AI-RISK · Path 3: Govern and protect
AI Risk Classification Lab
One day on which your real applications get classified instead of generic example cases from a slide.
- Duration
- 1 day
- Group
- up to 12 people
- Format
- In-house · Remote
- Language
- German or English
- Price
- €7,900 flat, plus VAT
Who this track is for
For governance owners and leaders who need to classify a list of deployed or planned AI applications with confidence. Ideal once you have the overview from AI-GOV and now want to decide individual cases cleanly.
Who it is not for
Not for organisations that have no picture of roles, register and oversight yet. They begin with EU AI Act and AI Governance (AI-GOV). Anyone who wants to test the security of an application books Secure GenAI and Agent Threat Modeling (AI-SEC).
Starting situation
You have a growing list of AI applications, but classification is a gut call. Sometimes everything is labelled high risk, sometimes a sensitive case is waved through as harmless, and no one can justify the decision when an authority or a customer asks.
This exists after the track
- Every submitted use case is assigned to a class: prohibited, high risk, transparency obligation or minimal
- Documented decision criteria that show why a case falls into its class
- A named control need per case instead of one blanket statement for everything
- A prioritised list of which applications need measures first
Prerequisites
A list of your deployed or planned AI applications and basic knowledge of their purpose. Prior knowledge of the EU AI Act helps but is not required.
Preparation before the track
You bring profiles of at least five real use cases: purpose, affected persons, data processed, model used and your role. These cases are classified in the lab.
What's included
- One on-site or remote day with Dino Bordonaro and up to twelve participants
- Classification decision tree and criteria catalogue as a working template
- Documentation template per case with class, rationale and control need
- Audit-proof training documentation and certificates of attendance
- A 15-minute follow-up call to prioritise your list of measures
Agenda
The four classes cleanly separated
Prohibited, high risk, transparency obligation, minimal. How to recognise each and where the grey zones sit. Core question: why does high risk follow use case and role rather than the industry as a blanket?
The decision tree in practice
We work through the criteria catalogue step by step. Exercise on a shared example case until every participant reads the tree with confidence.
Your real cases, round one
Each participant classifies two of their own use cases live. Decision: which class does the case fall into and which two criteria carry the decision?
Your real cases, round two and disputes
We bring the hard cases before the group. Exercise: where opinions diverge, we document both readings and the condition that tips the balance.
Control need and prioritisation
Per case we name which control is needed and how urgent it is. Day result: a documented, prioritised classification list of your submitted applications.
Exercises and lab share
Most of the day is classification work on your own use cases. Every participant leaves the lab with documented decisions on their real cases.
Platforms
Delivered on your premises or remotely. Work happens on your own application profiles, no production systems are connected.
Transfer evidence
The documented classification list at the end of the day is reviewed: class, two carrying criteria and control need per case. Attendance and content are documented in an audit-proof way.
Artifacts you take home
- Classification list of your use cases with class per case
- Documented decision criteria per classification
- Control need and urgency per case
- Prioritised list of measures as a starting point
Optional extensions
- EU AI Act and AI Governance (AI-GOV) for register, roles and control calendar around it
- Secure GenAI and Agent Threat Modeling (AI-SEC) for the applications classified as high risk
- A separately bookable workshop day to classify further cases
Boundaries
The lab delivers traceable classifications with documented criteria. It does not replace individual legal advice or a binding statement from an authority.
Frequently asked questions
Is the classification legally binding?
No. You receive a documented classification with a traceable rationale under the EU AI Act criteria. For binding statements in individual cases a lawyer's review remains your route, and our documentation is a solid basis for it.
We have more than twelve applications, is one day enough?
In one day we classify your most important cases together and train the decision tree so you can classify the rest yourself. For large inventories a further workshop day can follow.
Do we need prior knowledge of the legal text?
No. We introduce the four classes and the criteria in the morning. It helps if you know the purpose and data situation of your cases, because that is exactly what decides the class.