AI Risk
A risk level you can explain, factor by factor.
MERIDVAR classifies each AI system and vendor with published, versioned rules applied to stated facts. It is not a score. It records exactly which facts and which rules produced the level.
AI system factors
The level is the highest level any rule reaches.
| Level | Examples of factors that reach it |
|---|---|
| Critical | The organisation classified the system as a prohibited practice under the EU AI Act. Outputs are used in decisions about individuals and no person reviews them. A linked agent or MCP server can take consequential actions and no person approves them. |
| High | Classified by the organisation as high risk under the EU AI Act. Special category data, credentials or secrets can reach it. A linked MCP server has a tool, not blocked, that can delete or run commands. A linked agent can run code, move money, change access or send data outside. |
| Moderate | Personal, financial or confidential data can reach it. Outputs are used without human review. Access is not limited to named people. A linked agent or MCP server has no completed review, or is not in the inventory. |
| Low | A completed assessment in which no factor applies. |
Without a completed assessment there is no classification. The system reads "Not assessed", never "Low".
Principles
Four properties a risk officer can rely on.
Unknown is not safe
Where "yes" would trigger a factor, "unknown" triggers one at Moderate.
Deterministic
The same facts and rules version always give the same result. Each classification stores the facts it read and their hash.
Never edited
Classifying again creates a new record. The earlier one is kept and marked as superseded.
Goes out of date
When an assessment is reopened or a fact changes, the classification says so and says which facts changed.
Third party AI risk
Vendors are classified on what they do with your data.
A vendor due diligence assessment feeds its own rules. The result gates the approval of every AI system that depends on that vendor.
| Level | Vendor factors |
|---|---|
| Critical | The vendor trains on the organisation's data and there is no data processing agreement. |
| High | The vendor trains on the organisation's data. No data processing agreement. No contract. |
| Moderate | Any of those is unknown. No independent report or subprocessor list provided. No notice before model changes. No exit and deletion terms. |
Overrides
An administrator can override. The record keeps both levels.
- An override needs a reason and can carry evidence.
- The record keeps the level the rules computed beside the new level.
- An override can raise what is required and never lower it. Lowering a system with personal data to Low still requires a privacy review.
- Nothing is inferred from traffic. An observation never makes a system riskier or safer.
See MERIDVAR refuse a request on your own network.
A working session with the founder. We install the appliance with you, route a test request and walk through the evidence it leaves behind.