AI Governance Risk Levels Explained

AI Governance Check classifies every AI use case into one of four organizational governance levels. Each level reflects the potential for harm, the sensitivity of the data involved, the autonomy of the system, the degree of human oversight, and the regulatory context in which the AI operates. The classification is produced by a deterministic, rule-based engine — not an opaque model — so the result is transparent, consistent, and auditable.

The goal is not to slow down AI adoption, but to ensure that the amount of governance applied is proportionate to the risk a given use actually creates. A person using AI to brainstorm a non-sensitive idea should not face the same review process as a team deploying AI to screen job applicants or make clinical recommendations. By matching oversight to risk, organizations can move quickly on low-risk uses while dedicating appropriate attention and resources to uses that could affect people's rights, safety, finances, or access to services.

Below is a plain-language summary of each governance level, what it means, and what it implies for the organization. The same levels appear on every assessment result, along with the specific factors that drove the classification and a prioritized list of recommended actions and toolkit documents.

LOW

The use appears suitable for the baseline governance path. Register the use, confirm that the AI tool is approved, follow organizational data rules, verify important outputs, and maintain human responsibility. LOW-risk uses typically involve internal productivity assistance, drafting, brainstorming, or summarization where no sensitive data is involved, no consequential decisions are made, and a qualified person reviews the output before it is relied upon.

MODERATE

The use creates additional organizational exposure. A standard AI review is recommended before deployment. Document the owner and purpose, review the vendor where applicable, establish appropriate human oversight, and determine whether additional privacy, security, transparency, or monitoring controls are needed. MODERATE uses often involve customer-facing chatbots, marketing content, recommendation systems, third-party vendors, or situations where members of the public interact directly with AI-generated outputs.

HIGH IMPACT

The use could materially affect people, organizational risk, rights, safety, regulated activity, or consequential decisions. An enhanced governance review is recommended before deployment. Complete the AI Impact Assessment and obtain appropriate legal, privacy, security, business, or executive review based on the use. HIGH IMPACT uses typically involve employment decisions, healthcare, education, credit or financial services, biometrics, vulnerable populations, or autonomous actions with real-world consequences.

STOP / ESCALATE

The use raises issues that should not be handled through the standard approval path. Do not proceed until the use has been reviewed by the appropriate organizational authority or qualified specialist. This level is triggered when a proposed use may involve a prohibited purpose, severe or irreversible harm without sufficient safeguards, autonomous actions without meaningful human oversight, an unreviewed vendor in a regulated context, or activity clearly outside organizational approval involving high-impact factors.

Ready to classify your AI use?

Start Assessment

AI Governance Check | LTECwithLance — Decision-support tool only. Not legal advice or a compliance certification.