Saltar al contenido principal
Back to blog
GovernanceAI

Classifying AI Project Risk in Municipalities and Applying Proportionate Controls

July 27, 20264 min readOptimTech
Share:

Why risk classification matters today

Not every artificial intelligence project in a municipality has the same impact or requires the same safeguards. A clear risk assessment makes it possible to apply proportionate controls: security (ENS — Royal Decree 311/2022), data protection (GDPR) and the transparency and mitigation obligations set out in the EU AI Act. This reduces unnecessary costs, speeds up safe deployments and facilitates accountability.

Below is a practical, operational and adaptable protocol for technical teams, legal advisors and procurement officers in local government.

1. Quick operational risk matrix

Evaluate each system along two axes: impact on rights/services and the level of automation in decision-making.

  • Impact on rights/services:

    • High: affects financial grants, access to social services, sanctions or citizens’ rights.
    • Medium: influences resource prioritization, recommendations with administrative consequences.
    • Low: informs or assists internal tasks without decisive effects on people.
  • Degree of automation:

    • Autonomous (decision without effective human review)
    • Assisted (recommendation requiring human reversal)
    • Informational (support or search only)

Resulting classification (example):

  • High risk: high impact + autonomous → apply strict controls (potentially high-risk under the AI Act).
  • Medium risk: medium impact and/or assisted → apply intermediate controls.
  • Low risk: low impact and informational → apply basic controls (registration and transparency).

2. Proportionate controls mapped to practical obligations

Concrete controls by risk level, with practical regulatory references.

High risk (e.g., automated allocation of aid, scoring for access to benefits)

  • DPIA (Data Protection Impact Assessment) and documented justification (GDPR).
  • Technical validation and robustness testing, using real and synthetic datasets to cover edge cases.
  • Versioning and registry of models and datasets; traceability of training and preprocessing.
  • Explicit human oversight defined in procedure (final accountable person and SLA for intervention).
  • Periodic external audits and a technical explanation accessible to affected individuals (transparency in line with the EU AI Act).
  • Enhanced security controls and ENS classification in accordance with Royal Decree 311/2022 (confidentiality and integrity).
  • Incident response plan and public notification if rights are affected.

Medium risk (e.g., prioritization of inspections, recommendations for public works)

  • Simplified DPIA if personal data are involved.
  • Bias testing and monitoring of operational metrics.
  • Minimum decision logging and the ability for competent staff to review decisions.
  • Contracts and SLAs with vendors that require provision of testing evidence.

Low risk (e.g., internal query assistants)

  • Usage logging and transparency notices to staff.
  • Basic security requirements and access controls.
  • Periodic review of outputs to prevent performance degradation.

3. 6-step operational procedure

  1. Quick inventory: catalogue AI systems with owner, users, data types and function.
  2. Initial assessment: apply the matrix above and assign a risk level.
  3. Obligations by level: checklist of technical, legal and operational controls (DPIA, ENS, SLAs, tests).
  4. Testing and validation: define acceptance tests, bias criteria and operational KPIs before going live.
  5. Go-live with supervision: controlled deployment (canary/limited), incident logging and metrics.
  6. Periodic review: re-evaluate risk after functional changes or shifts in the legal context.

4. Practical points for procurement and purchasing

  • Include clauses in tender documents about risk classification, delivery of technical documentation (model cards, data sheets) and support obligations for audits.
  • SLAs should define human review times, access to logs and contingency protocols.
  • Request evidence of ENS / GDPR compliance and the ability to provide DPIAs and robustness tests.
  • Consider options that enable data sovereignty (local processing or in an ENS-compliant environment).

5. Short case examples and quick guidance

  • Information chatbot for opening hours and fees: low risk — controls: user notice, logging and supervised updates.
  • System for prioritizing social benefits: high risk — controls: DPIA, explainability, mandatory human review, external audit.
  • Tool that suggests construction inspections for non-compliance: medium risk — controls: accuracy metrics, quarterly review and internal transparency.

Takeaway / Immediate action

Recommended actions for the next 4 weeks:

  1. Make a minimal inventory of your 10 AI systems (if you have fewer, include all of them).
  2. Apply the risk matrix and label each system (high/medium/low).
  3. For any system labeled high: schedule a DPIA and designate the legal and technical owner within 15 days.

These three steps reduce operational risk and make it easier to comply with ENS, GDPR and the obligations under the EU AI Act. If you need an audited framework and a roadmap, tools like OptimGov Ready can be integrated into this process without replacing your responsibilities: they help structure the assessment and translate it into technical and contractual controls.

If you’d like, I can help turn your inventory into a risk-and-controls checklist tailored to the size of your municipality.