re-ai-gov Join the waiting list

Kennisbank

Classifying is not a one-time exercise

A classification of an AI application describes a situation at a particular moment: which model, which application, which users, which risk. That situation changes. A supplier adjusts a model, a team uses a tool for something other than what it was purchased for, a provider adds a feature without anyone requesting permission for it. The classification you made last year therefore does not automatically still describe today's situation.

The question "how often" has no fixed answer that applies to every organization. It depends on how many AI applications there are, how quickly they change, how diverse the teams working with them are, and how strict the oversight is in the sector in which you operate. A fixed annual moment is a starting point, not a guarantee that you won't miss anything in between.

What a fixed interval does not solve

An annual or semi-annual recalibration works well for applications you already know about and that entered through a formal process. For applications that no one has reported, a fixed interval does not work, simply because there is nothing to reassess on a fixed date. What do you do with employees who use a tool that no one has approved describes why that question is not resolved with a recurring calendar appointment, but with a different way of asking questions within the organization.

In addition, risk changes not only because of what an application does, but also because of what is fed into it. A chat window that is used today for summarizing public text can be used tomorrow for summarizing a contract. What do you do with company data in a free chat window shows that the risk level of the same tool can shift without the tool itself changing.

Signals that call for recalibration, regardless of the date

Besides a fixed moment, there are events that call for an interim recalibration. A change in the function of an application, an expansion of the user group, an incident or near-miss, a change in the supplier's terms, or a signal from an employee that something is being used differently than intended. These signals do not all carry the same weight, and not every organization will notice them equally quickly.

The question of who responds to those signals, and who has ownership of the recalibration itself, is a separate question. Who is responsible when an AI application makes a mistake describes that responsibility is often only established at the moment something goes wrong, whereas that question should actually have been answered already at the first classification.

Why a second process often disappears faster than the process that already existed

A recalibration rhythm that is placed alongside existing risk processes, without integrating into them, usually loses priority within a year. It is an extra step that no one asks for until something goes wrong, and precisely for that reason it gets left behind. Why a second process alongside the existing one gets ignored explains why recalibration works more effectively when it is embedded in existing risk management, rather than as a standalone process that competes for attention with the rest of the organization.

What the method cannot do

A classification method can provide a structure for assessing AI applications consistently on role and risk level, and that structure can be applied repeatably. What the method cannot do is guarantee that you see everything. A classification is only as good as the information underlying it, and that information partly comes from people who may have a reason not to report something. An employee using a tool that has not been approved does not report that on their own initiative if the expectation is that a sanction will follow.

The method also cannot predict when a supplier will change a model, or when an application that is low risk today will be deployed differently tomorrow. Recalibration therefore remains a matter of repetition and of organizing openness, not of a system that is set up once and then remains current on its own. How you keep that register up to date without it falling behind again after a few months is described in how do you keep an AI register up to date, which focuses on the distinction between a one-time inventory and an ongoing process.

This also includes the question of what oversight of AI means in practice between recalibration moments: who is watching, at what frequency, and based on which signals. What is human oversight in practice makes the distinction between oversight as a formal checkbox and oversight as something that continuously accompanies use.

The next question, once the classification is in place

A classification tells you which applications exist, what role they have and which risk level applies to them. That classification does not tell you how much of the work is actually being done by AI, and how much room per task still remains. Anyone who wants to answer that question cannot rely solely on a risk inventory; that requires a look at the work itself, task by task. The work scan from FTE TO AI calculates per task which part of it can be taken over by AI, as a complement to the picture that a classification provides.

Andrewde assistent van de Responsible AI Scan

Vraag maar. Governance begint bij weten wat er draait — ook wat niemand heeft goedgekeurd.

Answers come from this site’s knowledge base. Not tailored advice, and not a scan of your company.