re-ai-gov Join the waiting list

Kennisbank

Urgent or plannable: what the classification depends on

The question behind the question

An inventory of AI use usually results in a list that is too long to tackle in one go. The question that follows is not "what should we do" but "what should we do first". That is a classification question, and the answer does not depend on how many systems there are, but on what those systems do and for whom.

What urgency depends on

The first factor is the risk level of the application itself. A system that prepares decisions about people — hiring, credit provision, allocation of care or benefits — requires different handling than a tool that rewrites text for internal use. What a high risk level means for your organization therefore differs per application, and those differences determine which systems are addressed first.

The second factor is the organization's role in relation to that system. Whoever buys a model and uses it unchanged faces different obligations than whoever has a model trained on their own data or structurally adjusts the output. Whether you are a provider or a user of an AI application determines not only which obligations apply, but also how much time is needed to meet those obligations — a provider generally has more to prepare than a user.

The third factor is whether the system is already in use or is still being procured. A risk that is already running — with real users, real decisions, real data — requires a different order than a risk that is still in the contract phase and where agreements can still be put in place before the system goes live.

What changes when the situation changes

This classification is not a snapshot. A system that is low risk today may no longer be so after a modification. What it means when you adjust a model yourself — fine-tuning, a new dataset, a different application of the same underlying technology — depends on exactly what changes, but the classification made earlier does not automatically hold as a result.

The same applies to role change. An organization that acquires a ready-made model and subsequently adjusts it significantly can thereby shift from user to provider. When that role changes is not always the moment of the adjustment itself, but the moment at which that adjustment changes the character of the system. This too is a classification question, and it too requires reassessment as soon as the situation changes — not a one-time check that then remains valid.

And a system still being procured shifts from plannable to urgent the moment it goes live. The classification that applied to the contract phase does not apply to the usage phase.

What this means for the order

The practical consequence is that an inventory does not produce a priority list once, but a structure that must be gone through repeatedly. Systems with a high risk level and an active provider role require attention now. Systems with a low risk level that are not yet in use can be planned — but the planning must include a moment for reassessment, because adjustments, role change or going live can reverse the classification.

That requires a fixed place where decisions about that classification are recorded: which system has been marked as urgent, on the basis of which factor, and when that assessment was last carried out. An oversight decision log is the form in which that classification is made demonstrable — not as extra administration, but as the only proof that the classification is not accidental, but the result of a repeatable process.

The actual regulations — which deadlines apply, which obligations per risk class belong to which date — are covered elsewhere. This page describes the mechanism by which you distinguish urgent from plannable; you will not find the current legal text and deadlines here.

From classification to content

The classification into urgent and plannable says something about the order of attention, not about the content of the work itself. Once it is clear which AI application takes priority, the question remains open what that application actually does with the work surrounding it: which part of a task runs automatically, which part requires checking, and which part remains with a human. That question is answered by the work scan of FTE TO AI, which calculates per task which part of the work can be taken over by AI — an addition to the classification made here, focused on the content of the work itself.

Andrewde assistent van de Responsible AI Scan

Vraag maar. Governance begint bij weten wat er draait — ook wat niemand heeft goedgekeurd.

Answers come from this site’s knowledge base. Not tailored advice, and not a scan of your company.