Risk-Based Regulation
Risk-based regulation scales the intensity of oversight to the potential impact of an AI system: low-risk applications face minimal requirements, while high-impact systems face rigorous transparency, documentation, and human-oversight obligations. The principle nearly all the founding sources share — even where they disagree on the instrument (see synthesis).
In the sources
- israel-ai-regulation-overview — explicitly risk-based: high-risk uses named as credit scoring, medical diagnosis, autonomous vehicles; finance gets “graded explainability” proportional to decision impact.
- eu-ai-act — the most formal instance: risk tiers (unacceptable / high / limited / minimal) with obligations attached to each.
- nist-ai-rmf — organizes voluntary risk management around four functions, with Govern as the cross-cutting culture-and-accountability layer the other three (Map → Measure → Manage) run inside; the framework grades effort to risk rather than imposing fixed legal tiers nist-ai-rmf-overview.
- oecd-ai-principles — supplies the shared AI-system definition that the risk tiers above are drawn around, so jurisdictions tier different instruments over the same object.
Why it matters
Risk-tiering is the shared substrate beneath the horizontal-vs-sectoral fork: the EU and Israel disagree on whether the rules should be one binding law or sector-by-sector soft law, but both agree oversight should track risk. The open question is who defines the tiers and thresholds.
Related
ai-governance · eu-ai-act · nist-ai-rmf · oecd-ai-principles · israel-ai-regulation-overview · responsible-innovation