Risk classification

Classify every agent by risk before it reaches production

The EU AI Act demands risk classification. Your board demands accountability. But you can't classify what you can't see. Roval maps every agent to a risk tier across four dimensions, automatically.

The problem

You can't govern what you haven't classified

Over half of organizations lack systematic inventories of AI systems, making risk classification impossible

EU AI Act compliance analyses, 2025

For CTOs, CIOs, and AI teams, the challenge is no longer 'Can we build AI?' but 'Can we govern AI well enough to deploy it safely, sustainably, and defensibly?'

Data Science Dojo, AI Governance Checklist 2025

AI system boundaries are not obvious. Sorting out what is in scope and what is out takes analytical work that simply did not exist with ISMS implementations.

CSA / Schellman, ISO 42001 audit analysis 2025

Agents are non-deterministic, context-dependent, and operate across fluid boundaries. The semantic gap between what our detection tools expect and what agents actually do is significant.

Coalfire, 2026

Risk classification is the foundation of Roval's AI governance platform. Every policy, certification, and audit report builds on the risk tier assigned here.

How it works

From unknown exposure to defensible governance

Four dimensions, one risk score

Classify across data sensitivity, decision authority, blast radius, and regulatory exposure. Configurable dimension weights. The composite tier determines which compliance frameworks apply and which gates the agent must pass.

See the agent registry
Risk assessment Tier 3: High risk
Data sensitivity 85
Decision authority 70
Blast radius 60
Regulatory exposure 90
Composite score 76.3. EU AI Act Article 10 applies

EU AI Act risk levels, mapped automatically

Map every agent to the EU AI Act risk pyramid. High-risk systems get mandatory documentation, human oversight requirements, and conformity assessment tracking. Penalties reach EUR 35 million or 7% of global revenue.

See compliance integration
EU AI Act risk mapping
Category Agents Policy status
Unacceptable 0 -
High risk 12 8 certified
Limited 18 Transparency req.
Minimal 17 No obligations

Production gates that enforce policy

High-risk agents cannot reach production without completed risk classification and required certifications. The gate is enforced by the platform, not by process.

See lifecycle management
Lifecycle: customer-triage-agent
Draft
Review
Certified
Production
Missing: EU AI Act Article 9 risk documentation

Auto-classification with human review

The auto-classifier analyzes agent metadata and suggests a risk tier with reasoning you can review. Accept or override with one click. Every classification decision is logged.

See it in action
Auto-classifier result Tier 3 suggested
Reasoning
  • Agent handles PII (email, SSN) in request payloads
  • Makes autonomous decisions without human review loop
  • Serves 50,000+ users, blast radius is high
  • Touches payment data, PCI DSS scope applies
Accept Tier 3 Override
of CISOs saw agents exhibit unintended behavior
47%
Saviynt, 2026
maximum penalty under the EU AI Act
EUR 35M
EU AI Act
High-risk obligations enforceable
Aug 2, 2026
EU AI Act
reported a negative AI incident last year
51%
McKinsey, 2025
Compliance frameworks

Frameworks that mandate risk classification

Risk tiering is a legal requirement under these frameworks, not a nice-to-have.

EU
EU AI Act eu-ai-act

Four-tier risk classification: unacceptable, high, limited, minimal. High-risk obligations enforceable August 2026.

Active
24 requirements Effective Aug 2026
US
NIST AI RMF nist-ai-rmf

MAP function requires categorizing AI risks by likelihood and severity across trustworthiness dimensions.

Active
22 requirements Risk management
Industry
ISO 42001 iso-42001

Clause 6.1.2 requires AI risk assessments covering impact, likelihood, and risk treatment decisions.

Active
31 requirements AIMS certification
EU
GDPR gdpr

Article 35 mandates Data Protection Impact Assessments for AI processing that poses high risks to individuals.

Active
14 requirements Data protection

Start classifying your agents

Most teams complete their first full classification sweep in under a day.