Which AI for which job · part 2 of 6
AI without a language model: the systems that already run the place
Two rows of the map contain no language model: prediction and recommendation; perception, optimisation and simulation. They score credit, flag fraud, read scanned forms, plan routes, and they were doing it before "AI" meant a chat window. What they are, why they are not "less" than the rows below them, what they ask of the platform, and where the law already reaches them.
HokonokenSeptember 2026Reading time: 15 minNot legal advice · Views are my own, not my employer's
Three things to take away
- One shape, four jobs. A trained function, or a solver, maps inputs to a score, a label, a rank or a plan. Nothing in it reads a prompt, calls a tool or writes a sentence. The two doors of the first series, the tool gateway and the model gateway, do not exist here. The only door is the wiring of the output.
- The wiring sets the level, and the courts already read it that way. The Court of Justice of the EU held in December 2023 that a credit score is an "automated individual decision" in so far as the bank gives it "a determining role". A score at level 1 becomes a decision at level 4 without one line of the model changing.
- What this family asks of the platform is a lifecycle, not a gateway. Data with a lineage and a bias check, a registry with versions, serving, monitoring for drift and performance, a rollout with an analysis before promotion, records kept. Parts 5 and 6 of the first series apply to a gradient-boosted classifier exactly as they apply to a language model.
Four jobs, one shape
Prediction. A model trained on past cases emits a probability or a value for a new one: will this loan default, will this customer leave, will this pump fail, is this transaction fraudulent. Tabular data, a target column, a test set, a threshold. This is what most of an organisation's AI was before 2022 and still is.
Recommendation. The same thing with a rank instead of a score: which product, which article, which case to handle first. It is the most deployed predictive system there is and the one least often called AI, because it hides inside a channel. A "next best offer" is a prediction of a click.
Perception. Vision, speech, document capture. The output is a label, a bounding box, a transcript, a structured record extracted from a scanned form. This row is the entrance to many of the rows below it: the document an agent later acts on was read here first, and the error it made travels with the field.
Optimisation and simulation. Routing, scheduling, allocation, forecasting, digital twins. Often no learning at all: a solver takes a human-written objective and constraints and returns a plan. The AI Act draws a line here that is worth knowing. Recital 12 says the definition "should not cover systems that are based on the rules defined solely by natural persons to automatically execute operations", while it does include "logic- and knowledge-based approaches that infer from encoded knowledge". A pure solver with a hand-written objective sits near that line; a twin fed by a trained forecaster, or a learned surrogate of the solver, sits inside. Which side your system is on is a question for counsel. What it needs from the platform is the same either way.
What the four share is the shape. Inputs go in, one output comes out, and nothing in between is free text. There is no prompt to inject, no tool to misuse, no content to filter. By itself the system is at level 1 on the scale from part 1: it informs. What it needs, and what the law asks of it, depends on what the output is wired to.
Why they are not "less"
Three reasons, in increasing order of weight.
They are better instrumented than anything below them. A predictive model has a test set, metrics fixed before training, a threshold someone chose, and a decade of known failure modes: drift, leakage, feedback loops. Article 15(4) of the AI Act names the last one, asking providers of continuously learning systems to reduce "the risk of possibly biased outputs influencing input for future operations (feedback loops)". FINMA's guidance asks for "performance indicators defined in advance". Both are trivial to state for a classifier and an open research problem for free text. The rows below will borrow this discipline, and part 3 will show how little of it survives the move to content.
They are where the high-risk list points. Read Annex III of the AI Act with the map in hand and most of it describes a scoring, ranking or recognition model, not a chatbot. Systems that evaluate "the creditworthiness of natural persons or establish their credit score". Systems used by public authorities "to evaluate the eligibility of natural persons for essential public assistance benefits". Systems "to evaluate and classify emergency calls" or "to establish priority in the dispatching of emergency first response services". Systems used "to analyse and filter job applications", or "to allocate tasks based on individual behaviour or personal traits" or "to monitor and evaluate the performance and behaviour" of workers. Safety components in "road traffic, or in the supply of water, gas, heating or electricity". Remote biometric identification, biometric categorisation, emotion recognition. Every one of those is this row, and the obligations that come with the list, Articles 9 to 15, are written for it.
They are where the prohibitions are. Article 5, in force since 2 February 2025, bans social scoring, "the evaluation or classification of natural persons or groups of persons over a certain period of time based on their social behaviour"; criminal risk assessment "based solely on the profiling" of a person; emotion recognition "in the areas of workplace and education institutions"; and biometric categorisation that infers "race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation". None of those needs a language model. All of them are a trained function with the wrong target column.
The vendor's slide puts these rows at the bottom of a maturity ladder. The regulator put them at the top of the risk list. The regulator read the wiring.
What the platform owes them
Take the stack of the first series and remove what this row does not use. The MCP gateway goes: there are no tools. The content guardrails go: there is no text. The prompt-injection defences go: there is no prompt. What remains is the lifecycle in the figure, and each stage has an open component and an article.
- Data and lineage. Article 10(2) asks for documented "data collection processes and the origin of data", the "relevant data-preparation processing operations, such as annotation, labelling, cleaning", and an "examination in view of possible biases". Article 10(3) asks that data sets be "relevant, sufficiently representative, and to the best extent possible, free of errors and complete". For a scanned form, the perception stage is part of the data stage of whatever consumes it. Docling, an LF AI & Data project under MIT licence, v2.130.0 of 22 September 2026, does the parsing, layout and OCR on the open side; what it does not do is tell you how often it is wrong on your forms. That is a sample and a person.
- Training and tests. Article 9 asks for testing "against prior defined metrics"; Article 15(3) for "the levels of accuracy and the relevant accuracy metrics" declared in the instructions of use; FINMA 08/2024 §2.4 for tests of "accuracy, robustness and stability and, if necessary, bias". A test set held out from training, metrics chosen before the run, a threshold chosen with the business and written down. Part 6 of the first series ran this as an Argo Rollouts analysis before a model is promoted; the same AnalysisTemplate holds an AUC or a precision-at-threshold as easily as a garak probe.
- Registry. MLflow's model registry, "a centralized model store, set of APIs and a UI designed to collaboratively manage the full lifecycle of a machine learning model", v3.16.1 of 17 September 2026: registered model, version, alias, tags, and the run that produced each version. This is the inventory FINMA §2.2 asks for and the technical documentation of Article 11, if you put the risk class and the approver in the tags and keep it there.
- Serving. KServe v0.20.0 of 6 August 2026 lists serving runtimes for scikit-learn, XGBoost, LightGBM, PMML, MLflow models and Triton; Triton Inference Server v2.72.0 of 31 August 2026 takes TensorRT, PyTorch, ONNX, OpenVINO and RAPIDS FIL, which is where a vision model or a forest with a latency budget ends up. NVIDIA's cuOpt, Apache-2.0, v26.08.00 of 6 August 2026, is the solver side: linear, mixed-integer and vehicle-routing problems as a service. Article 15(5) applies to all of it, "resilient against attempts by unauthorised third parties to alter their use, outputs or performance", and names data poisoning, model poisoning and adversarial examples. The model is a file; the registry that says which file is running is the control.
- Monitoring. Drift is the failure this row has that the others do not have in the same form: the world moved, the model did not, and nothing errored. Evidently, Apache-2.0, v0.7.23 of 11 September 2026, computes drift and performance reports for tabular data; part 5 of the first series had the four records and the six-month retention of Article 26(6); Article 72's post-market monitoring plan is this stage written down. What no tool computes for you is the second half of Article 15(4): whether the model's own decisions are feeding its next training set. A fraud model that only sees the transactions it let through is learning from its own blind spot.
- Rollout and retrain. A retrained model is a new model. Part 6 of the first series applies without change: two versions behind one route, an analysis that must pass before traffic moves, the old version kept warm for rollback, a person who promotes and is recorded. That the model weighs 30 megabytes rather than 30 gigabytes makes the mechanics cheaper, not the gate lighter.
One thing this row needs that the rows below it rarely do: Article 10(5) lets a provider process special categories of personal data, "to the extent that it is strictly necessary for the purpose of ensuring bias detection and correction", under conditions. Testing a credit or benefit model for disparate impact means holding protected attributes somewhere, under access control, with a deletion date. That is a data-governance decision to take before the first training run, not after the first complaint.
Three organisations, nine jobs
The same three organisations as part 1, none of them real. Each job is placed by its wiring, and the last column is what the wiring brings with it.
Three of the nine rows are high-risk, and none of the three needs a language model. Two are prohibited-adjacent: the benefit score becomes social scoring the moment it draws on behaviour from unrelated contexts, and the inspection camera becomes worker monitoring the moment it turns towards the person at the line. The platform column barely changes across the nine rows; the regulatory column swings from nothing to Article 27. That is the pattern from part 1, seen from inside one family.
What this row teaches the rows below it
A test set. Metrics fixed before the run. A threshold chosen with the people who own the outcome and written down. A registry that says which version is live and who approved it. A drift monitor that fires before a customer does. A rollout gate that runs the same tests every time. None of this is glamorous, all of it is thirty years old, and the AI Act's Articles 9 to 15 are essentially a description of it.
The rows below have most of the platform and little of the discipline. A language model has no test set in this sense: there is no target column for "a good summary", no threshold to tune, no AUC to declare in the instructions of use. Part 3 is about what replaces them when the output is text a person reads, and about what does not replace them at all. The question that carries over is the one this row answers so easily: when the output is a sentence rather than a number, what exactly is the test?
Next in the series
- Part 1The map: who decides, who acts, and how far the system goes on its own. The reference for every part that follows.
- Part 3Generating and assisting: generative AI, integrated copilots, small specialised models. The person reads, the risk is the content.
- Part 4Answering on your own documents: RAG, agentic RAG, graph RAG. The risk becomes access to sources, and freshness.
- Part 5Acting within a perimeter: the AI agent with its tools, and the augmented workflow as the migration path. The risk is the action; the perimeter is outside the model.
- Part 6Pursuing a goal with several agents: agentic AI, delegation, intent. The most demanding regime, and the one sold first.
This article is an engineer's reading of public legal texts and public code, checked against the versions and dates given below. It is not legal advice. For a real deployment, read the texts with counsel and with your supervisor's guidance for your sector.
Read, not run. Everything in this series comes from reading public documents and public code at a stated date, not from running them in production. Treat it as a map to test, not a result to trust: the texts are amended, the projects move monthly, and a placement that is right for one organisation's wiring is wrong for another's. Place your own jobs on the map with the people who own them. When something here does not match what you find, tell me, or better, tell the project or the authority concerned: that is the only way a map like this one stays true.
Sources
- Regulation (EU) 2024/1689 (AI Act), Article 3(1), Article 5(1), Articles 9 to 15, Article 26(6), Article 27, Article 72, Recital 12, Annex III points 1, 2, 4 and 5; texts read on artificialintelligenceact.eu on 23 September 2026. Application dates as amended by Regulation (EU) 2026/1744, read in part 3 of the first series.
- Regulation (EU) 2016/679 (GDPR), Article 22, read on gdpr-info.eu, 23 September 2026. Court of Justice of the EU, press release 186/23 on Case C-634/21, SCHUFA Holding (Scoring), 7 December 2023; the quotation is from the press release, which is not binding on the Court.
- Federal Act on Data Protection (FADP, SR 235.1), Article 21; FINMA Guidance 08/2024, sections 2.2 to 2.7; Directive (EU) 2022/2555 (NIS2), Article 21(2). All as read for part 3 of the first series, 22 September 2026.
- MLflow Model Registry documentation; release v3.16.1, 17 September 2026. KServe predictive inference runtimes; release v0.20.0, 6 August 2026. Triton Inference Server, release v2.72.0, 31 August 2026.
- Evidently, Apache-2.0, release v0.7.23, 11 September 2026. NVIDIA cuOpt, Apache-2.0, release v26.08.00, 6 August 2026. Docling, MIT, LF AI & Data Foundation, release v2.130.0, 22 September 2026. Release tags and dates from each repository's GitHub releases page, 23 September 2026.
- Agent stack blueprint, the first series, parts 3, 5 and 6, for the regulatory matrix, the four records and the rollout gate.
Independent work, not affiliated with any regulator, court, standards body, foundation or vendor named. Not legal advice. Product names belong to their owners. Views are my own and do not represent the position of my employer. Text and diagrams: CC BY 4.0; quoted code and documents stay under their own licences.