Consequence Tier and Gate Path
Last reviewed · content updated
AdvancedWhat you'll learn
~22 min- Apply the principal-basis test and the presumed-high-impact list to a named system
- Assign an AI consequence tier from purpose, exposure, and reversibility that a second reviewer can reproduce
- Route every registered system to one of four exits, including the one where it does not deploy
What it is: the AI consequence tier — a written determination, from purpose, exposure, and reversibility, of how much goes wrong when this system is wrong, reproducible by a second reviewer — and the gate path the tier selects, including the exit where the system does not deploy.
What it buys: gates sized to consequence instead of to the vendor’s confidence or the loudest sponsor, and a defensible answer to “why did this one get the light path” — the record shows the test applied, not the mood in the room.
What to fund: reviewer hours for a second reproduction of every high-impact determination, and the gates the tier selects — or the decision to stop. A tier whose gates are unfunded is a promise, not a control.
Before the detail — Artifact: a tier determination a second reviewer can reproduce. Status of what follows: binding where M-25-21 applies; common baseline elsewhere.
Prompt first: tier all ten, mark every exit
Here is our register [paste Lesson 1.2's YAML] and our tier rubric(where the register lacks an exposure or reversibility fact, writeUNKNOWN - NEEDS-OWNER; never infer one)[paste: the principal-basis test, the presumed-high-impact list,purpose, exposure, reversibility].
For EACH of the ten systems, draft a tier determination record: - PRINCIPAL BASIS: is the output the principal basis for a decision with legal, material, binding, or significant effect on a person? Quote the register field you relied on - PRESUMED LIST: does the use case fall in a presumed category? Name it or write "none" - PURPOSE / EXPOSURE / REVERSIBILITY: one line each from the register; REVERSIBILITY names what it takes to undo one wrong output and a week of them - PROPOSED TIER and PROPOSED EXIT: light path / full gate path / stop / safe-discontinuation exit - with the one field that decides it - REPRODUCTION: what a second reviewer needs in front of them to reach the same tier without talking to you
Mark every determination NEEDS-OWNER. You are drafting the form,not making the call: the owner and a second reviewer decide, andwhere a federal frame applies, the agency does.The agent’s value is consistency — the same rubric applied the same way to ten systems, with the field it relied on quoted each time. Its limit is that a tier is a determination somebody is accountable for, and the record exists so a second person can reproduce it. The agent makes the inputs visible; it does not get a vote.
High-impact is determined, not elected
M-25-21 (OMB’s April 2025 memo on agency AI use — OMB being the White House budget office that binds agencies) defines high-impact AI in §5 by a test, not a checkbox: the output serves as a principal basis for a decision or action with legal, material, binding, or significant effect in six areas — civil rights and privacy; access to education, housing, insurance, credit, or employment; access to critical government services; health and safety; critical infrastructure and public safety; strategic assets. §6 adds a presumed list — use cases such as employment decisions and the safety-critical functions of critical infrastructure — that are high-impact unless someone rebuts the presumption in writing.
The rebuttal goes to the CAIO (the agency’s Chief AI Officer), and nobody elects a tier by not asking, and a vendor’s opinion of its own product does not enter the test.
The clock already ran: M-25-21 gave agencies 365 days to document the minimum practices for high-impact use — April 3, 2026 — after a CAIO within 60 days and a governance board within 90. A covered system running today without its determination is late, not early.
The commercial starting practice, plus the input it lacks
Commercial tiering starts from materiality as purpose times exposure — what the model is used for, times how much rides on it — the way SR 26-2 and OCC Bulletin 2026-13 (the revised US banking model-risk guidance, April 2026) size it for the models they still cover. Data Products 1.2 (a separate training in this series) asked the same questions — name consumer, decision, failure cost — and DevSecOps 1.3’s rule holds: route before you build.
Add one input the banking frame lacks: reversibility. The outage predictor’s wrong ranking is undone by dispatchers next shift. An agent that files, pays, or emails takes actions individually small and collectively unbounded — a week of wrong outputs is a queue of them, each already acted on. Gartner predicted in June 2025 that more than 40% of agentic AI projects will be canceled by the end of 2027; a tier should be cheap to assign and honest enough that cancellation is an available exit.
Call the result the AI consequence tier, and say what it is not. Not a FIPS 199 impact level (the federal system-impact rating for confidentiality, integrity, and availability): a Low system can make a high-consequence decision. Not a data classification: MU-AI-009 reads public comments and its bucket counts go into a regulatory filing. Not a support tier, and not model capability — a small classifier can be high-impact while a frontier model drafting meeting notes is not.
The record carries the three inputs and the two tests, so a second reviewer reaches the tier from the record alone; where the two disagree, the disagreement is written down, not averaged. Two calculations, kept separate: whether M-25-21 applies and the use is high-impact is a determination the agency makes; the house tier — purpose × exposure × reversibility — is Meridian’s own, and applies to all ten systems. The gates that apply are the union of what each demands.
Four exits
The tier selects the gate set your policy defines, and every system leaves this lesson through one of four doors:
Neither federal high-impact nor materially consequential by the house tier → light path. A register entry, a confirmed owner, periodic review. Most of Meridian’s ten — the meeting-notes generator, the code assistant — end here, honestly.
High-impact, gates funded → full gate path. Modules 2 through 5: evidence packet, evaluation on your own data, attack evidence, the signed record.
High-impact, gates not funded → stop. MU-AI-006 ranks the top 50 applicants per posting; those below rank 50 are never reviewed by a human. The output is the principal basis for an employment decision — a presumed case. If Human Resources (M. Sato) will not fund the evaluation, the subgroup slices, the appeal path, and the halt procedure, the system does not run. Not “runs while the gates are scoped.” The vendor’s fairness statement is a claim Module 2 will read, not a gate.
Already running, never inventoried → safe discontinuation, or a pilot exemption or waiver. M-25-21 §4(a)(i) is blunt: high-impact use that cannot meet the minimum practices must be safely discontinued, and the memo offers no grace period — continued federal use needs a pilot exemption (limited scale and duration; certified and centrally tracked by the CAIO; opt-in or opt-out where possible; the practices applied where practicable) or a waiver (Lesson 5.4 — who may sign one). Safely matters — a halt that strands the people in the queue is its own harm, so discontinuation is planned, not abrupt. Commercially the house practice is a remediation deadline the risk acceptor sets, with a stop condition. MU-AI-006 entered here and, unfunded, resolves to stop.
A pilot is not a fifth door: M-25-21 carves out pilots under four conditions, taught in Lesson 5.4, and a pilot is not production under another name.
The stop exit is the cheapest decision in this training — contract and revenue risk removed for the price of a signature — and every other exit costs hours.
The seam: from questionnaire to determination
The commercial starting practice is a tiering questionnaire that yields a level and a review-due date, in a spreadsheet or a governance platform. The federal delta: high-impact is definition-driven, carries a presumed list, and is rebutted only in writing to the CAIO; the agency, not the vendor and not the program office, determines applicability. The handoff artifact is the tier determination record — inputs, the two tests, the presumed-list check, the second reviewer’s reproduction, the date, the exit selected. What is not equivalent: federal tiers are defined by effect on rights and safety, not financial exposure. A model moving a great deal of money with no person at the end of it may fall outside the federal test; a free add-on ranking applicants is squarely inside it. Export commercial tiers into a federal determination unchanged and you get both wrong.
Stop and escalate when the owner of a presumed-high-impact system proposes to keep it running while the gates are “being scoped.” The clock decides, not the owner: the question goes to the risk acceptor who will sign the record and, where the federal frame applies, to the CAIO.
MU-AI-006 ranks applicants; those below rank 50 are never seen by a human. Human Resources says the vendor's model is 'certified fair' and asks for the light path. What is the correct exit?
Practice status — among organizations running AI systems that affect people or operations, commercial and federal
| Practice | Status | Also called |
|---|---|---|
| principal-basis test (M-25-21 s5) | required where the memo applies; strong optional elsewhere | decision-criticality test |
| materiality as purpose x exposure | common baseline | model materiality rating |
| reversibility as a tier input | emerging | blast radius / rollback cost |
| presumed-high-impact list with written rebuttal | required where the memo applies; strong optional elsewhere | default-high list with an exception record |
| second reviewer reproduces the tier from the record | strong optional | four-eyes tiering |
| tier determination record | common baseline | risk-tier questionnaire output |
| safe discontinuation of non-compliant high-impact use | required where the memo applies (no grace period; pilot exemption or waiver are the only continuations) | mandatory decommission on non-compliance |
| remediation deadline with a stop condition | house practice (commercial); emerging elsewhere | time-boxed risk acceptance |
Scale: required | common baseline | strong optional | reference-shop (seen only at organizations that publish their own practice) | emerging
Key takeaway
High-impact is determined by a test — is this output the principal basis for a decision with legal, material, binding, or significant effect — and by a presumed list rebutted only in writing; nobody elects out by not asking. Commercial tiering starts from purpose times exposure and adds reversibility, because agents make wrong outputs cumulative. The result is the AI consequence tier — not a FIPS 199 level, a data classification, a support tier, or model capability — which a second reviewer must reproduce from the record. The tier selects the gates, and four exits follow: light path, full gate path, stop, or the safe-discontinuation exit; the resume screener stops. Lesson 1.4 turns to what the gate path produces: the release decision itself.
LEADERSHIP DECISION fund the gates the tier selects or sign the stop - the one thing not on offer is a high-impact system running on a promisePRACTITIONER ACTION run the rubric over every registered system with the agent; record the inputs and the exit; get a second reviewer to reproduce each high-impact tier from the record aloneSUCCESS MEASURE zero high-impact systems running without a written determination and a funded gate path - the finding the first assessor otherwise writes