WorkflowIT & Data

AI Use-Case Intake & Risk Classifier

AI use-case intake and risk classification, every conclusion tied to its clause

Every new AI idea classified against the rules in minutes, each conclusion tied to its clause.

See one case, screen by screen ↓
demo9.1sfor six agents to check 23 clauses and classify a new AI idea on seven dimensions
target6daysmedian from intake to a board decision, every classification cited
target75%of new AI ideas need only AI literacy; the office spends its time on the rest
target412usesin one AI inventory, each with its tier, conditions and review date
The problem

Why a new AI idea waits five weeks for an answer

A QC lab head wants an assistant to triage deviations. Before anyone can say yes, the AI governance office has to work out where it sits under the EU AI Act, whether it touches a GMP decision under draft Annex 22, what personal data goes in, what the vendor may do with it, and who has to review what. Each of those answers lives in a different regulation, a different policy section and a different reviewer’s head.

So the sponsor fills in a 40-question form, gets re-interviewed when the answers do not match the design, and waits for a monthly committee. The design document says one thing, the intake form another, and nobody has time to cross-check the vendor’s terms. The ideas that need real scrutiny queue behind the many that only need AI literacy — and a generative model quietly setting a GxP outcome is easy to miss.

estimated≈35daysfrom intake to a decision, by form and committee
estimated40questionson the intake form, then re-interviews when answers and documents disagree
Where an AI idea’s days go, from intake to decision (days)estimated
By hand35 days
With the solution6.1 days
  • Sponsor answering questions9 → 1.6 d
  • Classifying against the rules0 → 0.1 d
  • Reviewers confirming14 → 2.3 d
  • Waiting for the AI review board12 → 2.1 d

Median days per step, as shown on the working solution’s dashboard for the last 30 days. The “before” split is estimated.

How it works

How an AI idea moves

Six specialist agents interview the sponsor, read the documents, classify the risk and plan the reviews; the AI review board decides.

What comes in
Idea inAnswers + documents · design, data flow, vendor model
Agents at work
Intake interviewerplain-word questions
Then
Design & vendor document readerevery fact with its page
Then
AI Act classifier
GxP & credibility classifier
Privacy, IP & security classifier
Then
Assessment planner & routerowners · due dates
A person decides
AI review boarddecides, with conditions
What comes out
Cited classification
Reviews with owners
AI inventory entry
One case, step by step

One AI idea, from intake to the inventory

Dr. Maya Chen, head of the QC laboratory at Plant 3 in Leiden, wants an assistant that triages about 40 deviations a month. Here is what happens to AIU-2041, screen by screen, in the working solution.

  1. 01Morning

    Every AI idea, on one risk landscape

    Dana Okafor · Lead, AI governance office

    Dana opens the solution to 10 open AI ideas, 4 waiting for her and a board meeting on Thursday with 3 decisions on the agenda. The landscape places each idea by EU AI Act category and GxP impact: emotion scoring under Prohibited, candidate screening under High-risk, the patient chatbot under Transparency. The deviation triage assistant sits in the tray marked “Not classified yet”.

    Regulatory clock: “Q4 2026 · Annex 22 final text expected · 6 decisions to re-check.”

  2. 02Submitted Oct 4

    Five plain-word answers and four documents

    Dr. Maya Chen · Head of QC laboratory, Plant 3

    The intake interviewer asked Maya five questions. Her answers: the assistant would read new deviation reports and suggest minor, major or critical; “ideally it sets the class in the QMS so the investigation starts faster”; no personal data; Nimbrel Cloud AI’s hosted model, already used for meeting notes. She attached the design and data flow, the vendor’s model card, the vendor’s enterprise terms and the QA-114 deviation SOP.

    “Intake complete — ready to classify. 5 answers and 4 documents. Six agents check them against 23 clauses in the rule library.”

  3. 03One click

    Six agents classify, each step in view

    The agents

    Dana presses “Run classification”. The document reader pulls 23 fields from the four documents, each with its page. The AI Act classifier finds minimal risk — not an Annex III use, 93 %. Then the warnings: the GxP classifier sees a critical GMP use with a generative model, the privacy classifier finds employee names in the inputs and the vendor’s no-training option not elected, and the consistency check catches the sponsor’s answer contradicting the design.

    Consistency check: “‘No personal data’ disagrees with design §3.1 · 2 redesigns proposed.”

  4. 049.1 seconds later

    “Not allowed as designed” — and exactly why

    GxP & credibility classifier

    Section 2.3 of the design says the assistant sets the deviation class in the QMS record. QA-114 says the class decides investigation depth, whether a CAPA is required and whether batch disposition is held. Draft Annex 22 §1 keeps generative models out of critical GMP applications, and the company’s AI policy 6.5 says generative AI must not make a GxP decision. Every clause is one click from its highlighted passage.

    The agents never approve a generative model in a critical GMP use — they propose redesigns: suggestion only (about 6 weeks), a static validated classifier (about 4–6 months), or send it back.

  5. 05Redesign chosen

    Suggestion only — a QA reviewer decides

    Dana Okafor · Lead, AI governance office

    Dana picks the recommended redesign and the classifiers re-check. GxP criticality moves from critical GMP to non-critical GMP with a person in the loop; model risk on the FDA influence × consequence grid drops from high to medium; personal data becomes “employee data · minimised”; vendor terms become “approved with no-training option”. Each change shows what it was before.

  6. 06Planned

    Six assessments with owners and due dates

    Assessment planner & router

    The planner turns the classification into the work: an AI validation plan for Sam Patel in IT Quality, a security review of hosting, region and connectors for Omar Haddad, the no-training option for Hannah Brooks in procurement, a privacy note and name removal for Lena Ortiz — no DPIA, with the reason recorded — AI literacy training for 12 QA reviewers, and a monitoring plan for agreement, overrides and drift. Five conditions of approval are written alongside.

    Condition 1: “Suggestion only — the assistant never sets the class.”

  7. 07Thursday’s board

    Approved with conditions, signed

    Dana Okafor · Board chair

    The approval route shows the sponsor, the agents, IT Quality and Security done, and the AI review board next. Dana opens the approval, reviews the five conditions, and signs with her password. The meaning of her signature is recorded with it, and the sponsor gets a note: approved as a suggestion-only assistant, QA reviewers decide every deviation.

    “Meaning: I approve this use case with the conditions above.”

  8. 08Registered

    Into the AI inventory, with its review date

    Assessment planner & router

    Only after the signed decision does the planner write inventory entry REG-0413: owner Dr. Maya Chen, enhanced review, the hosted model and its vendor, five conditions, next review Jan 7, 2027 and then quarterly, monitoring of agreement and override rates and of model version changes. The six assessments go to their owners.

    “Approved and signed · inventory entry REG-0413 · 6 assessments sent.”

  9. 09When a rule moves

    Annex 22 goes final — what changes?

    Dana Okafor · Lead, AI governance office

    Annex 22 is still a draft, with the final text expected in Q4 2026. Dana previews the re-check: six decisions cite the draft, open use cases and inventory entries alike, and all six are re-classified by the same agents. None changes tier; the adverse-event capture and the patient chatbot each gain an operator training record. Nothing changes until she confirms and the sponsors are told.

    “Nothing changes until you confirm.”

  10. 10Every month

    How fast ideas get an answer

    Dana Okafor · Lead, AI governance office

    In the last 30 days: 24 ideas received, 19 decided, a median of 6.1 days from intake to decision against a target of 7, and 14 % sent back for missing documents or contradictions. 18 of the 24 were minimal risk under the AI Act — so the office spends its time on the few that are not.

Who it’s for

Built for everyone who says yes to an AI idea.

The same idea, seen by the sponsor and the reviewers who carry it — what their week looked like, and what it looks like now.

DO
Dana OkaforLead, AI governance office
Board chair
Before
Reads intake forms that do not match the design, chases reviewers, and takes every idea to a monthly committee.
Now
Opens a cited classification with the conflicts already found, picks a redesign, and signs with the conditions on the record.
MC
Dr. Maya ChenHead of QC laboratory, Plant 3
Sponsor
Before
Fills in a long form in legal terms and waits weeks to hear whether her idea is even allowed.
Now
Answers five questions in plain words, sees the classification build as she answers, and gets a “yes if” with the reasons.
SP
Sam PatelIT Quality · computerised systems
GxP reviewer
Before
Works out GMP criticality and the validation approach from scratch for each idea.
Now
Confirms a GxP conclusion that cites draft Annex 22 and policy 6.5, and receives the validation and monitoring plans as assessments with due dates.
LO
Lena OrtizPrivacy counsel
Privacy reviewer
Before
Trusts the sponsor’s “no personal data” or reads every design herself.
Now
Sees where the answer and the design disagree, and gets a DPIA pre-filled from the intake whenever health data is involved.
OH
Omar HaddadInformation security architect
Security reviewer
Before
Learns about a new AI vendor or connector after it is in use.
Now
Gets a security review of hosting, region and connectors routed to him, and sees every use of a model re-checked when its vendor changes the default version.
Built on the engine

6 agents. Each with one job, and hard limits.

Six specialist agents interview the sponsor, read the documents, classify the risk and plan the reviews; the AI review board decides.

Intake interviewer

Talks to the sponsor in plain words, asks only the questions that change the classification, and requests the design and vendor documents.

  • Never promises approval
  • No legal advice to the sponsor — routes questions to the office
  • Stops after 12 questions
Design & vendor document reader

Reads architecture, data-flow and vendor model documents and pulls model type, hosting, data fields, training terms and who acts on the output — each with its page.

  • Cites the page for every field
  • Marks “not stated” — never assumes
AI Act classifier

Checks Article 5 practices, Annex I and Annex III, Article 50 transparency and deployer duties.

  • Cites a clause for every conclusion
  • Below 80 % confidence the dimension shows as undecided and a reviewer is asked
GxP & credibility classifier

Decides GxP criticality against draft Annex 22, GAMP AI and the company AI policy, and model risk with the FDA influence × consequence grid.

  • Flags generative or adaptive models in any critical GMP use
  • Proposes compliant redesigns, never approves
Privacy, IP & security classifier

Finds personal and special-category data, automated decisions, confidential data leaving the company and vendor training terms.

  • Health data always gets a DPIA proposed
  • Reads the contract system, never changes it
Assessment planner & router

Turns the classification into the required assessments with owners and due dates, routes reviews, builds the board agenda and writes the inventory entry after the decision.

  • Inventory entry only after a signed decision
  • Board decision always by a person
AI review board

Decides, with conditions on the record. The agents propose; a named person decides.

Ask in plain words

Ask about any AI idea, rule or decision

The governance office can ask in plain words — or tell it what to change. Answers cite the clause or the passage they rest on.

Why can’t the deviation assistant go ahead as designed?

Because as designed it would set the deviation class in the QMS — and the class decides investigation depth, CAPA and batch disposition. That is a critical GMP use, and draft Annex 22 keeps generative models out of critical GMP applications. Our own policy says generative AI must not make a GxP decision. Yes if: it only suggests and a qualified QA reviewer decides every deviation — then it is non-critical with a person in the loop.

Which use cases are high-risk or prohibited?

Two open ideas. Sales-call emotion scoring infers employees’ emotions at work — banned since Feb 2025. Candidate screening is Annex III point 4(a); deployer duties start Dec 2, 2027 and the DPIA is under way.

Add a rule: agents that email people outside the company need a security review

Added to the routing rules and switched on: an agent that sends email or messages outside the company goes to security review by Omar Haddad. It applies to new intakes now; today it would route 1 open idea — the patient-support chatbot, which emails co-pay forms. The change is versioned and in the audit trail.

What changes when Annex 22 is final?

Annex 22 is still a draft; the final text is expected in Q4 2026. Six of our decisions cite it, mostly §1 on where generative models may be used. If the final keeps human-in-the-loop for non-critical use, none changes tier; two gain an operator-training condition — adverse-event capture and the patient chatbot. When the final text is loaded, the rule change re-check runs these and asks you to confirm.

Every screen

The working solution, as it ships.

13 screens from the working solution, on its sample data. Pick one to see it large.

HomeEvery open AI idea placed by EU AI Act category and GxP impact, what needs the governance lead, and the regulatory clock.
The sponsor’s intakePlain-word questions, one at a time; each answer updates a live classification and what happens next.
The use caseThe intake conversation and attachments on the left, the seven-dimension sheet in the middle, the source passage on the right.
Agents at workSix steps in view — answers read, documents read with their pages, three classifiers, and a consistency check.
Not allowed as designedA generative model would make a critical GMP decision; the clauses behind it and three ways forward.
Re-checked after the redesignEach dimension with its new conclusion, what it was before, its clause and its confidence.
Required assessmentsValidation, security, vendor terms, privacy, AI literacy and monitoring — each with an owner, a due date and the clause it comes from.
Approve with conditionsThe board chair checks each condition and signs; the meaning of the signature is recorded with it.
The AI inventory entryOwner, tier, model, conditions, next review date and monitoring — written after the signed decision.
Rule libraryEach framework clause by clause, the passage the agents check against, and the use cases that cite it.
Rule change re-checkA preview of what the final Annex 22 text would change, decision by decision, before anyone confirms.
The dashboardIdeas received and decided, the EU AI Act mix, where the days go, and ideas by department.
Reviewers and routing rulesWho confirms each dimension, the routing rules the agents follow, the board slot and the confidence threshold.
Governance

Built for AI governance: cited, reviewed, signed, on the record.

Every conclusion cites its clauseEach of the seven dimensions — AI Act category, GxP criticality, model type, regulatory decision risk, personal data, IP and vendor terms, human oversight — cites the clause or document page it rests on and opens the highlighted passage.
Low confidence means “undecided”Below the confidence threshold a dimension is shown as undecided and the named reviewer is asked. Each dimension carries its confidence score.
Answers checked against the documentsWhen a sponsor’s answer contradicts the design or the vendor’s terms, the conflict is flagged on the answer and on the dimension — never silently resolved.
A person decides, and signsThe AI review board decides every idea outside self-service. The chair approves with her password, the conditions and the meaning of the signature recorded together.
No inventory entry without a signatureThe entry — owner, tier, model and version, conditions, monitoring and next review date — is written only after a signed decision.
Rule changes re-check every decisionThe rule library is versioned clause by clause. When a clause changes, every decision that cites it is re-classified, and nothing moves until the owner confirms. Every agent step and human decision is on the use case’s activity trail.
Configuration

Your reviewers and your routing rules

Who confirms what, which findings go where, and how fast — set on one screen, with new routing rules described in plain words.

SettingDefaultChoose from
GxP criticality and validationSam PatelAnyone on the team list
Personal data and DPIALena OrtizAnyone on the team list
Security, hosting and connectorsOmar HaddadAnyone on the team list
Board decision and signatureDana OkaforAnyone on the team list
Target: intake to decision7 working daysSet in working days
AI review boardThursday 15:00 CETThursday · Wednesday 15:00 CET
Show a dimension as “undecided” below80 % confidence75 · 80 · 85 %
Routing rules6 rules onSwitch each on or off · add in plain words
Connections

Works with the rules and records you already keep

The sponsor’s intakeplain-word answers about use, data, model and scale
Design and vendor documentsarchitecture, data flow, model cards, security questionnaires
Rule libraryEU AI Act, draft Annex 22, GAMP AI, FDA draft guidance, GDPR
Your AI policy and QMS procedurespolicy sections and procedures such as deviation management
Contract systemvendor terms, read only
AI inventoryevery approved use, its owner, tier, conditions and review date
What it changes

The difference, in numbers.

Every figure is labelled: a target the solution is built to, an estimate, a typical published result, or a proven one.

target
6days
median from intake to a board decision, every classification cited
Before≈ 5 weeks
With agents6.1 days
target
75%
of new AI ideas need only AI literacy; the office spends its time on the rest
minimal risk under the AI Act
target
412uses
in one AI inventory, each with its tier, conditions and review date

“demo” = seen in the working solution, on its sample data · “target” = the design goal, measured in the live solution · “estimated” = our estimate · Sources: EU AI Act (Regulation (EU) 2024/1689) · draft EU GMP Annex 22 (2025) · FDA draft guidance on AI to support regulatory decision-making (2025) · GDPR (Regulation (EU) 2016/679). People, companies and vendors named on this page are characters in the working solution.

Questions

What AI governance offices ask us.

What is AI use-case intake?

The front door for every new AI idea in the company: the sponsor describes what the AI would do, the governance office classifies the risk, the right reviewers assess it, a board decides, and the approved use is registered in the AI inventory. This solution runs that path with six agents doing the interviewing, document reading, classification and planning, and people deciding.

How does it classify an AI use case under the EU AI Act?

The AI Act classifier checks the idea against Article 5 prohibited practices, Annex I and Annex III high-risk uses, Article 50 transparency duties and deployer duties, and cites the clause behind its conclusion with a confidence score. In the working solution, sales-call emotion scoring is classified prohibited under Article 5(1)(f) and candidate screening high-risk under Annex III point 4(a).

How does it decide GxP criticality?

The GxP & credibility classifier asks whether the AI decides a GMP outcome, using draft EU GMP Annex 22, the GAMP AI guide summary and your AI policy, and scores model risk on the FDA draft guidance’s influence × consequence grid. A generative model in a critical GMP use is flagged as a conflict, with redesigns proposed — for example, suggestion only with a qualified reviewer deciding.

Does it decide whether an AI idea is approved?

No. The agents classify, cite and plan; reviewers confirm their dimensions; the AI review board decides and the chair signs. The agents never promise approval, never approve a redesign themselves, and write the inventory entry only after a signed decision.

What happens when a sponsor’s answers do not match the documents?

The document reader pulls each field from the design and vendor documents with its page, and a consistency check compares them with the answers. In the working solution, the sponsor answered “no personal data” while the design sends analyst names and reviewer initials; the conflict is flagged and name removal becomes a condition.

Which assessments does it plan?

Whatever the classification calls for: a DPIA when health or other special-category data is involved, an AI validation plan sized to GxP criticality, a credibility assessment plan for high model risk, a security review of hosting and connectors, a vendor terms review, AI literacy training and a monitoring plan — each with an owner and a due date.

What happens when a regulation or our AI policy changes?

The rule library is versioned clause by clause. When a clause changes, the rule change re-check re-classifies every decision that cites it, shows what would change, and waits for the owner to confirm before sponsors are told. A vendor model version change triggers a re-check of every inventory entry that uses that model.

How long does it take to go live?

The Agentic Solution Engine builds and deploys it from your requirements — your AI policy, your reviewer matrix, the frameworks you follow and a sample of past AI ideas — and it goes live once every quality gate has passed. We will walk you through it on your own AI ideas first.

See it on
your AI ideas.

We’ll run AI Use-Case Intake on a sample of your own AI ideas, against your own AI policy.