title: “AI System Classification” description: “Classifying AI systems for appropriate governance treatment.”
AI System Classification
Classification helps determine the governance treatment appropriate for an AI system based on its characteristics, intended use, context, risks, and applicable requirements.Purpose
Classification establishes a structured governance category or treatment pathway for an AI system. Classification can consider factors such as: * intended use * system capabilities * potential impact * risk * affected stakeholders * deployment context * lifecycle stage * applicable legal or regulatory requirements * organizational policy * governance requirementsClassification and risk
Classification and risk assessment are related but distinct activities. Classification determines an appropriate governance category or treatment pathway. Risk assessment examines the specific risks associated with the AI system, its use, operation, and context. Classification may therefore influence the depth, scope, or frequency of subsequent risk and governance activities without replacing risk assessment.Governance consequence
Classification should inform the governance pathway that follows. Depending on the resulting classification, an AI system may require different levels of: * risk assessment * control implementation * control assessment * approval * monitoring * evidence collection * assurance * management oversight * change review Classification decisions should be recorded and traceable to the information and criteria used to reach the decision.Machine-readable governance
Classification information can form part of an AI system’s machine-readable governance record and can be related to risk, controls, assessments, approvals, monitoring, assurance, and other lifecycle records. Where applicable rules are defined, classification-related information can also become an input to machine-readable governance evaluation.Reclassification
Classification should be reconsidered when material changes occur. Potential triggers include: * changes to intended use * changes to system capabilities * changes to deployment context * changes in affected stakeholders * changes in risk * changes in applicable requirements * significant system or model changes * changes to organizational governance criteria A reclassification decision should preserve traceability to the triggering change and resulting governance actions.Source
The canonical procedure is maintained in:guidance/02-procedures/04-AIGO-AI-Classification-Procedure-v0.1.md
The broader classification and governance model is defined by the AIGO Framework and associated machine-readable schemas.