Risk Classification (Tier 0–3)
Purpose
Section titled “Purpose”Ensure controls scale with risk, avoiding one-size-fits-all requirements while mandating strong safeguards for high-impact and potentially irreversible harms.
Ethical Mapping
Section titled “Ethical Mapping”A5 Proportionality & ModerationA3 Justice, Due Process, and RemedyA7 Stewardship
Tier 0 — Research / Educational
Section titled “Tier 0 — Research / Educational”Typical attributes:
- lab, sandbox, or instructional use
- no real-world high-impact decisions
- limited scale and exposure
Minimum expectations:
- basic ethics review and documentation (recommended)
- safe handling of sensitive data (required where applicable)
Tier 1 — Low-Risk Commercial
Section titled “Tier 1 — Low-Risk Commercial”Typical attributes:
- consumer or business utility with low harm potential
- limited consequence of errors; easy reversibility
Minimum expectations:
- disclosure packet (AI-T-1) for AI systems
- basic risk assessment (AI-S-1 or QC equivalent)
Tier 2 — High-Impact Societal
Section titled “Tier 2 — High-Impact Societal”Typical attributes:
- influences high-impact decisions (health, employment, education, housing, finance, public services)
- large scale or vulnerable populations
- meaningful privacy, bias, or security risk
Minimum expectations:
- equity impact assessment (AI-FJ-11)
- red-teaming and incident readiness (AI-S-2, AI-S-4)
- contestability and remedy pathways (A3-aligned)
Tier 3 — Critical / Existential
Section titled “Tier 3 — Critical / Existential”Typical attributes:
- risk of catastrophic, irreversible, or systemic harm
- dual-use capabilities with large-scale abuse potential
- cryptographic destabilization or major security escalation risk
- broad autonomy or rapid amplification beyond human control
Minimum expectations:
- multi-stakeholder governance review and dual-use controls
- moratorium-capable governance (Q-RD-10)
- independent audit as a precondition of deployment
Classification Criteria (Decision Record)
Section titled “Classification Criteria (Decision Record)”Operators MUST document a tiering decision record using, at minimum:
- Impact domain: high-impact decision involvement (yes/no; describe)
- Scale: number of affected parties and geographic scope
- Reversibility: ability to undo harms and timeframe
- Autonomy: degree of automated action vs. human authority
- Data sensitivity: personal, biometric, protected, national-security relevant
- Dual-use: credible misuse pathways and feasibility
If criteria are mixed, classify at the highest plausible tier unless a documented mitigation reduces risk below that tier.
Compliance Evidence
Section titled “Compliance Evidence”- tiering decision record and approvals
- periodic reassessment schedule (at least annually for Tier 2–3)
- triggers for re-tiering (capability change, scale change, incident)
Traceability Table (Requirement → Axiom → Evidence)
Section titled “Traceability Table (Requirement → Axiom → Evidence)”| Requirement / Control | Axiom(s) | Evidence Artifacts |
|---|---|---|
| Tiering decision record | A5, A3 | tiering decision record and approvals |
| Reassessment & re-tiering | A5, A7 | reassessment schedule, re-tiering triggers |
Change Log
Section titled “Change Log”- v0.2: Added Traceability Table and Change Log to conform to
ETHICAL_TRACEABILITY.mdandVERSIONING.md.