Is Your AI High, Medium or Low Risk? A 3-Question Test for UK Business Leaders

· By Peter Lowe

Category: Governance

Flat-vector illustration of a businessperson sorting AI tools into high, medium and low risk tiers on a board, in brand colours

Not every AI tool needs the same governance. Use this three-question AI risk classification test to focus your attention where it truly matters.

Once you have a list of the AI tools your business actually uses — and as the companion piece on [shadow AI](/insights/shadow-ai-find-before-regulator/) covers, most businesses find several times more than they expect — the next question decides where your attention goes. Not every AI tool deserves the same level of governance. A meeting-transcription tool and a CV-screening tool are both AI. They are not the same risk, and treating them as if they were is its own mistake. Over-govern the low-risk tools and you waste board time and goodwill. Under-govern the high-risk ones and you carry the consequences when something goes wrong. This piece walks through the three-question test we use to classify every tool on a client’s register. It also covers the hard floor underneath all of it: the uses [the EU AI Act bans outright](/insights/ai-compliance-governance-uk-business-owners/), which no risk rating can rescue. If one of your tools falls foul of those, the classification is beside the point — you stop. ## The three-question test For each tool on your register, ask these three in order. Stop at the first “yes.” **Question 1: Could this AI affect an important decision about a person?** By “important decision” we mean hiring or firing, approving or declining credit, deciding who qualifies for a service, setting someone’s pay or performance rating, deciding a customer’s insurance premium. If yes — even if the AI is only one input and a human makes the final call — it is High Risk. Treat it accordingly. If no, go to Question 2. **Question 2: Does this AI handle personal information about people at scale?** By “at scale” we mean personalising marketing to thousands of customers, recommending products from browsing behaviour, scoring or segmenting your customer database, analysing sentiment, profiling website visitors. If yes, it is Medium Risk — meaningful checks, but not the full High Risk treatment. If no, go to Question 3. **Question 3: Does this AI only help with internal tasks and never touch decisions about people?** Summarising documents, drafting internal reports, suggesting meeting times, transcribing meetings, generating images for internal slides. If yes, it is Low Risk. Register it, set a basic policy, and move on. ## What each level means in practice ### High Risk: full attention These are the tools regulators look at hardest, and where tribunal claims and customer complaints are most likely. For each one: - Complete a Data Protection Impact Assessment (DPIA) before you carry on using it. - Confirm a real person can review and overturn any decision it drives — and that the reviewer has the time, knowledge and authority to do it, not just a rubber stamp. - Run proper due diligence on the supplier (the companion piece on [supplier vetting](/insights/ai-supplier-due-diligence-questions/) covers how). - Make sure the people affected know AI is involved and can challenge the outcome. - Document all of it: the tool, the decisions it touches, the safeguards, the reviews. Examples: CV-screening software, loan and credit tools, AI that rates employee performance, AI that decides who gets a service or benefit, facial-recognition access systems. If you have EU customers, these are also the tools the EU AI Act treats as “high-risk.” That regime was originally due to bite in August 2026, but the EU has pushed the main high-risk deadline back to December 2027 — so it is coming, not imminent. The bans below, by contrast, are already live. ### Medium Risk: meaningful checks For each one: - Carry out a documented risk review — lighter than a full DPIA. - Tell people when they are dealing with AI, for example in a customer chatbot. (This transparency duty applies under the EU AI Act from August 2026 if you have EU users, and is good practice regardless.) - Review the tool periodically to check it is behaving as intended. Examples: customer-service chatbots, marketing personalisation, recommendation engines, sentiment analysis, send-time optimisation. ### Low Risk: basic record-keeping For each one: - Add it to your register with a named owner. - Set a brief acceptable-use policy. - Check once a year that its scope hasn’t changed — vendors quietly add features. Examples: AI writing assistants, document summarisers, meeting transcription, internal productivity tools, image generators for internal slides. ## The hard floor: eight things AI must never do Underneath the three levels sits a hard floor. The [EU AI Act](https://eur-lex.europa.eu/eli/reg/2024/1689/oj) bans these uses outright, with fines up to €35 million or 7% of global turnover. The bans have been live since February 2025, and they apply to any UK business with EU customers, users or staff — which is most. If any tool does any of these, stop using it for that purpose and take legal advice. **1. Manipulating people without them knowing.** Subliminal or hidden techniques that change how people think or act without their awareness. **2. Exploiting people’s weaknesses.** Targeting people because of age, disability, financial difficulty or other vulnerability — for example, pushing someone into a purchase they can’t afford because the system spotted they’re financially stressed. **3. Scoring people’s social behaviour.** Giving people a “social score” from their behaviour in one area, then using it against them in an unrelated one. **4. Predicting who will commit a crime.** Profiling individuals as likely criminals from their characteristics rather than actual evidence. **5. Building facial databases without permission.** Scraping photos from the internet or CCTV to build a facial-recognition database without consent. This is what Clearview AI was fined £7.5m for in 2022. **6. Reading employees’ or students’ emotions.** AI cameras or sensors detecting whether staff are stressed, bored or disengaged — except where there is a specific safety justification. **7. Categorising people by sensitive characteristics.** Using facial or biometric analysis to infer race, religion, political views or sexual orientation. **8. Live facial recognition in public spaces.** This is aimed mainly at law enforcement, but any private use of real-time facial recognition in publicly accessible spaces needs urgent legal review. The EU has since added a further prohibition, from December 2026, on AI that generates non-consensual intimate imagery or child sexual abuse material — relevant mainly if your business builds or offers image-generation tools. The eighth one catches more businesses than expected: retailers using face recognition for “loss prevention,” office buildings using it for access in publicly accessible foyers, venues using it for crowd management. All need a legal look. ## Worked examples by department ### HR and recruitment CV screening, candidate ranking, automated interview scoring, AI that scores performance reviews — all High Risk. These affect people’s livelihoods, and if you have EU customers the EU AI Act puts them in its high-risk category (now due from December 2027, moved back from August 2026). If your team uses AI mood or “wellbeing” detection, check straight away whether it falls under banned use 6. ### Marketing Subject-line generators, content writers, image generators for social — usually Low Risk, but they need a clear acceptable-use policy because staff will paste customer data into them. Personalisation, segmentation, sentiment analysis, lookalike audiences — usually Medium Risk, because they handle personal data at scale. Pricing or targeting that exploits vulnerability — for example, charging more to users the system flags as financially stressed — falls under banned use 2, and it catches more pricing tools than businesses realise. ### Customer service Chatbots answering enquiries — Medium Risk; tell customers they’re talking to AI and keep a human reachable. AI that decides who gets a refund, a service or a human — High Risk, because it’s deciding outcomes for people. AI handling complaints with no escalation route needs review for both fairness and consumer protection. ### Finance and operations Credit scoring, loan decisioning, insurance underwriting — High Risk, and top priority under the EU AI Act high-risk regime (December 2027) if you have EU customers. Fraud detection — usually Medium to High Risk, depending on how decisions are made and whether customers can challenge them. AI that suggests procurement, summarises invoices or categorises expenses — usually Low Risk; useful, defensible, just register it. ## Where to start this week Take the register from your discovery exercise and work through it tool by tool. For each one: run the three questions, check it against the eight bans, mark it High, Medium or Low, and note a date for the next action — DPIA, risk review or annual check. It’s usually a half-day once the register exists. By the end you’ll know where the next 60 days of attention should go, and, just as usefully, what you can leave alone. ## Where this needs a professional Most of this you can do yourself. Where a tool’s risk level is genuinely unclear — which happens more than you’d think — or where you’re close to one of the bans, that’s worth proper advice. The adviser you want is one who helps you find the compliant way to keep using a tool, or a compliant alternative, not one who simply tells you to down tools. A good one will still say stop when stop is right — a banned use is a banned use — but they’ll show you the route through rather than leaving you stuck. If you’d like a second pair of eyes on the classifications — particularly the borderline tools, which are more common than you’d expect — we run a 90-minute [risk-classification session](/ai-consultancy/) that goes through your register tool by tool and ends with a written risk register you can take to your board. It’s led by an AI governance expert, so timing depends on their availability. [Book a call with Peter](/contact/) and we’ll talk through whether it fits. ## Frequently asked questions ### How do I classify my AI as high, medium or low risk? Work through three questions: does it affect a person’s rights or livelihood, does it make or heavily influence a decision, and is there meaningful human review before that decision takes effect? The more "yes" answers on impact without human review, the higher the risk. ### What counts as high-risk AI? AI used for things like hiring, credit, insurance, eligibility or performance decisions is high-risk, because it materially affects people. The EU AI Act places these in its high-risk category and expects tighter controls and documentation. ### Does AI risk classification apply to UK businesses? Yes. UK GDPR governs automated decisions about people regardless of the tool, and any business with EU users also falls under the EU AI Act’s risk tiers. Classifying your AI is the fastest way to focus effort where regulators focus theirs. *Smart AI Studio works with UK business owners and leadership teams on practical AI adoption, including compliance, governance and risk. This article reflects the regulatory position as of July 2026 and is general guidance, not legal advice. AI regulation is moving quickly — the EU AI Act’s high-risk deadlines in particular were amended in mid-2026 — so check the current position before acting. For specific compliance questions, consult a qualified solicitor or data protection specialist.*

This article was written by Peter Lowe. The ideas and opinions are his own; AI was used to assist with drafting and editing.