← All guides
Guide · Governance & Law

How Does an AI Use Case Get Through Approval Cleanly?

Last reviewed: 23 July 2026

Five questions determine whether an AI use case gets approved: personal data, automated decisions about people, EU AI Act risk class, external foundation model, and human review capability. Following the tree cleanly means approval in 5 business days instead of 5 months — governance becomes an accelerator, not a hurdle.

Which five questions determine approval?

This decision tree guides the approval process for every new AI use case. It does not replace legal advice — it gives orientation for the internal process, step by step, no detours.

1

Does the use case process personal data? Yes → go to question 2. No → no GDPR review needed, go directly to question 3.

2

Does the system make automated decisions about people? Yes → GDPR Art. 22 review, check explicit consent or an exemption. No → standard data protection impact assessment, go to question 3.

3

Does the use case fall into an EU AI Act high-risk category? Yes → high-risk process: conformity assessment, technical documentation, human oversight. No → go to question 4.

4

Does the use case use an external foundation model (GPAI)? Yes → check GPAI deployer obligations: usage policy, output monitoring, transparency duty. No → go to question 5.

5

Can a human review and override the results? Yes → the use case can be approved, obtain governance board sign-off. No → build in human oversight or do not approve the use case.

How serious is the risk really?

AI risks differ fundamentally from classic IT risks: they are emergent — arising from model behavior, not configuration errors — and they change through learning processes. A static assessment is not enough; continuous monitoring is mandatory.

Data risks

From low quality to a critical data leak

Critical form: a data breach in the AI system or a critical data leak.

Model risks

From sporadic hallucinations to an autonomous bad decision

Critical form: systematic errors or an autonomous bad decision without oversight.

Compliance risks

From documentation gaps to an AI Act violation

Critical form: a high-risk use case without review or a direct EU AI Act violation.

Operational risks

From adoption gaps to a critical system outage

Critical form: vendor lock-in without an exit strategy or a critical system outage.

The tree is deliberately designed as a repeatable process, not a case-by-case review: every new use case goes through the same five questions, every answer is logged, every approval is traceable afterward. That's exactly what separates a governance process that builds trust from an ad-hoc decision that can't be explained at the next audit.

Anti-pattern

The underestimated risk: prompt injection is the most-used attack vector against AI agents in 2026. An attacker embeds manipulative instructions in data the agent processes — causing it to perform unintended actions. For agents with transaction authority, e.g. for payments or orders, this isn't a theoretical risk but an operational one. Mitigations: input validation, output sandboxing, minimal agent permissions.

Glossary

Decision TreeDPIAGPAI DeployerPrompt Injection

Get every use case through approval in 5 business days

The Compliance Center automatically runs every new use case through the decision tree and documents the result in an auditable way.

Start the AI Governance Check →

FAQ

Does this decision tree replace legal advice?

No. It gives orientation for the internal process. The final legal assessment, especially for high-risk cases, always belongs with Legal or external counsel.

What if a use case touches several questions at once?

The tree is still run through sequentially — each yes-answer can trigger additional obligations that stack rather than replace each other.

Why is prompt injection especially critical for agents?

Because agents with transaction authority carry out real actions — a successful injection turns from a text risk into an operational one.

How realistic is 5 business days to approval?

Realistic if roles and the decision tree are clearly defined beforehand. Without both, the same process often takes months because every question gets re-discussed.

DO

Daniel Ostner

From Chapter 4 of the Enterprise AI Guide book

View book →

Related guides