Skip to content
Back to blog
April 14, 2026·Stephan Moerman, CEO·2 min read

Risk-tier AI agents by authority, not intelligence

Risk & Compliancerisk tieringauthoritycontrols

Agent risk reviews often begin with model capability: which model is used, how autonomous it is, and how complex the task appears.

Those questions matter, but they can point the team in the wrong direction. A capable research agent with public, read-only access may be lower risk than a simple rules-and-model workflow that can change payroll data.

Risk follows authority, context, and consequence.

Assess the operating envelope

Tier the deployed system, not the model in isolation. Evaluate at least six dimensions:

  1. Data sensitivity: what can the agent read or infer?
  2. Action authority: can it write, send, execute, approve, purchase, or delete?
  3. Reach: which users, customers, systems, regions, or environments can it affect?
  4. Reversibility: can the effect be rolled back completely and quickly?
  5. Human dependence: is a qualified person reviewing before or after the action?
  6. Evidence quality: can the organization reconstruct the decision and prove which controls ran?

Frequency and scale amplify every dimension. A low-value action repeated thousands of times can create a high aggregate consequence.

Use a small number of tiers

Four tiers are usually enough to drive different controls:

Tier 1 — assistive

The system drafts, summarizes, or recommends. A person remains the actor and reviews the output before use. Controls focus on data access, disclosure, quality, and retention.

Tier 2 — bounded action

The agent can act in a limited, reversible scope: update a low-risk internal field, create a draft ticket, or retrieve approved data. Use scoped identity, allowlisted tools, runtime logging, and periodic evaluation.

Tier 3 — consequential action

The agent can affect customers, sensitive data, production systems, contractual communication, or meaningful spend. Require stronger pre-deployment evidence, policy enforcement, human checkpoints, separation of duties, rollback, incident routing, and continuous monitoring.

Tier 4 — critical or restricted

The system can create severe legal, safety, financial, or rights impacts, or operates where reliable controls are not yet possible. Keep it human-controlled, narrow the authority, use a supervised environment, or do not deploy.

The labels matter less than the control differences they trigger.

Treat risk as dynamic

An agent can move tiers without changing its model. Connecting a CRM, enabling outbound email, adding memory, expanding from staging to production, or removing an approval step changes the operating envelope.

Reassess after any material change. Tie the tier to a versioned record of tools, data, policies, and environment so a reviewer can see what was evaluated.

Do not confuse approval with safety

A high-risk agent does not become low risk because a person clicks approve. The system still needs least-privilege access, tested controls, usable evidence, and a response plan.

Human review is one control among several. It is strongest when reserved for decisions where context and judgment matter, not used as a blanket substitute for secure architecture.

Good risk tiering gives teams a paved road. Low-risk experiments move quickly inside clear boundaries. Higher-risk systems receive stronger engineering and oversight before their authority expands.

Know what every agent did — and why.

Start with a 14-day audit of your agents, access, evidence, costs, and human checkpoints.

Explore the audit pilot