Qualifying and Quantifying Risk under the EU AI Act
This paper proposes a "severity-first" two-step framework to reconcile the EU AI Act's qualitative focus on fundamental rights with its quantitative risk definition, while warning that delegating risk quantification to providers could enable "risk hacking" and regulatory underclassification.
Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer
Imagine you are the mayor of a bustling, futuristic city where robots are everywhere. Some robots are harmless, like a toaster that learns your favorite bread setting. Others are powerful, like a robot judge or a drone that scans faces in the park. The big question for any city leader is: "How do we keep everyone safe without stopping the cool new inventions?" This is the heart of a field called risk regulation. It's the art of figuring out how likely something bad is to happen (probability) and how terrible it would be if it did (severity). Usually, leaders try to do a quick math problem: multiply the chance of an accident by how bad the accident is. If the number is small, they say, "It's fine!" But what if the "bad thing" is something you can't easily count, like losing your privacy or your freedom? That's where things get tricky. If you can't put a price tag on a human right, how do you do the math? This is the exact puzzle facing the European Union as they try to write rules for Artificial Intelligence (AI).
This paper, written by researchers from Germany and the US, dives into the EU's new "AI Act," a massive law designed to sort AI systems into three buckets: "No Go" (banned), "High Risk" (needs strict rules), and "Minimal Risk" (free to go). The authors notice a funny tension in the law. On one hand, the law defines "risk" like a math equation: Probability × Severity. On the other hand, the law is trying to protect "fundamental rights" (like dignity, privacy, and fairness), which are usually treated as special, unquantifiable values. You can't really measure "dignity" in dollars or percentages. The authors suggest that if we try to force a simple math formula onto these complex human rights, companies might manipulate the system. They might tweak their numbers to make a dangerous robot look safe, a trick the authors call "risk hacking."
So, what do the authors propose? They suggest a new way to look at the problem, like a two-step dance. Step 1 is to look at the robot's purpose and ask: "Is the harm it could cause so severe that it breaks a fundamental right, regardless of how often it happens?" This is what they call a "severity-first" approach. Think of it like a bouncer at a club who doesn't care how likely a fight is; if the person is holding a grenade (high severity), they are banned immediately, even if they've never thrown it before. Step 2 is to look at the "math" of the situation: How likely is the harm? And what are the costs of stopping the robot?
The paper argues that the EU AI Act actually already uses this "severity-first" logic, even if it doesn't say it out loud. For example, the law bans certain AI uses (like reading emotions in the workplace) because the potential harm to privacy is just too high, even if the chance of it happening is low. The authors suggest that regulators should stick to this order: check the severity first, then worry about the probability. If we let companies decide the math themselves, they might try to argue that a "low probability" of a "catastrophic" event is actually "low risk," which would let dangerous AI slip through the cracks. By keeping the focus on how bad the harm could be first, we can protect human rights while still allowing useful technology to grow. The paper doesn't claim to have solved every math problem, but it offers a clear roadmap to stop the "risk hacking" and make sure the rules actually work for people.
Drowning in papers in your field?
Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.