How Does an AI Use Case Get Through Approval Cleanly?
Last reviewed: 23 July 2026
Five questions determine whether an AI use case gets approved: personal data, automated decisions about people, EU AI Act risk class, external foundation model, and human review capability. Following the tree cleanly means approval in 5 business days instead of 5 months — governance becomes an accelerator, not a hurdle.
Which five questions determine approval?
This decision tree guides the approval process for every new AI use case. It does not replace legal advice — it gives orientation for the internal process, step by step, no detours.
Does the use case process personal data? Yes → go to question 2. No → no GDPR review needed, go directly to question 3.
Does the system make automated decisions about people? Yes → GDPR Art. 22 review, check explicit consent or an exemption. No → standard data protection impact assessment, go to question 3.
Does the use case fall into an EU AI Act high-risk category? Yes → high-risk process: conformity assessment, technical documentation, human oversight. No → go to question 4.
Does the use case use an external foundation model (GPAI)? Yes → check GPAI deployer obligations: usage policy, output monitoring, transparency duty. No → go to question 5.
Can a human review and override the results? Yes → the use case can be approved, obtain governance board sign-off. No → build in human oversight or do not approve the use case.
How serious is the risk really?
AI risks differ fundamentally from classic IT risks: they are emergent — arising from model behavior, not configuration errors — and they change through learning processes. A static assessment is not enough; continuous monitoring is mandatory.
From low quality to a critical data leak
Critical form: a data breach in the AI system or a critical data leak.
From sporadic hallucinations to an autonomous bad decision
Critical form: systematic errors or an autonomous bad decision without oversight.
From documentation gaps to an AI Act violation
Critical form: a high-risk use case without review or a direct EU AI Act violation.
From adoption gaps to a critical system outage
Critical form: vendor lock-in without an exit strategy or a critical system outage.
The tree is deliberately designed as a repeatable process, not a case-by-case review: every new use case goes through the same five questions, every answer is logged, every approval is traceable afterward. That's exactly what separates a governance process that builds trust from an ad-hoc decision that can't be explained at the next audit.
The underestimated risk: prompt injection is the most-used attack vector against AI agents in 2026. An attacker embeds manipulative instructions in data the agent processes — causing it to perform unintended actions. For agents with transaction authority, e.g. for payments or orders, this isn't a theoretical risk but an operational one. Mitigations: input validation, output sandboxing, minimal agent permissions.
Glossary
Get every use case through approval in 5 business days
The Compliance Center automatically runs every new use case through the decision tree and documents the result in an auditable way.
Start the AI Governance Check →FAQ
Does this decision tree replace legal advice?
No. It gives orientation for the internal process. The final legal assessment, especially for high-risk cases, always belongs with Legal or external counsel.
What if a use case touches several questions at once?
The tree is still run through sequentially — each yes-answer can trigger additional obligations that stack rather than replace each other.
Why is prompt injection especially critical for agents?
Because agents with transaction authority carry out real actions — a successful injection turns from a text risk into an operational one.
How realistic is 5 business days to approval?
Realistic if roles and the decision tree are clearly defined beforehand. Without both, the same process often takes months because every question gets re-discussed.
Daniel Ostner
From Chapter 4 of the Enterprise AI Guide book
Related guides
Building AI Governance
Solid AI governance runs on three levels: strategic, tactical, operational. A minimal model with 5 roles and 6 core decisions is enough to get started.
EU AI Act for Companies
Four risk classes, staggered deadlines through December 2027, and why AI-powered recruiting is almost always high-risk — the Digital Omnibus status for companies.