Toolkit · Instrument 2
Risk Tier Classifier
Not every AI use deserves the same level of scrutiny. An internal drafting aid and a system influencing benefits eligibility present very different governance problems. Risk tiers allow a city to apply proportionate oversight based on a system's potential impact on residents.
Five classification factors
Evaluate each system against these five factors to assign a preliminary risk tier. Consequence and autonomy should carry the greatest weight, while data sensitivity, reversibility, and scale may increase the level of review.
Consequence
Can the system's output affect a person's rights, benefits, safety, liberty, or livelihood?
Autonomy
Does the output lead to action directly, or does a trained human meaningfully review it first?
Data sensitivity
Does the system process personal, protected, or surveillance-derived data?
Reversibility
If the system errs, how easily can the harm be detected and corrected?
Scale
How many residents does the system touch, and how often?
How to assign a tier
Use the five factors to assign a preliminary risk tier. The factors are not equally weighted: consequence and autonomy should drive the initial classification.
Step 1 · Start with consequence
Ask whether the system affects rights, benefits, employment, housing, public safety, liberty, or access to essential services.
- • No direct resident impact usually points toward Tier 1 or Tier 2.
- • Consequential resident impact should generally be treated as at least Tier 3.
- • Uses involving liberty, surveillance, biometric identification, coercive enforcement, or serious safety consequences should be considered for Tier 4.
Step 2 · Consider autonomy
Raise the tier when the system's output directly triggers action or when human review is limited, rushed, procedural, or unlikely to change the result.
Step 3 · Consider data, reversibility, and scale
Raise the tier when the system:
- • processes sensitive, biometric, protected, or surveillance-derived data;
- • may cause harm that is difficult to detect or reverse;
- • affects large numbers of residents;
- • is used frequently;
- • or operates across several departments or services.
Step 4 · Use the higher provisional tier when uncertain
When a system falls between two tiers, assign the higher provisional tier until legal, technical, privacy, security, and operational review is complete.
The four tiers
Minimal risk
Typical examples
Internal drafting aids, meeting transcription, internal translation, code assistance, administrative search, and summarization of non-sensitive internal material.
Recommended oversight
Department-level approval, basic acceptable-use rules, staff training, and appropriate records guidance.
Moderate risk
Typical examples
Resident-facing chatbots, document summarization for public release, service-request routing, permit or application triage, planning analytics, and non-consequential recommendation tools.
Recommended oversight
Responsible-official approval, accuracy testing, a correction pathway, documentation of system limitations, and disclosure when residents interact directly with the system.
High risk
Typical examples
Systems influencing benefits eligibility, permitting or code enforcement, hiring or employment screening, fraud detection, prioritization of inspections, housing decisions, and systems influencing access to public services.
Recommended oversight
Enhanced legal, privacy, civil-rights, security, and operational review before deployment; a named human decision-maker; public disclosure; an appeal or correction process; audit logging; and evaluation for potential disparate impacts.
Critical risk / enhanced review
Typical examples
Policing, surveillance, facial recognition, biometric identification, predictive enforcement, systems affecting liberty, systems creating serious public-safety consequences, and systems making or strongly determining coercive government actions.
Recommended oversight
Consider whether the use should proceed at all. Apply enhanced legal, privacy, civil-rights, security, technical, and operational review; governing-body authorization where appropriate; public notice and participation where appropriate; independent evaluation; strict human oversight; incident reporting; and periodic reauthorization.
Put the classifier to work
Classify the systems identified in the AI Use Inventory. Apply the most detailed procurement, review, transparency, and accountability safeguards to Tier 3 and Tier 4 systems.