G3 - It's ‘Just a Chatbot’ — Until a Regulator Reads the Transcripts.
Most governance failures are proportionality errors: heavyweight process crushing low-risk tools, or light-touch habit waving high-risk systems through. Both errors come from the same root — classifying by product category instead of consequence.
Where this gets hard
- A drafting copilot and a public-facing eligibility chatbot both read as ‘AI assistants’ — with wildly different regulatory exposure.
- Uniform heavyweight governance breeds shadow AI; uniform light touch breeds liability. Most organisations run both errors at once.
- Vendor marketing categories become de facto risk ratings, because they're the only classification anyone performed.
- Purpose creep changes a system's risk class mid-life — the pilot's shortlist quietly becomes the shortlist, and nobody re-scores.
- Some properties don't average away: certain data types and use cases set legal floors, however benign everything else looks.
Where to start
- Score every system on two axes — regulatory exposure and business criticality — and let the position set the governance depth.
- Write the rationale down. A bare tier label can't be defended two years later; the reasoning can.
- Hard-code the overrides: prohibited-use indications stop everything, and certain regulated use cases set a minimum tier by law.
- Define re-scoring triggers — new purpose, new population, substantial modification — and wire them into change management.
- Make light-touch an explicit decision with an annual attestation, so nobody mistakes proportionality for neglect.
The companion consulting document on our website includes a two-axis tiering instrument, the tier ladder and the override rules.
Part of RMAT's 12-part series on AI governance — Governing AI with Evidence. The companion consulting document — detailed checklists, a risk table, a maturity self-assessment and a 90-day action roadmap — is available on our website.
#CEO #CTO #Governance #AI #Risk