Purchasing an AI system and using it as delivered is a different situation from adapting a model to your own data or purpose. That adaptation can change your organization's classification — and with it, the questions you must be able to answer. Whether that happens, and how much weight it carries, depends on exactly what is being adapted and what the system is being used for.
The classification does not depend on whether you wrote the source code. It depends on what actually happens to a model after it comes into your possession. A few factors that play a role:
These factors work together. There is no fixed threshold that applies in all cases; the current regulations with the precise criteria are set out elsewhere, and that text may change. What remains valid on this page is the mechanism: adapting can change your role, and role determines obligation.
The role your organization takes on with respect to an AI system is not fixed. An organization that only uses a model as delivered generally holds a different position than one that modifies the model and subsequently brings it to market itself or deploys it internally at scale. The question of when that transition takes place, and what changes at that moment in what you must be able to demonstrate, is addressed on when your role changes and where that line lies. For organizations uncertain whether they are a provider or a deployer — a question that arises more often than expected as soon as internal adaptation takes place — a separate explanation is available on the distinction between provider and deployer of an AI system.
The reason this matters is not formal. A change of role changes what you must be able to show: what documentation you keep, who within the organization is responsible for oversight, and what steps were taken before the adapted system went into use. A model you have adapted yourself is a model for which you can yourself be asked to account for how that adaptation came about.
Adaptation can also affect the risk level of an application. A model originally intended for a low-risk application can end up in a higher-risk category through adaptation — for example, when after adaptation it is deployed for decisions about people. What a high risk level concretely means for your organization's obligations is set out on what a high risk level means for the requirements placed on your organization. Here too: the classification follows from the use, not from the intention with which the model was originally built.
This touches directly on the core of shadow AI. An adaptation that does not go through IT — a team fine-tuning a model itself on its own dataset, or a department connecting an external model to internal systems without reporting on it — changes your organization's classification without the board being aware of it. The IT inventory does not show that adaptation. Anyone wanting to know whether this is happening must ask the teams that work with it daily, and that conversation only yields something if it is conducted without repercussions.
When an adaptation changes the role or risk level of an application, a number of things change at once: the documentation that must be kept, the question of who within the organization owns that application, and the point at which something can still be planned versus what already requires attention. That distinction — between what is already urgent and what can be scheduled — is related to factors explained on what already requires attention now and what can still be planned. A more extensive treatment of the classification question itself, including the borderline cases that occur most often in practice, is available on the full explanation of what changes when you adapt a model yourself.
An adapted model is in practice often also a model that takes over part of the work from people who previously performed a task entirely themselves. Whether that is the case, and how much of the work is involved, is a question separate from the classification question but one that frequently follows it: as soon as it is clear that a model has been adapted and what it is being deployed for, it also becomes visible which part of a task it actually performs. The work scan from FTE TO AI calculates this per task and shows which part of the work can be taken over by AI, regardless of how the underlying model came about.
Vraag maar. Governance begint bij weten wat er draait — ook wat niemand heeft goedgekeurd.
Answers come from this site’s knowledge base. Not tailored advice, and not a scan of your company.