, who gets triaged first.
Regulatory exposure tracks the consequence of the decision, not the sophistication of the technique. A rules engine that determines benefits eligibility carries more weight than a transformer that summarises a meeting. And the column that keeps getting left off these charts is the one that matters most on the day something goes wrong: can you undo it.
This is not a maturity scale. Organisations run all six at once and add more of them as they mature. Nobody graduates off tier 1.
The six tiers
Tiers 1 to 4 are a technique axis. Tiers 5 and 6 are an architecture axis — they wrap any tier above rather than continuing the ladder.
| Tier / What it decides | EU AI Act exposure | Can you undo it? |
|---|---|---|
| 1 Rules & logic Benefits eligibility · Sanctions screening · Overdraft limits | Often falls outside the Act's definition of an AI system | Yes Read the rule |
| 2 Classical ML Credit scoring · Insurance pricing · Fraud detection | Annex III high-risk. Fraud detection is carved out | Partly Weights inspectable |
| 3 Deep learning CV screening · Imaging triage · Defect rejection | Annex III, or Annex I where embedded in a device | Hard No readable reason |
| 4 Generative AI Claim summaries · Candidate shortlists · Draft denials | Art. 50 transparency, plus Annex III if it decides | Hard Fluent either way |
| Architecture — wraps any tier above | ||
| 5 Workflows Routes the claim · Chains score-then-check · Escalates exceptions | Where Art. 14 human oversight can actually be designed in | By design You wrote the path |
| 6 Agentic Sends the denial · Closes the ticket · Moves the money | Inherits the classification of the action it takes | No It chose the path |
Simplest to build is not lightest to govern.
Post-Omnibus timing: Annex III stand-alone high-risk from 2 Dec 2027 · embedded and safety-component from 2 Aug 2028 · Art. 50 from 2 Dec 2026.
Where to go next
The tier 5 / tier 6 boundary is the one that changes who is accountable, and it is the same distinction drawn in the corrected AI taxonomy — where workflows and agents sit outside the containment nesting rather than inside it.
Cyber terms for the boardroom does the same job for cybersecurity — thirteen terms defined for oversight, each with the question to put to management.
The Governance Memo carries this work monthly for boards and CISOs — one breach post-mortem and two or three governance items.