Skip to Content

Sort your AI by what it decides

Not by what it is
October 8, 2026 by
Luis Roberto Aguirre Salazar

Once a mid-sized company has listed the AI it uses, the list tends to be long and flat. A writing assistant sits next to a feature that screens job applications. A meeting summariser sits next to a tool that suggests discounts for key accounts. Everything appears on the same page, in the same format, with the same weight.

A flat list invites one of two reactions. The first is to govern everything with the same intensity, which produces rules nobody can follow and teams that quietly work around them. The second is to govern nothing seriously, because no single item looks urgent enough to justify the effort. Both end in the same place: the uses that could genuinely hurt someone receive no more attention than the ones that could not.

In my view, the step that matters most after the inventory is not writing a policy. It is sorting. And the criterion for sorting is not the technology, the vendor or the price, but what each use decides and what happens when it gets that decision wrong.

This is the first in a series of practical pieces on AI accountability for mid-sized companies. Each one takes a single practice and looks at what it involves when it is done, rather than described. Sorting comes first because every other practice depends on it: it is what tells a company where to spend attention it does not have in unlimited supply.

The wrong ways to sort

The most common instinct is to sort by technology: generative tools in one group, predictive tools in another, the newest and most sophisticated at the top. It feels rigorous, but it says nothing about consequences. A very capable model drafting internal emails carries little risk. A simple scoring rule embedded in a CRM, ranking which customers get a follow-up call or which accounts are flagged for a credit hold, can affect real people every day without anyone thinking of it as AI.

Sorting by vendor reputation has the same blind spot. A well-known provider can supply a tool that is used for something sensitive, and a modest one can supply a tool used for something trivial. Sorting by cost is weaker still: the price of a licence tells you about the budget, not about the harm an error can cause.

What these approaches share is that they classify the tool. The thing worth classifying is the use.

Two questions that do most of the work

A useful sort does not need a scoring model. Two questions, answered honestly for each use, carry most of the weight.

Does the output change something for a specific person, or does it inform someone who then decides?

A tool that rejects an application, sets a price for a named customer or flags an employee, acts on a person. A tool that drafts a report a manager will read, and rewrite informs a decision without making it. The line is not always clean, because a recommendation that is accepted every time behaves like a decision. That pattern is worth noticing on its own.

If the output is wrong, can someone notice and undo it before it causes harm?

An inaccurate meeting summary is usually caught by the people who were in the meeting. A candidate filtered out by a screening feature never appears in front of anyone who could notice the mistake. Errors that stay visible are cheap; errors that disappear quietly are not.

Put together, the two answers produce a sort that most leadership teams can agree on quickly. Uses that act on people and whose errors are hard to see or reverse go to the top. Uses that inform internal work and whose errors are easy to catch go to the bottom. Everything else falls in between, and that middle group is where most of the useful discussion happens.

Classify the use, not the tool

The same tool can sit in two very different places. A writing assistant used to draft an internal memo belongs near the bottom of the list. The same assistant used to draft the letter that tells a candidate they were not selected, or a customer that their claim was declined, belongs much higher, because the output now reaches a person directly and carries a decision with it.

This is why the sorted list works best with one line per use rather than one line per product. It also explains why the list cannot be done once and filed. When a team finds a new use for an existing tool, or a vendor switches on a new feature inside software the company already pays for, the list has gained an entry, even though nothing new was purchased.

What the sort is for

Sorting is not an end. Its purpose is to make proportionality possible. The uses at the top deserve a named owner, a deliberate point where a person reviews the output before it takes effect, and a record of what was decided and why. The uses at the bottom need a short, clear rule and an occasional look, not a committee.

Without the sort, every one of those controls is either applied everywhere, which is unaffordable, or nowhere, which is untenable. With it, a company can say plainly which few uses receive the most care, and why those and not others. That is also an explanation it can give to a client, an employee or a partner who asks how the company uses AI, without having to improvise one.

My recommendation is to keep the exercise deliberately simple: one line per use, the two answers next to it, and an explicit agreement at leadership level about which uses sit at the top. That short list is where accountability effort should go first. The next pieces in this series take those controls one at a time, starting with how to design the point where a person reviews what the system produced.

Rhisco designs risk models, control artefacts and AI governance architecture to ensure positive outcomes when companies deploy AI. If your list has uses at the top without a clear owner, let’s talk: rhisco.com/services

This article was co-created with the assistance of artificial intelligence under strict supervision, editing, and verification of our team.


Your Data Isn't Good or Bad.
It is fit or unfit for a question.