Pushed by the EU AI Act and a nervous board, your organisation built an AI inventory. Then it put every entry through the same impact assessment and the same approval queue. Within months, teams stopped asking approval and turned to whatever tool got the job done. Uniform control breeds shadow AI. This keynote makes the case for triage: sort every use case, model and vendor-embedded AI feature by the damage it can actually do, then spend your governance effort where that damage sits. A few items need the full apparatus. Most need far less.
• See why “govern everything” fails in practice, as review queues outgrow their approvers and teams quietly move work to unsanctioned tools.
• Build an AI inventory that reaches past in-house models to the AI inside vendor software and the tools staff adopted without asking.
• Practical triage criteria that business and risk people can score together: impact on people, autonomy, data sensitivity, reversibility of errors, scale and regulatory exposure.
• Match each governance tier to its controls, from simple registration for low-risk tools to testing and formal sign-off for the few that can hurt people.
• Know the triggers for re-triage, because a pilot that picks up more users or starts touching personal data belongs in a higher tier.
• Leave with a triage checklist and a tier model you can run against your own AI inventory on Monday morning.