The risk-based approach and why it won
AI law and regulation · Lesson 2 / 21
Regulate the use case, not the technology
Early attempts to regulate AI tried to describe the technology itself: what counts as artificial intelligence, which architectures are dangerous, what compute threshold requires authorisation. Every such attempt broke on the same rock. Technology changes faster than rules are adopted, so by the time the rule took effect the system it described was already obsolete.
What the risk-based approach does instead
It moves the question from what kind of model this is to what happens to a person if the system gets it wrong. The same model can be harmless in one setting and tightly constrained in another. An image classifier inside a photo editor and the same classifier controlling access to a building are legally different things.
- Unacceptable risk. Use cases prohibited as such, regardless of how good the system is or whether anyone consented.
- High risk. Material effect on rights, access to goods and services, or safety. Permitted, but with the full package: documentation, data quality, human oversight, logging, impact assessment.
- Limited risk. The core duty is transparency: the person must understand they are dealing with a system or looking at generated material.
- Minimal risk. General law plus voluntary practice.
Category names and boundaries differ between jurisdictions and get revised. What stays stable is the underlying logic: the heavier the consequences for a person, the denser the duties.
Classifying your own use case
Five questions for a first-pass classification 1. Who is affected by what the system produces 2. What the person loses if it is wrong (money, access, reputation, health) 3. Whether the person can learn about the decision and challenge it 4. Whether a non-AI alternative exists 5. Whether the use case appears in your jurisdiction's lists, checked at source
Cheat sheet
- The use case is regulated, not the model architecture.
- The risk level sets the volume of duties.
- A change of use case demands a fresh classification.
- Check category boundaries against a current primary source.
Take one real AI use case from your own work. Describe it in one sentence, answer the five first-pass classification questions, and propose a risk level. Separately, name the source in your jurisdiction that you will check to confirm or overturn that assessment.