AI Policy Wiki
Dashboard

Risk-Based AI Regulation

high confidence · updated 2026-07-25

The regulatory approach — pioneered by the EU AI Act and now emulated by Brazil, Canada, and others — of tiering obligations by the risk level of an AI system's intended use, rather than regulating AI uniformly or only at the technology level.

Risk-based AI regulation calibrates legal obligations to the risk level of an AI system's intended use. Developed most fully in the EU AI Act (2024), it has since served as a de facto template for other jurisdictions. The approach contrasts with technology-uniform regulation (all AI treated the same) and with pure self-regulation (no tiered obligations).

The EU AI Act's four tiers

The EU AI Act sorts systems into four risk tiers by intended use, attaching escalating obligations to each.

TierExamplesObligations
Unacceptable riskSocial scoring; person-based crime prediction; real-time biometric identification in public (with narrow exceptions)Prohibited
High riskCritical infrastructure; education; healthcare; employment; law enforcement; border control; administration of justiceRisk management, data governance, logging, transparency to deployers, human oversight, accuracy/robustness/cybersecurity
Limited riskChatbots; generative-AI systems; emotion-recognition; biometric-categorizationTransparency to users (disclosure that content/interaction is AI-generated); AI-content labeling
Minimal or no riskVideo games; spam filtersNo specific AI regulation

Overlaid on these four tiers are general-purpose AI (GPAI) model obligations, a separate track focused on the technology itself rather than its use. These apply to foundation-model developers regardless of downstream application and cover technical documentation, training-data transparency, copyright policy, and energy-consumption disclosure. A further systemic-risk tier within GPAI, defined by a 10²⁵ FLOP training-compute threshold or AI Office designation, triggers additional obligations around red teaming, cybersecurity, incident reporting, and model evaluation.

Rationale

According to its proponents, the approach responds to two tensions in AI regulation. The first is uncertainty over which applications are harmful: blanket AI regulation treats trivial and catastrophic uses identically, inviting either over-regulation or under-regulation, whereas risk-based tiering concentrates regulatory effort where harm is most likely. The second is the choice between technology-level and application-level regulation. Pure application-level regulation (sectoral laws) misses GPAI systems whose applications are unpredictable, while pure technology-level regulation treats a medical-diagnosis AI and a video-game NPC identically. Risk-based tiering hybridizes the two: most regulation is application-level (by use-case risk tier), but GPAI provisions add a technology-level layer.

Emulation in other jurisdictions

Per G'sell (2024), several jurisdictions have adopted or proposed risk-tiered frameworks modeled in part on the EU approach. Brazil's PL 2338 implements a "risk-based approach based on a gradation of risks," with obligations scaled to system risk level. Canada's proposed Artificial Intelligence and Data Act draws on multiple international frameworks including the EU AI Act, with a focus on "high-impact" systems. Japan is considering a binding framework for "high-risk AI systems and those with significant potential impact and risk if misused." South Korea's AI Basic Act includes risk-tiered obligations, though less granular than the EU's. India is considering provisions for "especially high-risk" AI systems in the forthcoming Digital India Act.

G'sell describes this pattern as consistent with the Brussels Effect, in which EU technology regulation becomes the global template through extraterritorial reach and compliance-cost asymmetries.

The pattern continued into 2026 in Southeast Asia: on July 10, 2026, Malaysia's National AI Office opened a consultation (comments due July 31) on a proposed AI Governance Bill built around three risk tiers and a Central AI Authority (Source: substack.com).

Limitations

Several limitations of risk-based tiering have been documented. The same underlying model (for example, a GPT-class model) can fall into different risk tiers depending on how it is deployed, leaving foundation-model developers uncertain over which obligations apply to their models' downstream uses. Critics argue the EU AI Act's high-risk Annex III is over-inclusive, contending that employment and education tools may not create commensurate risks; this is discussed on the EU AI Act (Regulation 2024/1689) page. The 10²⁵ FLOP threshold for systemic GPAI risk is compute-based and will need recalibration as training efficiency improves (see EU AI Office — Enforcement Framework + GPAI Provider Guidelines). A further concern is enforcement lag: risk-based tiering requires regulators to interpret "intended use" correctly, which demands technical expertise that many agencies lack.

Compatibility with frontier-safety frameworks

The risk-based approach pairs with the capability-threshold systems used by frontier labs, including responsible scaling policies, the Preparedness Framework, and the Frontier Safety Framework. Both are tier-based: risk-based regulation tiers by application risk, while capability-threshold frameworks tier by model capability level. The two could in principle be composed, so that a high-capability model deployed in a high-risk application would warrant the strictest combined obligations. No jurisdiction has yet formally integrated them; risk-based regulation governs applications, capability thresholds govern models, and mapping between them remains ad hoc.

Binding capability-threshold proposals

A distinct strand proposes binding regulation tiered by model capability rather than by application use-case. In the essay "Policy on the AI Exponential" (June 10, 2026), Dario Amodei argued that frontier AI should be regulated on the model of the Federal Aviation Administration: models above a compute threshold would undergo mandatory third-party testing in four risk areas — cybersecurity, biological weapons, loss of control, and automated R&D — with government authority to block or reverse deployment of models judged to present unacceptable risks. Reporting put the proposed threshold at models trained above 10²⁵ FLOPs, or built by companies with over $500 million in AI revenue or $1 billion in AI R&D, and described third-party evaluation as performed either by an FAA-style agency or by government-authorized private evaluators (a "regulatory markets" approach) (Source: insideaipolicy.com; politico.com).

The companion legislative text, Anthropic's Advanced AI Framework, differs from that reporting on two structural points. The covered-developer test is conjunctive rather than disjunctive: a developer must both train models requiring more than 10²⁵ FLOP and meet the revenue or R&D-spending threshold. And deployment-blocking authority is presented as a menu of options rather than a settled recommendation, on the stated reasoning that policymakers "could begin with a lighter-touch model and revisit that choice as model capabilities advance and the independent evaluation ecosystem matures." Agency review would be confined to four enumerated violations — missing disclosures, an insufficiently disinterested or qualified evaluator, an evaluator without adequate time or access, or a finding of significant catastrophic-harm risk after safeguards — with remedies pursued through the courts rather than imposed directly, and with expedited judicial review available to the developer. The framework also proposes that the threshold itself may need to become capability-based rather than compute-based as the FLOP required to train dangerous models falls.

On the boundary between federal and state authority, the framework takes the restrictive position that Congress should not preempt state law unless it enacts a regime meeting or exceeding the framework's own strongest measures, that any preemption should reach only expressly occupied functions such as catastrophic-risk testing, evaluator licensing, and closely related reporting, and that federal compliance should confer no immunity, safe harbor, or presumption against liability under state law. See State-Level AI Regulation. Amodei framed this as a step beyond the transparency legislation Anthropic had previously supported (CA SB 53, the NY RAISE Act), justified by cybersecurity and biological risks he argues are now definite enough to target precisely. The 10²⁵ FLOP figure matches the EU AI Act's GPAI systemic-risk threshold, though the EU layer triggers documentation and evaluation obligations rather than deployment-blocking authority. The proposal contrasts with the same-week OpenAI plan "Built to benefit everyone" (Altman and Pachocki), which emphasizes broad distribution of power and an international coordinating organization over binding national testing.

Contrasts with other regulatory approaches

G'sell notes that China's framework is primarily principle-based, specifying general obligations rather than risk tiers (see China — Interim Measures for the Management of Generative AI Services). The US federal approach has favored voluntary frameworks and sector-specific enforcement, hands-off until EO 14110 and shifting again under Trump-era EOs; at the state level, laws such as the Colorado AI Act are increasingly risk-based. Risk-based frameworks also differ from fully technology-neutral regulation: sectoral laws such as HIPAA for healthcare and ECOA for credit regulate outcomes regardless of whether AI is used, whereas risk-based frameworks add AI-specific layers on top.

Relationships