Articles

Which AI Workloads Should You Build? A Risk-Based Prioritization Framework

AI Governance & Security Playbook

Part 3 — AI Workload Identification & Risk Triage

Key Insights

  • Workload Identification and risk classification are dependent functions viewed from two perspectives. You cannot responsibly approve a workload without understanding its risks and the controls needed to manage them.
  • Workload adoption must account for two interdependent processes. 1) A top-down business nomination process that identifies the workloads you want, and 2) A bottom-up shadow-AI discovery assessment that identifies the workloads that already exist. With roughly 45% of employees already using AI on corporate devices, discovery is not optional [1].
  • Data readiness is the primary feasibility constraint. A high-value workload using ungoverned data is not yet feasible and will be error-prone. Because AI governance is inseparable from data governance, the quality, lineage, and access controls of the underlying data determine whether an idea can proceed.
  • Risk tiers should drive control intensity. Well-defined risk tiers should be the organizing principle and gating factor for AI workload adoption. Tier assessments must include: 1) human-in-the-loop thresholds, 2) observability, 3) impact assessments, and 4) red-teaming. Assessment rigor should scale with the assessed risk of the workload rather than be applied uniformly.
  • Frameworks already exist; NIST AI RMF, ISO/IEC 42001, the EU AI Act, multinational deployment guidance, and the OWASP agentic taxonomy. The discipline is applying them consistently, not inventing new ones.
Introduction

Most enterprises believe they have multiple AI use cases that will contribute to top-line revenue growth and bottom-line profitability. The problem is that many organizations lack a disciplined way to choose among them and to assign the appropriate level of control to each. They also cannot create a suitable set of metrics to evaluate success. Candidate workloads arrive from every business function, and many are already running informally through consumer accounts and embedded SaaS features. This creates risk of inadvertent disclosure of sensitive company and personal information [2]. Without a methodology, the organization defaults to two failure modes:

  • Promising workloads stall due to a lack of decision.
  • Risky ones proceed without any assessment.

Decision Frameworks: Choosing What and How to Build

These frameworks guide the selection and design of a workload once it has been discovered and characterized. 

  • CISA four-step model — the cleanest end-to-end scaffold for the whole intake decision, moving from understanding AI to securing its deployment [3]. 
  • NIST AI RMF (Map function) — purpose-built for identifying and contextualizing candidate workloads before commitment [4]. 
  • Value/feasibility portfolio screening — a two-axis prioritization technique; the value axis is supported by AI-maturity revenue evidence and the feasibility axis by data-readiness assessment [5]. 
  • Build vs. buy vs. internal model — a sensitivity-driven architectural rule: crown-jewel workloads favor an internally deployed model; routine workloads favor an enterprise-tier vendor [6, 7]. 
  • The “Agents Rule of Two” / lethal-trifecta test — a design gate for any agentic candidate that combines access to sensitive data, exposure to untrusted content, and outbound communication [2, 8]. 

Risk Frameworks: Classifying and Controlling

These frameworks classify a workload’s risk and determine the controls it must carry into production. 

  • EU AI Act risk tiers — the primary classification decision that triggers conformity assessments, human oversight, and registration for high-risk systems [9]. 
  • ISO/IEC 42001 impact assessment and risk register — the certifiable system of record for each workload assessed risk and treatment [10]. 
  • NIST AI RMF (Measure and Manage) — for assessing likelihood and impact and prioritizing mitigations once a workload is mapped[4]. 
  • DPIA and FRIA — the GDPR Article 35 Data Protection Impact Assessment and the EU AI Act Article 27 Fundamental Rights Impact Assessment, triggered for personal data and high-risk workloads, respectively [11, 12]. 
  • OWASP Top 10 for Agentic Applications (2026) — the risk taxonomy to apply specifically to agentic workloads [13]. 

A Five-Phase Identification Methodology 

Phase 1 — Discover and Inventory Candidates

Populate the AI Inventory and Use-Case Register from two directions simultaneously. A top-down business intake invites functions and leaders to nominate use cases aligned with business objectives. A bottom-up shadow-AI discovery sweep, inspecting DNS and proxy egress, applying Cloud Access Security Broker tooling, and analyzing browser telemetry, surfacing the workloads employees are already running (most of them through personal, consumer-tier accounts). The bottom-up half matters because you cannot triage what you cannot see; discovery converts invisible usage into governable inventory before you plan the workloads you want.

Phase 2 — Characterize Each Candidate

For every register entry, capture the attributes that drive downstream decisions: the data classes the workload touches (mapped to the organization’s AI-sensitive classification scheme); the consequences of its outputs (informational versus consequential to a person’s rights, money, health, or safety); its autonomy level (assistive chat, retrieval-augmented, or tool-using agent); its user population; and whether it is internal- or customer-facing. This is precisely the Map function of the NIST AI RMF, which identifies and contextualizes each candidate within organizational objectives and its sociotechnical setting before any commitment is made. Characterization is also where data classification is applied, because the data a workload consumes is the strongest predictor of its risk tier.

Phase 3 — Screen for Value and Feasibility

Score each characterized candidate on two axes: business value and feasibility. Value can be anchored in evidence that governance-mature organizations (“AI Masters”) achieve materially higher revenue growth, providing a defensible basis for prioritization rather than enthusiasm alone. Feasibility, however, is dominated by data readiness: quality, lineage, and access controls. A high-value workload built on ungoverned data is not yet feasible, and the register should record it as blocked, pending data remediation, rather than as approved. This phase also frames the first architectural decision: build, buy, or run internally. Routine productivity workloads argue for an enterprise-tier vendor; workloads touching crown-jewel IP argue for an internally deployed model whose data never leaves the perimeter. 

Phase 4 — Classify by Risk Tier

Evaluate each surviving candidate using the risk-classification frameworks. This is where a promising idea becomes either a minimal-risk productivity tool or a high-risk deployment requiring conformity work. The EU AI Act’s four tiers (unacceptable, high, limited, minimal) are the primary classification, and ISO/IEC 42001 provides a certifiable place to record each workload’s assessed risk and treatment [14]. Two instrument-level assessments are triggered here: a DPIA for personal data and a FRIA for high-risk agentic systems. For agentic workloads specifically, apply the OWASP Top 10 for Agentic Applications — goal manipulation, tool misuse, excessive agency, and memory poisoning. Because the AI Act and GDPR overlap but aren’t interchangeable, workloads touching personal data need both [12]. 

Phase 4 identifies the required assessments and the baseline control level. The following triage summary translates classification into action and should be recorded for each workload in the register.

 

The path should be conservative: an unacceptable-tier workload should be rejected outright, and a high-risktier workload cannot enter production until its conformity documentation, impact assessments, human-oversight design, and initial red-team pass are complete and recorded. Lower-risk tiers have lighter controls, but every workload, regardless of tier, has an accountable owner and a place in the register.

Phase 5 — Gate Through Governance

The AI Steering Committee approves, defers, or rejects each candidate, assigns an accountable owner via RACI mapping, and sets control levels proportional to the tier. For agentic workloads, apply the “Agents Rule of Two” [8] as a hard design gate: an agent becomes dangerous when it simultaneously has access to sensitive data, exposure to untrusted content, and the ability to communicate externally. The design must eliminate at least one of these before proceeding. Architectural mitigations, such as the CaMeL pattern, which separates trusted control instructions from untrusted data, can raise the ceiling on what is safely permissible [15]. The gate also establishes human-in-the-loop checkpoints for high-consequence actions, consistent with Singapore’s Model AI Governance Framework for Agentic AI [16]. It establishes a red-teaming cadence proportional to risk, drawing on the NIST adversarial ML taxonomy [17] and Microsoft’s distinction between safety and security red teaming [18]. The approved workload re-enters the register with its tier, owner, and control set recorded as the artifact the board reports against. 

Mapping the Pipeline to the Frameworks

The table below aligns each phase of the methodology with the decision and risk frameworks that guide and govern it. Identification and risk classification proceed together, not in sequence. 

Conclusion

Identifying AI workloads and triaging their risk is not two projects but one. The methodology in this installment sequences the frameworks the organization should already recognize:  

  • Discovery and characterization on the front end 
  • Classification and governance gating on the back end 

No workload should reach production without an assessment tier, an owner, and a proportionate set of controls. The frameworks are not novel; the discipline of applying them consistently and recording the results in a living register is what separates a governed AI program from an ungoverned one. 

This is a capability to be maintained, not a one-time exercise. As new workloads arrive, models drift, and the regulatory timeline advances, the register and the triage path should be revisited on a defined cadence, keeping the organization’s answer to “which AI, and how controlled?” current with both its ambitions and its obligations. 

Not sure which of your AI workloads should be prioritized — or which ones your data readiness can actually support? Our AI Opportunity Roadmap is a no-cost, expert-led diagnostic that identifies and prioritizes your highest-value AI use cases and scores your Data Governance Readiness, giving you the Phase 2 and Phase 3 groundwork this article describes, done for you.

 

References 

  1. Verizon, 2026 Data Breach Investigations Report. 2026: https://www.verizon.com/business/resources/T961/reports/2026-dbir-data-breach-investigations-report.pdf.
  2. Ferrara, E., Why AIs Biggest Threat to Enterprise IP Is Convenience Not Malice, in Green Leaf Insights, M. Miner, Editor. 2026, Green Leaf Group: https://greenleafgrp.com/insights/why-ais-biggest-threat-to-enterprise-ip-is-convenience-not-malice/.
  3. Agency), C.C.a.I.S., et al., Principles for the Secure Integration of Artificial Intelligence in Operational Technology, U.S.C.a.I.S. Agency, et al., Editors. 2025, CISA: https://www.cisa.gov/sites/default/files/2026-01/joint-guidance-principles-for-the-secure-integration-of-artificial-intelligence-in-operational-technology-508cV2.pdf.
  4. NIST. AI RMF Core – AIRC. 2023  [cited 2026 August]; Available from: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/.
  5. Joutey, S.A., Value vs Feasibility Matrix: A Step-by-Step Guide, in Fygurs Blog. 2025: https://www.fygurs.com/blog/value-vs-feasibility-matrix-guide.
  6. Mutlow, N., Build Or Buy?, in Forbes. 2020, Forbes: https://www.forbes.com/sites/servicenow/2020/12/11/build-or-buy/.
  7. Scale, Enterprise Guide: Build vs. Buy, in Scale Guides. 2026, Scale: https://scale.com/guides/build-vs-buy.
  8. Meta, Agents Rule of Two: A Practical Approach to AI Agent Security, in Meta AI. 2025, Meta: https://ai.meta.com/blog/practical-ai-agent-security/.
  9. Commission, E. AI Act: Shaping Europe’s digital future. 2026  [cited 2026 May 30]; Available from: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai.
  10. (ISO/IEC), I.S.O., ISO-42001:2023 — Information technology — Artificial intelligence — Management system. 2023, International Standards Organization: https://www.iso.org/standard/42001.
  11. Union, E., Article 27 Fundamental Rights Impact Assessment for High-Risk AI Systems. 2024, European Union: https://artificialintelligenceact.eu/article/27/.
  12. Parliament, E.U., Article 35 GDPR – Data protection impact assessment. 2016, European Union: https://gdpr-info.eu/art-35-gdpr/.
  13. OWASP, OWASP Top 10 for Agentic Applications 2026. 2026: https://genai.owasp.org/download/52117/?tmstv=1765059207.
  14. Chaudhary, A., Use ISO 42001 & NIST AI RMF to Help with the EU AI Act, in Industry Insights. 2025, Clod Security Alliance: https://cloudsecurityalliance.org/blog/2025/01/29/how-can-iso-iec-42001-nist-ai-rmf-help-comply-with-the-eu-ai-act.
  15. Tallam, K. and E. Miller Operationalizing CaMeL Strengthening LLM Defenses for Enterprise Deployment. 2025.
  16. Authority, I.M.D. Model AI Governance Framework for Agentic AI. 2026  [cited 2026 August]; Available from: https://www.imda.gov.sg/assets/97c3917f-a5b5-4eb0-83d6-5a626d0cced4.pdf.
  17. Vassilev, A., et al., NIST Trustworthy and Responsible AI NIST AI 100-2e2025: Adversarial Machine Learning A Taxonomy and Terminology of Attacks and Mitigations, NIST, Editor. 2025: https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-2e2025.pdf.
  18. Microsft. Planning red teaming for large language models LLMs and their applications. Learn Microsoft 2026  [cited 2026 August]; Available from: https://learn.microsoft.com/en-us/azure/foundry/openai/concepts/red-teaming.