{"id":"4d43cc07-3f55-4ff6-b8f5-ae3444716852","arxiv_id":"1909.01095","paper_version":3,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":6.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":0,"one_line_summary":"Regulators should define AI regulation scope by specific risk sources (technical approaches, applications, capabilities) rather than by the vague term AI.","lead":"This paper argues that AI regulations should not define their scope using the term 'artificial intelligence,' because existing definitions are vague and over- or under-inclusive. Instead, it proposes a risk-based approach that defines regulations by the technical approaches, applications, and capabilities that create the risks regulators want to reduce.","discovery_kind":"new_method","skeptic_critique":{"model":"deepseek-v4-flash","headline":"The risk-based categories still fail the two requirements the paper calls most important; Table 3 undermines the central conclusion.","rationale":"The reader's weakest assumption concerned the provenance and completeness of the six requirements in Table 1. My concern is different and more internal: even granting those requirements, the paper's own evaluation in Table 3 shows that the proposed risk-based categories do not satisfy the two requirements the paper itself calls most important (over-inclusiveness and precision/vagueness), and under-inclusiveness also remains unresolved for all categories. This is not an external critique about jurisdiction-specific legal doctrines; it is a gap inside the argument. The paper may still be right that a multi-element, risk-based approach is preferable to defining AI, but the evidence presented is insufficient to establish that it meets the requirements better in the respects that matter most. I therefore keep the conditional verdict: the paper should either demonstrate that a combined definition overcomes these failures or soften its claim. This does not require rejection because the paper's negative thesis (do not rely on the term AI) is well supported, and the positive proposal is plausible; it needs clearer support at the precise point where Table 3 records failures.","tokens_in":15882,"tokens_out":4213,"duration_ms":39843,"concrete_test":"Evaluate the composite definition from Section 3.4 against over-inclusiveness and under-inclusiveness using the paper's own criteria. Choose two concrete cases: (a) a low-risk facial recognition system based on supervised learning used by police for trivial identification, and (b) a high-risk facial recognition system based on unsupervised learning deployed for law enforcement. Determine whether the composite definition includes case (a) and excludes case (b). If the composite is over-inclusive or under-inclusive in these cases, the claim that the risk-based approach meets the most important requirements fails; if it passes, the paper should show this explicitly in an updated Table 3.","verdict_should_be":"UNCHANGED","load_bearing_attack":"Section 2.3 identifies over-inclusiveness and vagueness/precision as the most important requirements: 'existing definitions of AI do not meet the most important requirements for legal definitions. They are highly over-inclusive and vague.' Table 3 then evaluates the proposed alternatives: technical approaches fail over-inclusiveness ('game-playing agents based on reinforcement learning') and under-inclusiveness ('relevant risks cannot be attributed to a single technical approach'); applications pass over-inclusiveness but fail under-inclusiveness; capabilities fail both. Thus none of the three categories satisfies the two most important requirements. The paper's conclusion in Section 3.4 that these definitions 'meet more of the requirements' is true only for precision, understandability, and practicability, not for the requirements that motivated the critique of AI definitions. The multi-element example ('facial recognition systems for law enforcement purposes based on supervised learning') is never evaluated against over- and under-inclusiveness; it appears over-inclusive (some low-risk systems using supervised learning for that purpose would be covered) and under-inclusive (systems using unsupervised learning or other approaches with comparable risks would be excluded). The central policy recommendation therefore rests on an incomplete comparative evaluation.","agreement_with_reader":"partial"},"referee_report":{"model":"deepseek-v4-flash","summary":"The paper argues that policy makers should not use the term \"artificial intelligence\" to define the material scope of AI regulations, because existing AI definitions fail what the author identifies as the most important requirements for legal definitions (over-inclusiveness, under-inclusiveness, precision, understandability, practicability, flexibility). Instead, the author proposes a risk-based approach that defines scope through three categories of risk factors: technical approaches (e.g., reinforcement learning), applications (e.g., facial recognition), and capabilities (e.g., physical interaction). The paper evaluates each category against the six requirements in Table 3, claims that these alternatives meet more requirements than AI definitions, and extends the argument to AGI regulation. The central contribution is a structured set of evaluative criteria and a concrete alternative framework for AI regulation.","tokens_in":16093,"tokens_out":3304,"duration_ms":33349,"significance":"If the argument is accepted, the paper provides a useful, policy-relevant framework for drafting AI regulation, with a clear set of criteria and concrete definitional elements. Its strengths include the systematic derivation of requirements from EU and US legal principles, the survey of existing definitions, and the explicit discussion of AGI as a regulatory target. The paper is clearly written and engages with prior literature. However, the central comparative claim is incomplete: the alternatives are shown to meet more requirements only on precision, understandability, and practicability, while still failing over- and under-inclusiveness, which the paper itself calls most important. The multi-element approach is asserted to reduce over-inclusiveness and increase precision but is never evaluated. These gaps are load-bearing for the main recommendation, so the paper requires substantive revision before its conclusion can be accepted.","major_comments":[{"comment":"The central claim that risk-based definitions \"meet more of the requirements\" is undermined by the paper's own evaluation: technical approaches and capabilities each fail over-inclusiveness and under-inclusiveness, and applications fail under-inclusiveness. Since Section 2.3 identifies over-inclusiveness and vagueness (precision) as the \"most important requirements,\" the table shows that the proposed alternatives do not address the most important failure of AI definitions. The paper should either justify why satisfying precision, understandability, and practicability outweighs continued failure on over- and under-inclusiveness, or it should evaluate a combined multi-element definition against all six requirements. As written, the conclusion that policy makers should favor the risk-based approach does not follow from Table 3.","section":"Section 3.4, Table 3"},{"comment":"The paper proposes the example \"facial recognition systems for law enforcement purposes based on supervised learning\" and asserts that this approach allows policy makers to \"reduce over-inclusiveness and increase precision,\" but it never evaluates the example against the requirements in Table 1. On its face, the example appears over-inclusive (it covers all such systems regardless of their actual risk) and under-inclusive (it excludes systems using unsupervised learning or other approaches that could pose comparable risks). Without a systematic evaluation of a multi-element definition against over- and under-inclusiveness, the central recommendation rests on an untested assumption. The author should add an explicit evaluation of the multi-element approach, or qualify the claim accordingly.","section":"Section 3.4, multi-element example"}],"minor_comments":[{"comment":"In the sentence about the US Supreme Court, there is a missing space: \"According to the(US Supreme Court, 1926, p. 391)\" should read \"According to the (US Supreme Court, 1926, p. 391).\"","section":"Section 2.1"},{"comment":"The phrase \"the termssupervised learningand unsupervised learning\" appears without spaces around the italicized terms; this should be corrected to \"the terms 'supervised learning' and 'unsupervised learning'.\"","section":"Section 3.1"},{"comment":"The sentence \"A third category of AI risk factors is a system’s capabilities\" is awkward; consider \"A third category of AI risk factors is a system's capabilities\" or more simply \"A third category is capabilities.\" Ensure that the possessive is typeset consistently.","section":"Section 3.3"},{"comment":"The reference to \"White House, 2020\" is listed in the references as \"Guidance for regulation of artificial intelligence applications\" with a URL; the in-text citation appears once in the list of definitions and once in the discussion of AGI, which is fine, but the reference entry would benefit from a consistent format with other executive documents (e.g., adding the issuing office).","section":"Section 2.2"}],"recommendation":"major_revision","confidential_remarks":"The paper is well-suited for a policy-oriented AI or law-and-technology journal. The main concern is that the central comparative evaluation is incomplete, not that the overall direction is wrong. If the author can address the over- and under-inclusiveness issue for the multi-element approach and temper the conclusion to match what Table 3 actually shows, the paper could make a solid contribution."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"The short version: this is a genuinely useful policy paper, not a technical one. It makes a coherent case that regulators should stop trying to define 'AI' and instead scope rules by specific technical approaches, applications, and capabilities. That three-part categorization is a real contribution, and the paper is honest about its own limits. But the stress-test note lands: Table 3 shows that no single category passes both over-inclusiveness and under-inclusiveness, which the paper itself calls the most important requirements. The multi-element example ('facial recognition systems for law enforcement purposes based on supervised learning') is presented as the fix, but it is never evaluated against those same criteria. So the central recommendation rests on an incomplete comparative evaluation.\n\nWhat is actually new: the first comprehensive list of requirements for legal definitions of AI, the risk-factor categorization, and a first pass at extending the argument to AGI. The paper also engages properly with prior skeptical scholarship (Reed, Casey & Lemley, Buiten) and with the EU AI Act, and it does not oversell its evidence—the subjective nature of Tables 2 and 3 is acknowledged up front.\n\nThe soft spots are real but proportionate. The requirement list is distilled from EU and US law and may not transfer cleanly; the examples are selected to favor the proposed alternative; and the claim that the risk-based approach 'meets more of the requirements' is technically true but dodges the two failures that motivated the critique of AI definitions. That is a genuine gap, not a manufactured one. Still, the core argument—that the term AI is too vague and over-inclusive for legal scoping—holds up, and the paper never claims the categories are perfect, only better.\n\nWho is this for? Policy makers drafting AI regulations, legal scholars working on AI governance, and anyone in the EU AI Act debate. It deserves serious refereeing, not a desk reject. The referee should push for an explicit evaluation of the multi-element approach against over- and under-inclusiveness, and for a clearer statement of which requirements are load-bearing. With that revision, this would be a solid and citable piece.\n\nRecommendation: send it to peer review. It is timely, readable, and the flaw is fixable.","headline":"Useful policy paper with a real contribution, but the stress-test is right that the risk-based categories individually fail the paper's own 'most important' requirements; the multi-element solution is asserted, not evaluated.","tokens_in":16554,"tokens_out":2135,"would_cite":true,"duration_ms":23378,"reading_group":"yes","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"deepseek-v4-flash","headline":"To regulate AI safely, policy makers should stop trying to define \"artificial intelligence\" and instead define the specific risks—technical approaches, applications, and capabilities—that they want to reduce.","keywords":["AI regulation","legal definitions","risk-based approach","material scope","AGI regulation","technical approaches","applications","capabilities"],"falsifier":"Give a panel of lawyers and technical experts the same 100 deployed AI systems and ask them to classify each as in or out of scope under the EU AI Act's current definition; if their classifications are consistently precise and the resulting inclusion set matches the regulation's stated risk objectives without capturing harmless systems, the paper's claim that term-based definitions fail the key requirements would be contradicted.","tokens_in":15688,"feed_emoji":"⚖️","tokens_out":6871,"duration_ms":63025,"temperature":0.7,"pith_summary":"The paper argues that the material scope of AI regulations should not be anchored to the term \"artificial intelligence,\" because every existing definition of AI is too vague and over-inclusive to satisfy basic requirements for legal definitions. It proposes a set of six requirements for legal definitions—over-inclusiveness, under-inclusiveness, precision, understandability, practicability, and flexibility—and evaluates existing definitions against them. It then argues that a risk-based approach, defining scope via technical approaches (e.g., reinforcement learning), applications (e.g., facial recognition), and capabilities (e.g., physical interaction with the environment), meets these requirements better and allows finer-grained targeting. The paper concludes that policy makers should define AI regulations by the risks they want to reduce rather than by a contested umbrella term, and suggests this approach also works for future AGI regulation, where the emphasis shifts to capabilities.","feed_headline":"Regulate AI by risk, not by defining 'AI'","feed_subtitle":"Six legal-definition tests show why 'AI' fails them, and why risk-based scopes—approaches, applications, capabilities—pass.","key_machinery":"The engine of the argument is a six-requirement checklist for legal definitions (Table 1): over-inclusiveness, under-inclusiveness, precision, understandability, practicability, and flexibility, anchored in proportionality, legal certainty, the vagueness doctrine, effectiveness, and good legislative practice. The checklist does double work: it first eliminates the term \"AI\" by scoring existing definitions against it (Table 2), then it validates the replacement categories—technical approaches, applications, and capabilities—(Table 3). The positive proposal's operative mechanism is the multi-element scope definition, which combines entries from those three categories so that a regulation applies to precisely those systems whose risks justify it.","core_discovery":"The paper's central claim is that the term \"AI\" cannot carry the material scope of a regulation because any workable definition of it is over-inclusive, vague, and hard to apply in practice. The author derives six requirements for legal definitions from EU and US legal principles and good legislative practice, then uses them to show that existing definitions from computer science, philosophy, and policy fail the most important tests. The positive alternative is a risk-based scope: define regulation by the main causes of the risks it targets, namely technical approaches (e.g., reinforcement learning), applications (e.g., facial recognition), and capabilities (e.g., physical interaction or automated decision-making). Combining these elements—as in \"facial recognition systems for law enforcement purposes based on supervised learning\"—meets the requirements better than any single definition of AI, and the same logic can be extended to AGI regulation by leaning more on capability definitions such as recursive self-improvement.","pith_inferences":["The same decomposition could be applied to other broad regulatory terms, such as automation or algorithmic systems, suggesting that regulators should generally ask which applications and capabilities create harm before deciding what to call the regulated technology.","The six-requirement checklist could be operationalized as a scoring rubric for regulatory impact assessments, making trade-offs between precision and future flexibility explicit.","A natural empirical test would compare the systems captured by the EU AI Act's current definition with those captured by a risk-based definition using the same risk list; divergence would show how often the choice of definition changes the regulated set.","The AGI section implies that legal scholarship could productively focus on defining a small set of risk-relevant capabilities before advanced systems exist, rather than waiting for technical consensus on what counts as general intelligence."],"forward_implications":["Drafters of future AI regulations can define material scope as a list of technical approaches, applications, and capabilities, without ever using the word \"AI.\"","Such scopes can be tailored to the specific risk profile of each system, reducing over-inclusiveness and increasing precision relative to a single umbrella definition.","The EU AI Act's current structure is close to this recommendation—Annex I lists technical approaches and Annex III high-risk applications—but making the break from \"AI\" explicit and distinguishing between technical approaches would sharpen it.","For AGI regulation, capability-based definitions such as recursive self-improvement become the most workable route when the future technical approach is unknown.","The six-requirement list offers a reusable standard for evaluating any proposed legal definition of a technology."],"supporting_citations":[{"why":"Annex I and Annex III of the proposed AI Act supply the technical-approach and high-risk-application lists that the paper compares with its own risk-based categories; it is also the main target of the \"empty shell\" argument.","marker":"European Commission, 2021"},{"why":"Provides the definitions of over-inclusive and under-inclusive used in Table 1.","marker":"Baldwin et al., 2011"},{"why":"Grounds the vagueness doctrine, from which the paper derives the precision and understandability requirements.","marker":"US Supreme Court, 1926"},{"why":"Grounds the principle of legal certainty, another source of the precision and understandability requirements.","marker":"Court of Justice of the European Union, 2009"},{"why":"Supplies a legal definition of AI and examples of under-inclusiveness; also gives the objection that vague definitions are common in law, which the paper answers.","marker":"Scherer, 2016"},{"why":"Argues for regulating unsafe behavior rather than defining \"robot,\" directly supporting the paper's risk-based and multi-element approach.","marker":"Casey & Lemley, 2019"},{"why":"Frames the core question as \"why do we need to define AI at all?,\" motivating the shift from definitions to policy goals.","marker":"Turner, 2019"},{"why":"Provides a survey of safety-relevant AI characteristics against which the paper positions its own three-category risk-factor taxonomy.","marker":"Hernández-Orallo et al., 2019"},{"why":"Supplies existing definitions of automated decision-making and \"legal or similarly significant effect\" used as capability-based examples already enacted in the GDPR.","marker":"Article 29 Data Protection Working Party, 2018"}],"fun_headline_variants":["AI defies legal definition, so regulate risks","Ditch AI definitions, target risks instead","Risk-based AI law beats defining the term","What is AI? Law should ask what risks","Regulate AI risks, not the term 'AI'"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The argument depends on the six requirements in Table 1 being the correct and sufficiently complete standard for legal definitions; if a jurisdiction does not accept those requirements or would weight them differently, the failure of term-based AI definitions and the success of risk-based categories do not automatically follow.","fun_headline_variants_meta":{"raw":{"variants":["AI defies legal definition, so regulate risks","Ditch AI definitions, target risks instead","Risk-based AI law beats defining the term","What is AI? Law should ask what risks","Regulate AI risks, not the term 'AI'"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000157,"raw_usage":{"total_tokens":1193,"prompt_tokens":885,"completion_tokens":308,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":501,"completion_tokens_details":{"reasoning_tokens":237}},"tokens_in":501,"tokens_out":308,"duration_ms":3339,"temperature":1.0,"reasoning_tokens":237,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-14T10:56:50.430654+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Give a panel of lawyers and technical experts the same 100 deployed AI systems and ask them to classify each as in or out of scope under the EU AI Act's current definition; if their classifications are consistently precise and the resulting inclusion set matches the regulation's stated risk objectives without capturing harmless systems, the paper's claim that term-based definitions fail the key requirements would be contradicted.","supporting_citations":[{"cited_title":"APACrefauthors \\ 1926","cited_arxiv_id":null,"evidence_quote":"Grounds the vagueness doctrine, from which the paper derives the precision and understandability requirements."},{"cited_title":"APACrefauthors \\ 2016","cited_arxiv_id":null,"evidence_quote":"Supplies a legal definition of AI and examples of under-inclusiveness; also gives the objection that vague definitions are common in law, which the paper answers."},{"cited_title":"APACrefauthors \\ 2019","cited_arxiv_id":null,"evidence_quote":"Frames the core question as \"why do we need to define AI at all?,\" motivating the shift from definitions to policy goals."},{"cited_title":", Fernando Martínez-Plumed, S A","cited_arxiv_id":null,"evidence_quote":"Provides a survey of safety-relevant AI characteristics against which the paper positions its own three-category risk-factor taxonomy."}],"review_version":1}