Qualifying and Quantifying Risk Under the EU AI Act
arXiv:2608.08564
Abstract
The EU AI Act uses a risk-based approach to regulate AI systems, calibrating the intensity of regulation according to the risks they pose. While the term 'risk' implies quantification, resulting from the combination of the probability and severity of harm, the AI Act refers to risks to fundamental rights, thereby engaging a qualitative perspective. In this piece, we address this puzzle using a two-step framework under which the EU AI Act balances risks with the protection of fundamental rights, the legitimate purposes of providers and deployers, and the impacts of regulatory measures on providers, deployers, and regulators. We discuss this framework against the backdrop of potential approaches to quantifying risks, with a specific focus on defining and measuring the main components of the concept of risk: probability, severity, and their combination. We suggest that the protection of fundamental rights and risk quantification can be aligned by incorporating quantification methodologies into the proposed framework. In particular, the AI Act implies a balancing analysis that uses a severity-first approach to classify and quantify the risks posed by AI systems. The integrated framework not only helps to clarify the AI Act's risk-based approach, but can also inform technical and implementation choices. Finally, we conclude that if the risk quantification methodology or its application to the protection of fundamental rights is left to providers and deployers, there is potential for 'risk hacking', which could lead to the underclassification of AI systems and subsequent regulatory shortcuts.
15 pages, 2 figures