Four-Tier AI Risk Classification (Hong Kong)
Tags: Frameworks
TL;DR
- Classifies AI systems into Unacceptable, High, Limited, and Low risk with proportionate governance.
- Sets concrete obligations: prohibition, conformity assessment + HITL, transparency + opt-outs + audits, or self-certification.
Why it matters for HK marketers: Your AI use cases must be tiered and controlled accordingly—this determines process overhead, disclosures, and audit readiness.
The framework
- Unacceptable Risk: Uses causing harm, affecting human safety, or subliminal manipulation. Governance: Prohibited; legal liability for development/deployment.
- High Risk: Critical infrastructure contexts (e.g., healthcare diagnostics, autonomous vehicles). Governance: Conformity assessments, human-in-the-loop, real-time monitoring.
- Limited Risk: Moderate societal impact (e.g., recruitment tools, educational AI). Governance: Transparency obligations, user opt-outs, annual compliance audits.
- Low Risk: Minimal risk (e.g., spam filters, creative tools). Governance: Self-certification.
Marketing context
- Campaign tooling: Most creative assistants are likely Low Risk but still need content safety checks.
- Hiring/assessment tools: Classed as Limited Risk—expect consent flows, explanations, and audit trails.
- Prohibited zones: Any AI features that manipulate users subliminally or threaten safety fall into Unacceptable.
4-tier risk framework: Unacceptable, High, Limited, Low.
So what for marketers
Catalogue AI use cases by tier and implement the matching controls before launch; document decisions and evidence to streamline compliance reviews.
← Back to Knowledge Base