When designing AI governance, not all AI systems should be governed under the same conditions. The required governance must be classified according to the environment, role, and risk associated with the AI system.

Governance requirements first differ by AI Type. An AI Model primarily performs inference or generation in response to inputs, whereas an AI Agent may interact with external systems, perform sequences of actions, and potentially connect to Execution. Even when the same underlying model is used, governance requirements may differ depending on how the AI is deployed.

Governance can then be classified from four additional perspectives.

The first is Domain. Healthcare, Finance, Education, Manufacturing, and other domains are subject to different laws, regulations, professional standards, and operational requirements. Governance must therefore identify not only the AI itself, but where the AI is being used.

The second is Risk. The required level of oversight, validation, and execution control varies according to the potential impact of AI use, ranging from Standard and High-Risk applications to Critical Infrastructure. Applying the same governance intensity to low-risk applications and systems affecting human life or critical infrastructure would not be reasonable.

The third is Functional Role. Content Generation, Decision Support, and functions connected to Execution represent fundamentally different roles for AI. The required Authority and Execution Control therefore vary according to the role the AI performs.

The fourth is Stakeholder. Factors such as Children, Accessibility, Security, and Regional Requirements affect who may be impacted and what protections or jurisdiction-specific conditions apply.

Importantly, these classifications do not operate independently. Multiple classifications overlap to form a Governance Context. The same AI Model, for example, may require substantially different governance when used for general-purpose writing than when used for Decision Support in healthcare.

Governance Classification is therefore not a mechanism for simply labeling AI as “safe” or “dangerous.” It provides an entry point for structuring the question of which governance requirements apply to this AI, for this use, in this environment, based on:

AI Type × Domain × Risk × Functional Role × Stakeholder