Spokes.wiki Search About
Defined Term practice updated Thu Jun 18 2026 00:00:00 GMT+0000 (Coordinated Universal Time)

Risk-Based Regulation

Risk-based regulation scales the intensity of oversight to the potential impact of an AI system: low-risk applications face minimal requirements, while high-impact systems face rigorous transparency, documentation, and human-oversight obligations. The principle nearly all the founding sources share — even where they disagree on the instrument (see synthesis).

In the sources

  • israel-ai-regulation-overview — explicitly risk-based: high-risk uses named as credit scoring, medical diagnosis, autonomous vehicles; finance gets “graded explainability” proportional to decision impact.
  • eu-ai-act — the most formal instance: risk tiers (unacceptable / high / limited / minimal) with obligations attached to each.
  • nist-ai-rmf — organizes voluntary risk management around four functions, with Govern as the cross-cutting culture-and-accountability layer the other three (Map → Measure → Manage) run inside; the framework grades effort to risk rather than imposing fixed legal tiers nist-ai-rmf-overview.
  • oecd-ai-principles — supplies the shared AI-system definition that the risk tiers above are drawn around, so jurisdictions tier different instruments over the same object.

Why it matters

Risk-tiering is the shared substrate beneath the horizontal-vs-sectoral fork: the EU and Israel disagree on whether the rules should be one binding law or sector-by-sector soft law, but both agree oversight should track risk. The open question is who defines the tiers and thresholds.

ai-governance · eu-ai-act · nist-ai-rmf · oecd-ai-principles · israel-ai-regulation-overview · responsible-innovation