A Risk-Tiering Framework for Governing SAP Generative and Agentic Artificial Intelligence in Regulated Enterprise Environments: A Utility Sector Case Study
DOI:
https://doi.org/10.70917/ijcisim-2026-5853Keywords:
AI governance, Risk Tiering, SAP, Agentic AI, EU AI Act, NIST AI RMF, Regulated Industries, Enterprise AIAbstract
Generative and agentic artificial intelligence systems are entering production on SAP Business Technology Platform at regulated enterprises whose governance frameworks were not designed for them. This paper presents a risk-tiering framework for governing SAP generative and agentic AI deployments in regulated enterprise environments, developed through design science methodology and validated through a case study in the utility sector. The framework defines four risk tiers: minimal-risk assistive AI, moderate-risk recommendatory AI, high-risk autonomous AI with consequential business impact, and critical-risk AI in safety or regulatory reporting, mapped to SAP process domains and data sensitivity classifications. Governance controls at each tier are calibrated to the autonomy level and regulatory exposure of the AI use case. The framework is aligned by construction to the risk classification structure of the EU AI Act, the NIST AI Risk Management Framework, and SAP's ISO/IEC 42001-certified responsible AI posture. A case study in the utility sector involving 15 generative and agentic AI use cases across five SAP domains demonstrates practical application, producing a tier distribution of approximately 30% Tier 1, 40% Tier 2, 25% Tier 3, and 5% Tier 4 and a governance operating model reviewed by external auditors and regulatory affairs professionals. The framework provides enterprise architects and AI governance leads in regulated SAP environments with an implementable, auditor-defensible governance instrument that is calibrated to the SAP platform context.