Risk classification, risk matrix and the controls behind them
ExploreWorldAI is an EU regulatory intelligence platform for companies, not a travel service.
European rules do not ask whether a service feels safe, they ask which class it belongs to, how each risk was scored and which control answers it. This page shows the three steps in the order they are used: the class the service sits in, the matrix that turns likelihood and impact into one level, and the controls each level triggers.
The register below is the live view of our own assessment. A risk is written down before a control is chosen, and a risk that has been reduced stays on the page with its new level rather than being removed.
Reviewed: 2026-08-08
Classification
Two rulebooks decide the class: the AI Act by what the service does to a person, and the GDPR by what the processing does to a person's rights. Both are stated here, with the position we take under each tier.
| Tier | Definition | Typical examples | Our position |
|---|---|---|---|
| Prohibited practice (Article 5, Regulation (EU) 2024/1689) | Uses that are banned outright because they exploit vulnerability, score people socially or read emotion and traits in ways the union does not accept. | Social scoring, untargeted collection of facial images, emotion reading at work, exploitation of age or disability. | Not applicable. The service reads published company material and produces business findings, it never scores a person and never infers emotion, health or belief. |
| High risk (Article 6 and Annex III, Regulation (EU) 2024/1689) | Uses in listed areas where an output affects access to work, education, credit, essential services or justice, and therefore carries the full duty set. | Filtering job applications, credit decisions, admission decisions, allocation of public benefits. | Our interpretation: this is not the part that applies as delivered. Recruitment and capital matching produce a ranked view with the arithmetic shown, and the decision stays with the customer; a customer who uses an output as the deciding factor takes on the high-risk duties themselves, which the terms state. |
| Limited risk (Article 50, Regulation (EU) 2024/1689) | Uses where the duty is transparency: a person has to know they are dealing with a machine and that content was produced by one. | Support assistants, generated text and summaries, machine-written suggestions in a report. | This is where the service sits. The assistant states it is a service and not a person, generated text is marked as generated, and every figure carries the source it was read from. |
| Minimal risk (Recital 165, Regulation (EU) 2024/1689) | Uses with no specific duty beyond the general rules, where voluntary codes are the only additional layer. | Sorting, filtering, ranking of published material without effect on a person's rights. | Covers the measurement parts of the service. We still apply the limited-risk transparency rules to them, because a customer should not have to know which part produced a line. |
| High risk to rights and freedoms (Article 35, Regulation (EU) 2016/679) | Processing that is likely to result in a high risk to a person's rights, which requires an impact assessment before it starts. | Large scale profiling, systematic monitoring of public space, special category data at scale. | Assessed and documented as not high risk: no special category data, no profiling of individuals, no monitoring, and identity held as a generated code rather than a name. |
The matrix
One risk gets one level, and the level is the product of two judgements made separately: how likely it is within twelve months, and what it would cost the person or the customer if it happened. The scale is fixed so two assessments made a year apart can be compared.
- Likelihood
- Rare: no known occurrence in the sector in the last three years
- Possible: has occurred in the sector, not here
- Likely: expected at least once in twelve months
- Impact
- Limited: inconvenience, corrected within the same day
- Serious: a person or a customer loses money, time or standing
- Severe: rights are affected, or the service cannot be delivered
| Level | Rule |
|---|---|
| Low | Accepted and reviewed at the annual pass. No new control is built. |
| Medium | A named control is required, with an owner and a date. Reviewed each quarter. |
| High | The activity does not ship until the level is reduced. Reviewed monthly until it is. |
Open risk register
The risks we actually carry, scored on the same scale, each with the person accountable and the control that answers it. A risk leaves this table only when the activity behind it stops.
| Risk | Likelihood | Impact | Level | Owner | Control |
|---|---|---|---|---|---|
| A generated line is read as a fact about a named person | Possible | Serious | Medium | Product owner | Source per field, generated text marked, missing data shown as missing |
| A customer uses a ranked list as the sole basis for a decision about a person | Possible | Severe | High | Managing director | Arithmetic shown per line, human decision required in the terms, no automatic rejection |
| Personal data reaches a record that should hold only the generated code | Rare | Serious | Medium | Data protection owner | Quarterly sample review, masking before storage, no free text kept |
| A supplier outside the union processes customer content | Rare | Severe | Medium | Managing director | Union hosting, supplier list with jurisdiction per row, transfer assessed before use |
| A source read by the service is wrong or out of date | Likely | Limited | Medium | Editorial owner | Reading date on every figure, source link kept, checked every third day |
| Service interruption during a customer run | Possible | Limited | Low | Operations owner | Queue with retry, no charge for a failed run, status page |
| A partner key is used by someone other than the partner | Rare | Serious | Medium | Operations owner | Key stored as a fingerprint, rotation by the customer, per key ceilings and expiry |
Risk management as a running process
- Article 9, Regulation (EU) 2024/1689
- Purpose
- A risk assessment written once and filed is worth nothing; the value is in the pass that happens whether or not anything went wrong.
- How it works
- Every new part of the service is scored on the matrix before it reaches a customer
- Medium risks are reviewed each quarter, high risks each month, low risks once a year
- A change that raises a level reopens the assessment instead of being noted as an exception
- The register keeps the score history, so a reduction can be shown and not just claimed
- Hard limit
- No activity at high level is delivered to a customer. Reducing the level is the only route, an accepted high risk is not an option.
- Control point
- Register reviewed at the cadence set by the level; a missed review is visible as a stale date.
Human oversight
- Article 14, Regulation (EU) 2024/1689; Article 22, Regulation (EU) 2016/679
- Purpose
- A result is a basis for a decision, never the decision itself, and the person deciding has to be able to disagree with it.
- How it works
- Every ranked result shows the arithmetic behind each line, so a reviewer can see why it landed where it did
- The assistant hands over to a person on legal, payment and identity questions rather than answering them
- No result rejects an application, closes an account or refuses a customer on its own
- A customer can export the working and challenge a line without asking us for it
- Hard limit
- No decision with a legal or similarly significant effect on a person is produced by the service alone.
- Control point
- Handover rules reviewed at each release that touches them; handovers counted in operations.
Data governance and quality
- Article 10, Regulation (EU) 2024/1689; Article 5(1)(d), Regulation (EU) 2016/679
- Purpose
- A wrong figure costs more than a missing figure, so the service shows what it read and admits what it could not.
- How it works
- Every figure carries the source it came from and the date it was read
- A field that could not be read is shown as missing rather than estimated
- Sources are checked every third day, and a dead source raises an alert instead of ageing quietly
- Only published material is read; nothing behind a login, and nothing about private life
- Hard limit
- The service never fills a gap with a plausible value. Missing stays missing.
- Control point
- Source check runs on a schedule; failures are logged and handled the same day.
Technical robustness and security
- Article 15, Regulation (EU) 2024/1689; Article 32, Regulation (EU) 2016/679
- Purpose
- A service that fails has to fail visibly and cheaply, and a failure must not turn into a data problem.
- How it works
- Ceilings per caller and per day, so one heavy user cannot take the service down for the rest
- Failed runs are retried on a schedule and are not charged to the customer
- Everything stored is encrypted, everything in transit runs over a protected connection
- Operations are monitored continuously and a failure raises an alert to a named owner
- Hard limit
- A failure never results in a partial answer presented as a complete one.
- Control point
- Operations monitoring with alerting; incident records reviewed monthly.
Record keeping and traceability
- Article 12, Regulation (EU) 2024/1689; Article 5(2) and Article 30, Regulation (EU) 2016/679
- Purpose
- Control that cannot be shown afterwards is an opinion, so every run and every access leaves a record.
- How it works
- Each run writes its own record, so a result can be traced back to what produced it
- Each read and export writes time, purpose, jurisdiction and the identity code behind the request
- Records hold counts, outcomes and references, never the text a customer wrote
- Incidents are recorded with time, scope and measures while they are being handled
- Hard limit
- Records are never used to build a picture of an individual's behaviour.
- Control point
- Access records reviewed monthly; the review itself is recorded.
Related pages
ExploreWorldAI is operated by Valkiv Ventures AB (Reg. no. 556995-1311), Kungsgatan 8, 111 43 Stockholm, Sweden. EU-hosted, with data processing assessed against the GDPR. Contact: hello@exploreworldai.com.
Machine-readable summaries for AI agents: /llms.txt and /llms-full.txt.