Boardroom Answers · Strategic Command · Risk Management & Governance
EU AI Act Risk Classification: Where a Platform Sits
The question a Board Member / Non-Executive Director (NED) asks: “The EU AI Act is now enforcing. Where does your platform sit under it — and is any of it high-risk?”
The short answer
One open item, stated up front: whether our workforce modules hit Annex III high-risk awaits counsel sign-off — and we run them at the high-risk control bar meanwhile. The rest of the platform is human-in-loop decision support whose architecture reads like the Act’s own checklist: logging, oversight, traceability, robustness.
The full executive answer
Here is our classification analysis, including the one open item — and I will give you the open item first because you would find it anyway. The Act’s Annex III lists high-risk uses, and one of them is AI used in employment and workforce decisions — promotion, task allocation, performance evaluation. A subset of our 68 modules touches workforce and organisational diagnostics, and whether our specific implementations fall inside Annex III is a legal judgment we have deliberately not self-certified: it is awaiting qualified counsel sign-off, and until that opinion lands we treat those modules to high-risk-grade controls as a matter of engineering conservatism. I would rather tell a board "counsel review pending, controls built to the higher bar" than hand you a self-serving classification.
For the platform generally: most modules are decision-support for strategy, risk and governance analysis with a human decision-maker in the loop — a posture the Act treats far more favourably than autonomous decision systems, and the Act’s high-risk obligations read like our architecture document: risk-management system, logging and traceability, human oversight, accuracy and robustness measures. Concretely we ship: append-only hash-chained logging of every generation; mandatory human approval gates; documented model governance across two providers with adjudication; provenance validation on quantitative output; and prompt-injection and personal-data protections on everything entering a model. Alignment with ISO/IEC 42001 — the AI-management-system standard that is emerging as the practical route to demonstrating Act compliance — is the architectural spine, with certification itself on the roadmap after SOC 2.
Also relevant to a director: the Act primarily binds providers and deployers of AI systems — your organisation, as deployer, carries its own obligations when using any AI, including human-oversight and usage-transparency duties. A governed platform materially eases your deployer obligations compared with the ungoverned chatbot use almost certainly already occurring in your organisation — that comparison, not perfection, is the honest baseline for this conversation.
Grounded in: EU AI Act (Annex III; deployer obligations) · ISO/IEC 42001
The natural next questions
Related governed answers
- As a director I see risk through a heat map twice a year, and I know it is theatre. What does board-level risk reporting look like out of your platform, and how is it less theatrical?
- Our vendor-risk policy would normally screen out a company your size. Escrow, data portability, continuity — walk me through why engaging you is a governable risk rather than a policy exception.?
- Boards exist to exercise independent human judgment. Doesn’t systematising AI into board work erode the very thing — genuine deliberation — that makes a board worth having?
Want this answered live, on your data?