AI governance

"Governance" sounds like paperwork you do after the fun part. It isn't. It's a classifier: given what your system does and who it touches, the law and your risk framework tell you which obligations attach — and getting the tier wrong is how a shipped product becomes an unshippable one. This page lets you run that classifier on your own system.

EU AI Actrisk tiersNIST AI RMF model cardscompliance

The EU AI Act is a risk pyramid — find your tier

The EU AI Act doesn't regulate "AI" as one thing. It sorts systems into four tiers by risk, and the obligations scale with the tier: minimal-risk systems are essentially free, limited-risk ones owe transparency, high-risk ones carry heavy engineering and documentation duties, and a short list of uses is simply banned. The tier isn't about how clever the model is — it's about what it decides and about whom.

Tick what describes your system and watch where it lands. The tier is always the highest one any single answer triggers — one high-risk use case pulls the whole system up:

Classify your system

Two things people get wrong. First, most systems are minimal-risk — a spam filter or a recommender owes almost nothing, and treating it like a high-risk system is its own kind of failure (wasted quarters). Second, the transparency tier is easy to forget: if a user could mistake your system for a human, or you generate synthetic media, you must say so — that's a real obligation with a low bar to meet and a high cost to miss.

NIST AI RMF: govern, map, measure, manage — forever

The EU Act tells you what you owe; the NIST AI Risk Management Framework is how a team actually runs risk day to day. It's four functions, and the crucial part is that it's a loop, not a checklist you complete once. Govern sets the culture and accountability that the other three run inside; you Map context and risks, Measure them, then Manage — and new information sends you back around. Step through it:

The NIST AI RMF loop — ▶ play it

The model card is where governance becomes an artefact

All of this stays abstract until it's written down, and the standard place to write it is a model card — a one-page datasheet shipped with the model. Intended use and out-of-scope uses; the training data and its known gaps; performance broken down by subgroup, not just an aggregate; limitations and ethical considerations. It's the document an auditor, a customer, and the engineer who inherits this in a year all read first. A high-risk EU AI Act system essentially requires this content; every system benefits from it.

⚠️ Traps & honesty: this classifier is a teaching tool, not legal advice — the real EU AI Act has detailed definitions, carve-outs and exceptions (e.g. narrow law-enforcement allowances for otherwise-banned biometrics), and timelines that phase in by tier · "high-risk" here follows the Act's Annex III use-case list, simplified · a General-Purpose AI model carries its own separate obligations on top of the use-case tier · always confirm your specific obligations with counsel before you ship into the EU.
Takeaways: the EU AI Act classifies by use and impact, not cleverness — four tiers, obligations rising from none → transparency → heavy → banned, and your tier is the highest any single use triggers · most systems are minimal-risk; don't over-comply · transparency (disclose AI, label synthetic media) is the easy tier to miss · the NIST AI RMF is a continuous Govern-Map-Measure-Manage loop, not a one-time audit · a model card is where the obligations become a shippable artefact. Next: build vs buy is the decision this governance frames.

Second opinion (the topic is taught here — these corroborate and are the official sources): EU AI Act Explorer · NIST AI Risk Management Framework · Google — Model Cards.