← Latest papers
🤖 AI

High-Risk AI Systems and the Problem of Identity in the European AI Act

This paper argues that the European AI Act's reliance on ambiguous identity judgments for high-risk AI systems can be resolved by applying the "function+" framework, which individuates systems through intended function and trustworthiness profiles to create an auditable, operational standard for synchronic identity in regulatory and governance contexts.

Original authors: Andrea Ferrario

Published 2026-05-26
📖 6 min read🧠 Deep dive

Original authors: Andrea Ferrario

Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer

The Big Problem: When Does a Robot Become a "New" Robot?

Imagine you buy a very smart, high-stakes robot to help run a hospital or a border checkpoint. The European Union has a new law (the AI Act) that says these robots must be checked and certified before they can work.

But here is the tricky part: Robots change. They get software updates, they learn from new data, and sometimes their settings are tweaked.

The law asks a difficult question: Is this still the same robot, or is it a new one?

  • If it's the same robot, you don't need to pay for a new expensive check-up.
  • If it's a new robot, you have to stop, go back to the drawing board, and get a brand new certificate.

The paper argues that the current law is a bit vague about how to answer this question. The author, Andrea Ferrario, suggests a new way to think about it using a "recipe" for identity.


The Solution: The "Function+" Recipe

To solve this, the author uses a philosophical idea called Function+. Think of it like defining a Car.

  1. Techno-Function (The Engine): What is the machine built to do? (e.g., "Transport people from A to B").
  2. The Context (The "Plus"): How is it supposed to behave in the real world? (e.g., "It must not crash, it must be fair to all passengers, and it must be transparent about why it turned left").
  3. The Trust Score (The Level): Is it actually doing a good job right now? (e.g., "It is 95% safe and 90% fair").

The paper says an AI system is only "the same" if its Engine, its Rules, and its Trust Score stay consistent.


Two Real-Life Stories from the Paper

The author uses two stories to show why this matters:

Story 1: The Hospital Triage Robot (Time Travel)

A hospital uses an AI to decide which patients need emergency care first.

  • The Change: A new virus hits. The hospital updates the AI to handle older patients better and adds a feature that explains why it made a decision.
  • The Conflict: The doctor says, "It's the same robot, just updated." The AI company says, "It's the same robot." But the nurses say, "No! It thinks differently now. It's a different robot!"
  • The Paper's View: If the AI's "Trust Score" (how well it explains itself and treats patients fairly) drops or changes its core rules, it is legally a new robot. It needs a new certificate. If the law doesn't have a clear way to measure this, nobody knows who is liable if the robot makes a mistake.

Story 2: The Airport Face-Scanner (The Twin Paradox)

Two airports want to buy face-scanning robots from the same company.

  • The Setup: Airport A gets "Robot X" (super fast, expensive). Airport B gets "Robot Y" (slightly slower, cheaper). They look the same and do the same job.
  • The Conflict: The company says, "Robot X is better because it's faster. It's a different product, so you have to pay more." The airport officials say, "No, they do the exact same job. You're just charging us extra for speed we don't need."
  • The Paper's View: The current law doesn't have a clear test to say, "Are these two robots the same?" The author suggests we should check: Do they have the same Trust Score? If they are equally safe and fair, they should be treated as the same robot for legal purposes, regardless of minor speed differences.

The Author's Two Main Claims

Claim 1: The Law Already Has a "Time Machine" (Diachronic Identity)
The paper says the EU AI Act does have a way to handle changes over time, but it's hidden in the rules.

  • The Rule: If you change the robot so much that it breaks the rules or changes its job, it's a "Substantial Modification."
  • The Fix: The author suggests we use the Function+ recipe to make this clearer. We need to write down exactly what the robot's "Trust Score" was when it started, and if that score drops too low later, we know it's a new robot.

Claim 2: The Law is Missing a "Mirror" (Synchronic Identity)
The paper says the law is silent on how to compare two robots at the same time.

  • The Gap: If Airport A and Airport B have two different robots, the law doesn't give a checklist to say, "Are these legally the same?"
  • The Fix: The author proposes a simple Audit Flowchart (like a checklist for a security guard):
    1. Do they have the same Job Description? (Intended Purpose)
    2. Do they have the same Rulebook? (Trustworthiness Profile)
    3. Do they have the same Report Card right now? (Trustworthiness Level)
    • If YES to all three: They are the same robot.
    • If NO to any: They are different robots.

The Recommendations: How to Fix It

The author suggests two practical steps to make this work in the real world:

  1. Be Specific About the Job: Don't just say "This AI helps doctors." Say "This AI helps doctors sort patients by urgency, but it is not allowed to diagnose cancer." This prevents the AI from pretending to be something it isn't.
  2. Standardize the Report Card: Instead of every company making up their own way to measure "safety" or "fairness," we need a standard template. Imagine if every car had to show a "Safety Star Rating" (like 5 stars) calculated the exact same way. If an AI's rating drops from 5 stars to 3 stars, we know it's time for a new check-up.

Summary

The paper argues that to regulate AI fairly, we need to stop guessing if a robot is "the same" or "new." We need a clear, mathematical way to measure its purpose, its rules, and its performance. If those change, the law should treat it as a new robot. This makes it easier to know who is responsible when things go wrong and stops companies from charging extra for robots that are essentially the same.

Drowning in papers in your field?

Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.

Try Digest →