ENEnglish
Language
DeutschDEEnglishENEspañolESFrançaisFRItalianoITPortuguêsPTNederlandsNLΕλληνικάEL
HumanOSE Home

Preliminary risk classification

AI-assisted rental applicant risk assessment (Decision Support) · uc_cx_a01

← Back to use case · Back to dashboard

This classification is a preliminary assessment for governance preparation — not a legal assessment and not a final classification.
This report serves governance and compliance preparation on an evidence basis. It does not constitute legal advice, certification, or a conformity attestation.
Preliminary risk classificationNear high-risk — mandatory human oversight, external legal review recommended
Confidence of the assessmentmedium
ReviewHuman review required
StatusComputed

Reasoning (rule reference)

  • R-HIGH-SCREEN-01 · Screening of natural persons affecting access to an essential service (housing) — near high-risk constellation, mandatory human oversight.
  • R-ELEV-ECON-01 · Economic impact on natural persons — decision support requires human approval of effective steps.
  • R-ELEV-PII-01 · Processing of personal data sources — GDPR principles (purpose limitation, data minimization, data subject rights) must be applied.
  • R-LIM-TRANSPARENCY-01 · Generative or recommending AI function — transparency and labeling obligations must be reviewed.

Rules version: v0.1.0 · Jurisdiction: eu-de · v2

Open legal questions

  • Is access to housing to be classified as an essential private service within the meaning of Annex III of the EU AI Act? External legal review recommended; until clarified it is treated as near high-risk.

Recommended risk mitigations

  • Mandatory human review of every individual-case assessment by a named accountable person.
  • Bias review and monitoring of the assessment logic before and during use.
  • Establish an appeal/correction channel for affected persons (Incident & Appeal Register).
  • Data minimization: process only governance-necessary categories, no copies of raw data.
  • Every effective action (booking, decision, notification) is approved by a human.
  • Role-based access control and audit events for every access to sensitive objects.
  • Label AI-generated content as such; escalation to a human is possible at any time.
  • Obtain external legal review before any real use (near high-risk constellation).

Uncertainty notes

Rule set v0.1 works with internal review heuristics on the EU AI Act, GDPR, Swiss DSG and the UK context. The assessment depends on the completeness of the registry entries and does not replace a legal review.

Evidence events

2026-07-10T11:52:53.678Z · ra_uc_cx_a01_v2_v0.1.0_mrevmf1q2

View governance report →