Which AI for which job · part 2 of 6

AI without a language model: the systems that already run the place

Two rows of the map contain no language model: prediction and recommendation; perception, optimisation and simulation. They score credit, flag fraud, read scanned forms, plan routes, and they were doing it before "AI" meant a chat window. What they are, why they are not "less" than the rows below them, what they ask of the platform, and where the law already reaches them.

HokonokenSeptember 2026Reading time: 15 minNot legal advice · Views are my own, not my employer's

Three things to take away

  1. One shape, four jobs. A trained function, or a solver, maps inputs to a score, a label, a rank or a plan. Nothing in it reads a prompt, calls a tool or writes a sentence. The two doors of the first series, the tool gateway and the model gateway, do not exist here. The only door is the wiring of the output.
  2. The wiring sets the level, and the courts already read it that way. The Court of Justice of the EU held in December 2023 that a credit score is an "automated individual decision" in so far as the bank gives it "a determining role". A score at level 1 becomes a decision at level 4 without one line of the model changing.
  3. What this family asks of the platform is a lifecycle, not a gateway. Data with a lineage and a bias check, a registry with versions, serving, monitoring for drift and performance, a rollout with an analysis before promotion, records kept. Parts 5 and 6 of the first series apply to a gradient-boosted classifier exactly as they apply to a language model.

Four jobs, one shape

Prediction. A model trained on past cases emits a probability or a value for a new one: will this loan default, will this customer leave, will this pump fail, is this transaction fraudulent. Tabular data, a target column, a test set, a threshold. This is what most of an organisation's AI was before 2022 and still is.

Recommendation. The same thing with a rank instead of a score: which product, which article, which case to handle first. It is the most deployed predictive system there is and the one least often called AI, because it hides inside a channel. A "next best offer" is a prediction of a click.

Perception. Vision, speech, document capture. The output is a label, a bounding box, a transcript, a structured record extracted from a scanned form. This row is the entrance to many of the rows below it: the document an agent later acts on was read here first, and the error it made travels with the field.

Optimisation and simulation. Routing, scheduling, allocation, forecasting, digital twins. Often no learning at all: a solver takes a human-written objective and constraints and returns a plan. The AI Act draws a line here that is worth knowing. Recital 12 says the definition "should not cover systems that are based on the rules defined solely by natural persons to automatically execute operations", while it does include "logic- and knowledge-based approaches that infer from encoded knowledge". A pure solver with a hand-written objective sits near that line; a twin fed by a trained forecaster, or a learned surrogate of the solver, sits inside. Which side your system is on is a question for counsel. What it needs from the platform is the same either way.

What the four share is the shape. Inputs go in, one output comes out, and nothing in between is free text. There is no prompt to inject, no tool to misuse, no content to filter. By itself the system is at level 1 on the scale from part 1: it informs. What it needs, and what the law asks of it, depends on what the output is wired to.

Why they are not "less"

Three reasons, in increasing order of weight.

They are better instrumented than anything below them. A predictive model has a test set, metrics fixed before training, a threshold someone chose, and a decade of known failure modes: drift, leakage, feedback loops. Article 15(4) of the AI Act names the last one, asking providers of continuously learning systems to reduce "the risk of possibly biased outputs influencing input for future operations (feedback loops)". FINMA's guidance asks for "performance indicators defined in advance". Both are trivial to state for a classifier and an open research problem for free text. The rows below will borrow this discipline, and part 3 will show how little of it survives the move to content.

They are where the high-risk list points. Read Annex III of the AI Act with the map in hand and most of it describes a scoring, ranking or recognition model, not a chatbot. Systems that evaluate "the creditworthiness of natural persons or establish their credit score". Systems used by public authorities "to evaluate the eligibility of natural persons for essential public assistance benefits". Systems "to evaluate and classify emergency calls" or "to establish priority in the dispatching of emergency first response services". Systems used "to analyse and filter job applications", or "to allocate tasks based on individual behaviour or personal traits" or "to monitor and evaluate the performance and behaviour" of workers. Safety components in "road traffic, or in the supply of water, gas, heating or electricity". Remote biometric identification, biometric categorisation, emotion recognition. Every one of those is this row, and the obligations that come with the list, Articles 9 to 15, are written for it.

They are where the prohibitions are. Article 5, in force since 2 February 2025, bans social scoring, "the evaluation or classification of natural persons or groups of persons over a certain period of time based on their social behaviour"; criminal risk assessment "based solely on the profiling" of a person; emotion recognition "in the areas of workplace and education institutions"; and biometric categorisation that infers "race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation". None of those needs a language model. All of them are a trained function with the wrong target column.

The vendor's slide puts these rows at the bottom of a maturity ladder. The regulator put them at the top of the risk list. The regulator read the wiring.

THE LIFECYCLE THE PLATFORM OWES · NO PROMPT, NO TOOL, NO TEXT Data and lineageorigin, labelling, bias check Art. 10(2)(b)(c)(f)S1 · PART 5 Training and testsmetrics fixed in advance Art. 9 · 15(3) · FINMA 2.4S1 · PART 6 Registryversions, aliases, who approved Art. 11 · FINMA 2.2S1 · PART 5 Servingsklearn, XGBoost, ONNX, Triton Art. 15(5)S1 · PART 1, 2 Monitoringdrift, performance, feedback Art. 12 · 15(4) · 72S1 · PART 5 Rolloutanalysis gate, then rollback path Art. 9 · 15(1)S1 · PART 6 retrain: the monitoring result reopens the data stage, and the rollout gate runs again THE SAME OUTPUT, THREE WIRINGS · THE WIRING SETS THE LEVEL The trained functionin: inputs · out: a score, label, rank, planpredictive · recommendation · perception ·optimisation and simulationLEVEL 1 BY ITSELF A person decidesreads the output, decides, actsLEVEL 1 READ Article 14 is met by design: the person is the oversight. The residual risk is 14(4)(b), automation bias: a score that is always followed is a rule with extra steps. A rule decidesthreshold, batch, nobody looksLEVEL 4 COMMIT GDPR Art. 22(1), FADP Art. 21: a decision "based solely on automated processing". CJEU C-634/21, 7 Dec 2023: the score is that decision when the bank gives it "a determining role". Art. 14(4)(d)(e): someone must be able to override and stop. The next system consumes itan extracted field, a label, a planLEVEL: THE CONSUMER'S WRITE The error travels. Art. 10(3) data quality applies where this output becomes another system's input; when that system is an agent, part 5 of this series takes over.
no language modelthe wiring where the law bitesLevels from part 1: 1 informs · 4 acts, reviewed afterWorst action: read · write · commit
Top: the six stages a platform owes a model without a language model, with the AI Act article each stage answers and the part of the first series that describes the layer. The retrain loop is the same rollout gate run again. Bottom: the same output wired three ways. Nothing in the model changes between the first wiring and the second; the level, the worst action and the applicable articles all do.

What the platform owes them

Take the stack of the first series and remove what this row does not use. The MCP gateway goes: there are no tools. The content guardrails go: there is no text. The prompt-injection defences go: there is no prompt. What remains is the lifecycle in the figure, and each stage has an open component and an article.

One thing this row needs that the rows below it rarely do: Article 10(5) lets a provider process special categories of personal data, "to the extent that it is strictly necessary for the purpose of ensuring bias detection and correction", under conditions. Testing a credit or benefit model for disparate impact means holding protected attributes somewhere, under access control, with a deletion date. That is a data-governance decision to take before the first training run, not after the first complaint.

Three organisations, nine jobs

The same three organisations as part 1, none of them real. Each job is placed by its wiring, and the last column is what the wiring brings with it.

JobFamily, levelWorst actionWhat the platform must provideRegulatory line
A public agency scores benefit applications for likely eligibility; a caseworker sees the score with the file.Predictive, 1commit, by the caseworkerLineage of the training data with the bias examination of Art. 10(2)(f) on file; registry entry with risk class; the score and the decision recorded together so 14(4)(b) can be checked later.Annex III 5(a). Article 27: a body governed by public law must do a fundamental rights impact assessment before deployment, describing "the specific risks of harm" and the human oversight measures. Article 5(1)(c) is the boundary: scoring "based on their social behaviour" across unrelated contexts is prohibited, not high-risk.
The same agency captures the paper form with layout analysis and OCR; the fields feed the score.Perception, 1read; a wrong field feeds the scoreParsing pipeline with document versions; per-field confidence kept; a sampled human check with its error rate written down; the extracted record traceable to the page.Not an Annex III row by itself. It is the data stage of a high-risk system: Art. 10(3), data "free of errors and complete", and 10(2)(c), the "cleaning" and "labelling" operations, apply to it through the system it feeds.
The same agency triages emergency calls: a model ranks urgency and the queue follows the rank unless a dispatcher intervenes.Predictive, 4commit: the order of responseDeclared accuracy per class (15(3)); a dispatcher's override surface with every override recorded; a fallback order when the model is down; rollout gate with replayed calls.Annex III 5(d): systems "to establish priority in the dispatching of emergency first response services", high-risk. Article 14(4)(e), the stop button, is the dispatcher's override. Article 27 for the public body.
A bank scores credit applications; below a threshold the application is refused without review.Predictive, 4commitMetrics fixed in advance, an independent review distinct from development (FINMA 2.7), fallback to manual, six-month logs; bias testing with the 10(5) data kept under access control.Annex III 5(b). GDPR Art. 22(1), FADP Art. 21: a decision "based solely on automated processing" with legal effect; the person may obtain human intervention (22(3)). CJEU C-634/21, 7 December 2023: the score itself is that decision when the bank attributes to it "a determining role". Article 27 also applies to 5(b) deployers.
The same bank blocks card transactions the fraud model flags; the customer finds out at the terminal.Predictive, 4commit, reversible on callDrift monitoring against live traffic; a feedback-loop control (15(4)): the model must also see what it blocked; a fast human path to unblock, recorded.Annex III 5(b) excludes systems "used for the purpose of detecting financial fraud": not high-risk. GDPR Art. 22 still applies if the block is solely automated and significantly affects the person; the unblock path is the 22(3) safeguard. NIS2 Art. 21(2) for the bank.
The same bank ranks "next best offers" in the app.Recommendation, 1readRegistry, an offline metric and an online test before promotion, a record of which model version showed which offer.Not an Annex III row. Profiling under GDPR and FADP: information duties and the right to object; FINMA 2.2 inventory entry with a low risk class, so it can be shown to be low.
A manufacturer predicts machine failures from sensors; a planner schedules maintenance.Predictive, 1readDrift monitoring against telemetry; retrain path through the same rollout gate; registry with the sensor set each version was trained on.Outside Annex III. Annex I only if the model is a safety component of a regulated product, a definition Regulation 2026/1744 narrowed in July 2026. Contractual and product-liability regimes do the rest.
The same manufacturer rejects parts on the line from camera images; the line acts on the label.Perception, 4commit: a good part scrapped, a bad part shippedDeclared accuracy per defect class; an edge runtime (Triton-class) with the model version reported; a sampled human re-check of rejects and accepts; an override.Outside Annex III: no natural person is evaluated. Product-safety and quality regimes apply to the part; Art. 15 applies by analogy if you want the auditor to nod. A worker-monitoring variant of the same camera would be Annex III 4(b).
The same manufacturer plans production with a solver fed by a demand forecast; the plan is executed unless a planner edits it.Optimisation, 4write; commit when orders are placedObjective and constraints versioned like a model; the forecast model in the registry; a replay of yesterday's plan as the rollout test; the planner's edits recorded.Recital 12: the solver alone may fall outside the definition of an AI system; the trained forecaster inside it does not. Outside Annex III unless the plan is a safety component of critical infrastructure (Annex III point 2). Counsel decides which side of the recital you are on.

Three of the nine rows are high-risk, and none of the three needs a language model. Two are prohibited-adjacent: the benefit score becomes social scoring the moment it draws on behaviour from unrelated contexts, and the inspection camera becomes worker monitoring the moment it turns towards the person at the line. The platform column barely changes across the nine rows; the regulatory column swings from nothing to Article 27. That is the pattern from part 1, seen from inside one family.

What this row teaches the rows below it

A test set. Metrics fixed before the run. A threshold chosen with the people who own the outcome and written down. A registry that says which version is live and who approved it. A drift monitor that fires before a customer does. A rollout gate that runs the same tests every time. None of this is glamorous, all of it is thirty years old, and the AI Act's Articles 9 to 15 are essentially a description of it.

The rows below have most of the platform and little of the discipline. A language model has no test set in this sense: there is no target column for "a good summary", no threshold to tune, no AUC to declare in the instructions of use. Part 3 is about what replaces them when the output is text a person reads, and about what does not replace them at all. The question that carries over is the one this row answers so easily: when the output is a sentence rather than a number, what exactly is the test?

Next in the series
  1. Part 1The map: who decides, who acts, and how far the system goes on its own. The reference for every part that follows.
  2. Part 3Generating and assisting: generative AI, integrated copilots, small specialised models. The person reads, the risk is the content.
  3. Part 4Answering on your own documents: RAG, agentic RAG, graph RAG. The risk becomes access to sources, and freshness.
  4. Part 5Acting within a perimeter: the AI agent with its tools, and the augmented workflow as the migration path. The risk is the action; the perimeter is outside the model.
  5. Part 6Pursuing a goal with several agents: agentic AI, delegation, intent. The most demanding regime, and the one sold first.
This article is an engineer's reading of public legal texts and public code, checked against the versions and dates given below. It is not legal advice. For a real deployment, read the texts with counsel and with your supervisor's guidance for your sector.
Read, not run. Everything in this series comes from reading public documents and public code at a stated date, not from running them in production. Treat it as a map to test, not a result to trust: the texts are amended, the projects move monthly, and a placement that is right for one organisation's wiring is wrong for another's. Place your own jobs on the map with the people who own them. When something here does not match what you find, tell me, or better, tell the project or the authority concerned: that is the only way a map like this one stays true.

Sources
  1. Regulation (EU) 2024/1689 (AI Act), Article 3(1), Article 5(1), Articles 9 to 15, Article 26(6), Article 27, Article 72, Recital 12, Annex III points 1, 2, 4 and 5; texts read on artificialintelligenceact.eu on 23 September 2026. Application dates as amended by Regulation (EU) 2026/1744, read in part 3 of the first series.
  2. Regulation (EU) 2016/679 (GDPR), Article 22, read on gdpr-info.eu, 23 September 2026. Court of Justice of the EU, press release 186/23 on Case C-634/21, SCHUFA Holding (Scoring), 7 December 2023; the quotation is from the press release, which is not binding on the Court.
  3. Federal Act on Data Protection (FADP, SR 235.1), Article 21; FINMA Guidance 08/2024, sections 2.2 to 2.7; Directive (EU) 2022/2555 (NIS2), Article 21(2). All as read for part 3 of the first series, 22 September 2026.
  4. MLflow Model Registry documentation; release v3.16.1, 17 September 2026. KServe predictive inference runtimes; release v0.20.0, 6 August 2026. Triton Inference Server, release v2.72.0, 31 August 2026.
  5. Evidently, Apache-2.0, release v0.7.23, 11 September 2026. NVIDIA cuOpt, Apache-2.0, release v26.08.00, 6 August 2026. Docling, MIT, LF AI & Data Foundation, release v2.130.0, 22 September 2026. Release tags and dates from each repository's GitHub releases page, 23 September 2026.
  6. Agent stack blueprint, the first series, parts 3, 5 and 6, for the regulatory matrix, the four records and the rollout gate.

Independent work, not affiliated with any regulator, court, standards body, foundation or vendor named. Not legal advice. Product names belong to their owners. Views are my own and do not represent the position of my employer. Text and diagrams: CC BY 4.0; quoted code and documents stay under their own licences.