Not every AI system deserves the same level of scrutiny. A spam filter and an algorithm that decides whether someone qualifies for a bank loan simply do not carry the same consequences if they go wrong. That distinction is the entire logic behind AI risk classification in Nepal — a system that sorts AI applications into tiers based on how much harm they could cause, and then applies proportionally stricter rules to the riskiest ones. This article breaks down how Nepal's framework is expected to work, what counts as a high-risk AI system in Nepal, and what it practically means if you build or deploy AI tools in the country.
Why Governments Classify AI Systems by Risk Level
Regulating every AI application with the same rulebook creates two problems at once: it smothers low-stakes innovation (a chatbot that recommends restaurants doesn't need the same paperwork as a medical diagnostic tool) while potentially under-regulating genuinely dangerous use cases. Risk-based classification solves both problems by tying the intensity of oversight to the actual potential for harm. The European Union pioneered this approach at scale with its AI Act, which sorts systems into "unacceptable," "high," "limited," and "minimal" risk categories — and Nepal's own policy architecture draws visibly on this same logic, adapting it to local priorities like financial inclusion, data sovereignty, and public-service delivery.
How Nepal's Framework Is Expected to Work
The National AI Policy 2082 does not spell out a fully finished, article-by-article risk taxonomy the way the EU AI Act does. Instead, it mandates that a governance framework be prepared to classify AI systems by risk level and mitigate risks accordingly, with the National AI Centre — acting under the guidance of the AI Regulation Council — responsible for assessing existing and emerging risks and preparing corresponding action plans. In other words, the classification system itself is a deliverable the government has committed to producing, not a finished rulebook that already exists in full detail.
What we do already have is a real, sector-specific preview of how this is likely to play out. In late 2025, Nepal Rastra Bank — a member of the AI Regulation Council — released a draft AI guideline for commercial banks, development banks, finance companies, microfinance institutions, and payment service providers and operators. That draft explicitly adopts a risk-based classification system, and it gives us the clearest working definition of "high risk" that Nepal has produced so far: a system qualifies as high-risk if it carries potential for serious harm, has wide-ranging impact, involves minimal human oversight, poses risks to individual rights, or relies on sensitive personal data. Expect the broader national framework to echo this same logic once it is finalised.
High-Risk vs Low-Risk AI: Practical Examples
Based on the criteria above and the sectoral priorities named throughout the national policy, here is a realistic picture of how AI use cases are likely to be sorted:
- Likely high-risk: AI-driven credit scoring and loan approval, algorithmic fraud detection tied to account freezes, AI in medical diagnosis and treatment recommendations, AI used in hiring and employment decisions, and AI systems supporting critical infrastructure such as power grids or payment rails.
- Likely limited-risk (transparency-focused): customer-facing chatbots, AI-generated marketing content, and deepfake or synthetic-media tools — all of which are expected to face disclosure requirements so users know they are interacting with or viewing AI-generated output.
- Likely minimal-risk: internal productivity tools, spam filters, basic recommendation engines, and routine back-office automation that does not materially affect an individual's rights, finances, or safety.
- Likely prohibited or unacceptable: AI used for government-run social scoring of citizens and manipulative or exploitative systems designed to bypass a person's free will — categories explicitly flagged as off-limits in comparable frameworks that Nepal's policy draws inspiration from.
What This Means for Developers and Companies
If your AI system is likely to fall into the high-risk bracket — and this is especially relevant for fintech companies building credit, payments, or fraud-detection tools — the emerging expectations already visible in the Nepal Rastra Bank draft guideline give a strong indication of what compliance will look like:
- Board-level accountability: senior management and the board of directors are expected to remain ultimately responsible for outcomes produced by an institution's AI systems, not just the technical team that built them.
- Governance frameworks: institutions are expected to define their AI-related risk tolerance, set a strategic direction for AI adoption, and establish clear oversight structures before deploying high-risk tools.
- Non-discrimination testing: because algorithms can encode bias, institutions are expected to build and document strategies that actively test for discriminatory outcomes.
- Training and annual reporting: staff training programmes and periodic reporting are expected to become standard compliance requirements for high-risk deployments.
For companies operating below the high-risk threshold, the compliance burden is expected to be considerably lighter — largely centred on transparency and disclosure rather than full governance overhauls. Still, given that the national-level classification framework is still being finalised, it is worth building internal documentation habits early rather than waiting for the rules to be locked in.
Frequently Asked Questions
Has Nepal officially finalised its AI risk classification framework?
Not in full. The National AI Policy 2082 mandates that such a framework be developed, and the National AI Centre is tasked with assessing risks and preparing action plans. The clearest real-world example so far is sector-specific: Nepal Rastra Bank's draft AI guideline for banks and payment providers.
Is Nepal's approach modeled on the EU AI Act?
The structural logic — sorting systems by risk level and applying proportional obligations — closely mirrors the EU AI Act's approach, though Nepal's version is being adapted for local sectors like financial inclusion and public-service delivery rather than copied wholesale.
Does risk classification apply only to financial institutions?
No. The national framework is intended to apply across sectors, including health, education, and public administration. Financial services simply have the most developed guidance so far because Nepal Rastra Bank moved first with a sector-specific draft.
What should a startup do if it is unsure which risk tier applies to it?
Given that the framework is still developing, the safest approach is to document your AI system's data sources, decision logic, and human-oversight mechanisms now, and seek guidance from the National AI Centre or your sector regulator before a formal classification becomes mandatory.
Discussion