{"id":"3ac95e80-f029-4e83-bcf3-45f24fd727db","arxiv_id":"2608.08564","paper_version":1,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":6.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":0,"one_line_summary":"The EU AI Act's risk definition implies a severity-first balancing approach, not a simple probability-times-severity product.","lead":"This paper argues that the EU AI Act's definition of risk should be read as a 'severity-first' balancing test: regulators should first weigh how severe a harm could be, then consider how likely it is. It proposes a two-step framework to reconcile quantified risk with the protection of fundamental rights.","discovery_kind":"new_application","skeptic_critique":{"model":"deepseek-v4-flash","headline":"The severity-first reading is not implied by the AI Act: Article 5 prohibitions are largely per se bans, and several include explicit probability tests; the paper's selective examples do not establish a general 'combination' rule.","rationale":"The paper is a well-structured interpretive contribution: it identifies a real tension between the quantitative definition of risk in Art. 3(2) and the qualitative nature of fundamental rights, and it usefully surveys the ambiguity in 'probability,' 'severity,' and 'combination.' The two-step balancing framework and the discussion of ordinal severity scales are valuable, and the 'risk hacking' concern is a legitimate policy insight. The central claim, however, is that the AI Act 'implies' a severity-first approach, not merely that such an approach is advisable or possible. That implication is not established. The examples chosen (Art. 5(1)(h) and Annex III) are examples of categorical legislative judgments, not illustrations of a severity-first decision procedure operating within the Art. 3(2) definition. Moreover, Art. 5(1)(a)-(b) explicitly invoke probability ('reasonably likely'), which undercuts the claim that severity is always assessed first. The paper's response—that probability is a 'secondary evaluation'—is asserted without textual support or a systematic survey of counterexamples. This is precisely the coherence gap the reader identified: the paper presupposes that all risk-relevant provisions instantiate one 'combination' rule, but a careful reading shows a mix of per se bans, probability-inclusive tests, and joint standards. The appropriate remedy is to soften the claim from 'implies' to 'is best read as' or 'we propose,' and to provide a systematic table of how each provision treats probability and severity. With that revision, the paper remains a strong and useful contribution. I therefore retain the reader's CONDITIONAL verdict: the concern is real but addressable, and the paper's core framework and policy warnings survive a more modest claim.","tokens_in":13612,"tokens_out":4765,"duration_ms":49457,"concrete_test":"Construct a provision-by-provision audit: for each risk-relevant provision (Art. 5(1)(a)-(h), Art. 6(1)-(3), Art. 7(1), Art. 9(2), Art. 13(3), Art. 14(2), Annex III), classify the statutory trigger as (i) per se / categorical, (ii) severity-only, (iii) probability-only, (iv) joint probability-severity, or (v) sequential severity-first. Count the classifications. If the per se or joint categories outnumber severity-first sequences, or if Art. 5(1)(a)-(b) cannot be re-read without adding an unstated 'secondary evaluation' step, the claim that the AI Act 'implies' severity-first fails and should be softened to 'proposes' or 'is best read as'.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The central claim—that the AI Act implicitly operationalizes Art. 3(2)'s 'combination' as a severity-first balancing analysis—rests on a selective inference from Art. 5 and Annex III, and the text does not support the strength of the claim. First, Art. 5(1) is a list of prohibited practices; most items are per se bans (e.g., social scoring in Art. 5(1)(c), untargeted scraping in Art. 5(1)(e), emotion inference in Art. 5(1)(f)) that are triggered by the practice itself, not by a prior severity ranking followed by a probability check. Second, at least two provisions—Art. 5(1)(a) and (b)—make probability explicit: the prohibited conduct must 'cause or be reasonably likely to cause significant harm.' The paper acknowledges this but merely asserts that probability is a 'secondary evaluation' (Section 4). That is an interpretive preference, not an implication of the statutory text. Third, Annex III is a legislative list of high-risk areas; Art. 6(3) allows declassification only where the system 'does not pose a significant risk of harm,' which is a joint probability-severity standard, not a severity-first rule. The paper does not provide a systematic audit of all risk-relevant provisions (Arts. 5, 6, 7, 9, 13, 14 and Annex III), so the 'implies' claim is unsupported. The paper's decisive example, real-time biometric ID (Art. 5(1)(h)), is a categorical ban; it shows how some practices are singled out for prohibition but says nothing about how the 'combination' operator in Art. 3(2) should be computed for systems that are not categorically banned.","agreement_with_reader":"partial"},"referee_report":{"model":"deepseek-v4-flash","summary":"The paper addresses the tension between the EU AI Act's quantitative definition of risk ('the combination of probability and severity', Art. 3(2)) and the qualitative nature of harms to fundamental rights. It proposes a two-step balancing framework: first, balance the potential harm to fundamental rights against the intended purpose of the AI system; second, balance the resulting risk against the impact of regulatory intervention. It then analyzes the three components of risk (probability, severity, combination), arguing that the Act implicitly adopts a 'severity-first' approach in which severity is assessed before probability and the 'combination' is a balancing analysis rather than expected risk. The paper concludes with a warning about 'risk hacking' by providers who might exploit ambiguity in risk quantification to underclassify their systems.","tokens_in":14016,"tokens_out":7951,"duration_ms":73807,"significance":"If the paper's interpretation were accepted, it would provide a principled way to reconcile fundamental rights protection with risk quantification, implying that ordinal severity rankings can replace monetary valuation. The paper is clearly written, interdisciplinary, and engages seriously with both legal scholarship and technical literature; its discussion of ambiguity in probability and the notion of 'risk hacking' are valuable contributions. However, the central interpretive claim—that Art. 3(2) 'implies' a severity-first balancing analysis—is not robustly demonstrated, and the paper's practical utility depends on this claim. The two-step framework is a plausible normative proposal, but the paper overstates its textual support.","major_comments":[{"comment":"The claim that Art. 3(2) 'implies' a severity-first approach is not supported by the cited provisions. Art. 5(1)(h) is a categorical prohibition of a specific practice (real-time remote biometric identification); as a per se ban, it shows that the legislator singled out certain practices, but it does not demonstrate that the general definition of 'combination' is to be operationalized severity-first. Conversely, Art. 5(1)(a)-(b) include explicit probability elements ('causes or is reasonably likely to cause significant harm'), and the manuscript merely asserts that these are a 'secondary evaluation' without textual support. Art. 6(3) uses 'does not pose a significant risk of harm', which is a joint probability-severity standard, not a severity-first ordering. Because the manuscript does not systematically audit all risk-relevant provisions (e.g., Arts. 5, 6, 7, 9, 13, 14, Annex III), the inference from selected examples to a general severity-first principle is overreaching. I recommend either weakening the claim to 'consistent with' or adding a systematic analysis of the full set of risk-relevant provisions.","section":"Section 4"},{"comment":"The interpretation of 'combination' as a balancing analysis that includes the system's purpose and the costs of regulatory intervention goes beyond the statutory definition. Art. 3(2) defines risk as a combination of probability and severity of harm; it does not mention purpose or regulatory burden. The manuscript infers these additional factors from the Act's objectives (Recitals 4-6) and from the existence of exceptions in Art. 5, but this is an interpretive construction rather than an implication of the text. The paper should present the balancing analysis explicitly as a normative framework for implementation, or ground it in specific provisions that mention acceptable risk levels and proportionality (e.g., Art. 9(5)), rather than presenting it as the Act's own reading.","section":"Sections 2.4 and 3.3"},{"comment":"The two-step framework is described as 'the AI Act's risk-based approach,' but the Act does not prescribe this specific ordering. Step 1 (balancing harm vs. purpose) and Step 2 (balancing risk vs. regulatory intervention) are reconstructions that the authors impose onto the Act's structure. This is acceptable as an analytic proposal, but the paper should avoid stating that this is what the AI Act 'does' without precise statutory anchors. The strength of the severity-first claim depends on the reader accepting this framework as the Act's own, so the presentation should distinguish between textual mandate and authorial proposal.","section":"Section 2.4"}],"minor_comments":[{"comment":"The term 'risk hacking' appears in the abstract and in Section 1 but is not formally defined; consider providing a one-sentence definition at first use.","section":"Abstract / Section 1"},{"comment":"The rain probability example is extensive; trimming it to the 'event definition' and 'accumulation' points would make the connection to the AI Act clearer.","section":"Section 3.1"},{"comment":"The four panels are informative, but the text does not explain the axes beyond 'Severity' and 'Probability'; adding a brief legend and explicit labels for the 'blind spot' region would improve readability.","section":"Figure 2"},{"comment":"Footnote 20 mentions the 'Digital Omnibus for AI' proposal without explaining what it is; a short parenthetical description would help the reader.","section":"Section 5 (footnote 20)"},{"comment":"The sentence citing Malgieri and Santos (2025) and Council of Europe (2024) as support for the severity-first approach would benefit from a brief statement of what those sources actually argue, as this is a key piece of external support.","section":"Section 4"}],"recommendation":"major_revision","confidential_remarks":"The paper fits the journal's interdisciplinary scope, but the central claim is overstated relative to the evidence. I would advise the authors to recalibrate the language ('implies' to 'proposes' or 'is consistent with') and to add the systematic audit of risk-relevant provisions. With those changes, the paper could be a strong contribution to the debate on AI risk regulation."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Colleague,\n\nThe paper is a competent, clearly written interpretive piece on how to operationalize the AI Act's risk definition. The genuinely new bit is the 'severity-first' reading of Art 3(2)'s 'combination' — the idea that regulators should assess severity before probability, and that probability matters only as a secondary check. The two-step balancing framework is less novel; it largely restates standard fundamental rights proportionality analysis.\n\nWhere the paper is good: it lays out the ambiguity in 'probability' (event definition, epistemic uncertainty) and 'severity' (measurability, units) in a way that is accessible and technically informed. The ordinal approach to severity, drawing on Alexy and others, is sensible. The 'risk hacking' point — that providers will game whatever quantification method is chosen — is well taken.\n\nThe soft spot is the strength of the central claim. The paper says the AI Act 'implies' a severity-first approach. That is not supported by the text. Several provisions use a joint probability-severity standard: Art 5(1)(a) and (b) prohibit conduct that 'causes or is reasonably likely to cause significant harm', which is a probability-qualified severity test. Art 6(3) declassification turns on 'does not pose a significant risk of harm', again a combined standard. Art 5(1)(c), (e), (f) are per se bans triggered by the practice itself, not by a severity ranking. The paper's go-to example, real-time biometric identification (Art 5(1)(h)), is a categorical prohibition; it says nothing about how the combination operator should be applied to systems that are not categorically banned. So the 'implies' claim is an interpretive preference, not a textual necessity.\n\nThe other leap is reading 'combination' as including purpose and regulatory costs. Art 3(2) defines risk as the combination of probability and severity only. The balancing of purposes and regulatory impacts may be a sensible normative framework, but it is not in the statutory definition. The paper conflates what the Act should mean with what it says.\n\nThe authors cite Malgieri and Santos (2025) and the Council of Europe HUDERIA methodology, which already suggest probability is secondary when fundamental rights are at stake. The paper's contribution is organizing that into a specific 'severity-first' rule and connecting it to Art 3(2). That is useful, but it should be framed as a recommended interpretation, not an implication.\n\nRecommendation: worthwhile for peer review, but the authors need to soften 'implies' to something like 'is best read as', and ideally provide a more systematic read of Arts 5, 6, 7, 9 and Annex III, or explicitly argue why open texture is acceptable. As it stands, the central claim is a normative proposal in descriptive clothing.\n\nThis is a paper for AI law and policy readers, not for a technical CS audience. I'd send it to a serious referee.","headline":"A clear and useful interpretive paper whose central 'severity-first' claim is a plausible normative recommendation, not something the AI Act's text actually implies; worth peer review with revisions.","tokens_in":14480,"tokens_out":2399,"would_cite":false,"duration_ms":24402,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"deepseek-v4-flash","headline":"The EU AI Act's risk definition, read carefully, is a severity-first balancing test, not an expected-risk formula, so protecting fundamental rights does not require monetising them.","keywords":["EU AI Act","risk-based regulation","fundamental rights","severity-first","risk quantification","probability and severity","risk hacking","balancing analysis"],"falsifier":"A concrete refutation would be any official interpretation or court ruling that classifies a high-severity, very-low-probability harm as minimal risk, or an Annex III addition justified by the high frequency of low-severity harm—either would show that combination is not severity-first.","tokens_in":13433,"feed_emoji":"⚖️","tokens_out":7772,"duration_ms":72107,"temperature":0.7,"pith_summary":"This paper argues that the EU AI Act's definition of risk—'the combination of the probability of an occurrence of harm and the severity of that harm'—does not force regulators to put a monetary value on fundamental rights. Instead, the Act implicitly uses a severity-first balancing analysis: first ask how severe the harm would be, then consider its probability, the system's intended purpose, and the cost of regulating. The authors ground this in a two-step framework: balance potential harm against purpose, then balance the unregulated risk against the impact of regulatory measures on providers, deployers, and regulators. If the reading is right, fundamental-rights protection and risk quantification are compatible, and the Act's three risk levels can be derived without monetising rights. The same reading exposes a regulatory danger: if quantification methodology is left to providers and deployers, they may choose interpretations that underclassify their systems ('risk hacking').","feed_headline":"EU AI Act weighs severity before probability, paper argues","feed_subtitle":"Severity-first reading reconciles rights-based harms with quantitative risk and warns of 'risk hacking'.","key_machinery":"Two-step balancing framework with a severity-first combination rule. Step 1 balances potential harm to protected rights against the system's legitimate purpose; Step 2 balances the resulting risk without intervention against the impact of regulatory measures, choosing avoidance, reduction, or acceptance. The severity-first rule orders the analysis—severity threshold before probability—so high-severity harms cannot be traded away by low probability, and it makes the Act's classification provisions (Art. 5 prohibitions, Art. 6(3) declassification, Annex III use cases) cohere as one balancing analysis.","core_discovery":"The paper's central claim is that the EU AI Act's risk-based approach is best understood as a severity-first balancing framework rather than an expected-risk calculation. The 'combination' in Art. 3(2) is not multiplication; it is a structured balance of four factors: the expected risk of the system without intervention, the benefits of its intended purpose, the risk reduction achieved by regulation, and the costs regulation imposes on providers, deployers, and regulators. Severity is assessed before probability because the Act protects fundamental rights: a sufficiently grave harm is unacceptable or high-risk even at extremely low probability, as with the ban on real-time remote biometric identification in public spaces, while a later finding of very low probability can declassify a system under Art. 6(3). The authors conclude that rights and quantification align if severity is measured on an ordinal scale rather than in monetary units, and that the choice of measurement methodology is a political decision with regulatory consequences.","pith_inferences":["Beyond the paper: an official severity-first reading would imply that conformity assessment resources should be spent mostly on systems that pass a severity screen, not across all systems uniformly.","Beyond the paper: the two-step framework can be turned into a testable procedure for Art. 7—classify a candidate use case as high-risk if its severity ranking matches Annex III entries, independent of its probability.","Beyond the paper: 'risk hacking' could be countered by dual reporting—asking firms to file both expected-risk and severity-first classifications and auditing cases where the two diverge.","Beyond the paper: the same severity-first lens could be applied to risk provisions in adjacent EU data-protection and digital-services law, though the paper itself does not extend the claim there."],"forward_implications":["Art. 5 prohibitions become severity-based: a harm grave enough is banned regardless of probability, with probability entering only as a secondary check.","Art. 6(3) declassification becomes the probability stage: an Annex III system is high-risk by severity, but can drop to minimal risk if the concrete application shows no significant probability of harm.","Fundamental-rights impact can be assessed ordinally (for example low, medium, high, very high) without monetary units, so the Commission's statement that rights cannot be monetised does not block risk assessment.","Requiring providers and deployers to report risk under several interpretations of probability would limit 'risk hacking' through self-serving choices.","The two-step balance can guide updates to Annex III under Art. 7 and the design of risk-management standards under Art. 9."],"supporting_citations":[{"why":"Establishes the existing debate on whether risk-based approaches like the AI Act's are compatible with qualitative fundamental-rights protection, which this paper answers.","marker":"Gellert (2021)"},{"why":"Supplies the technical definition of risk as a probability-severity combination that Art. 3(2) mirrors, framing the quantification puzzle.","marker":"Mahler (2021)"},{"why":"Provides the view of fundamental rights as moral boundaries, which underlies the paper's severity-first claim that grave harms outweigh purpose and probability.","marker":"Yeung and Bygrave (2022)"},{"why":"Supplies the ordinal, perception-inclusive method for assessing severity of impacts on fundamental rights, the paper's answer to the units problem.","marker":"Malgieri and Santos (2025)"},{"why":"Provides the prior analysis of the AI Act's risk-based approach as a balancing and classification decision, including the Art. 6(3) declassification logic this paper builds on.","marker":"Gasiola (2025)"},{"why":"Frames the AI Act as combining risk regulation with risk-based calibration, grounding the two-step framework's structure.","marker":"De Gregorio and Dunn (2022)"},{"why":"Is the official Impact Assessment that declares fundamental-rights impacts not quantifiable in monetary terms, the position this paper argues against.","marker":"European Commission (2021)"},{"why":"Explains the acceptable-residual-risk mechanism under Art. 9, which anchors Step 2's choice of regulatory intervention.","marker":"Schuett (2024)"}],"fun_headline_variants":["Severity-first: the AI Act's real risk logic","AI Act's risk is a balance, not a multiplication","Risk hacking: the hidden danger of the AI Act","EU AI Act: severity before probability, always","Quantifying EU AI Act risk without crippling rights"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The argument assumes that the AI Act's separate risk provisions—prohibitions, declassification, and Annex III—instantiate one coherent severity-first balancing rule; if the Act is deliberately open-textured and other readings are equally valid, the inference from selected examples does not generalize.","fun_headline_variants_meta":{"raw":{"variants":["Severity-first: the AI Act's real risk logic","AI Act's risk is a balance, not a multiplication","Risk hacking: the hidden danger of the AI Act","EU AI Act: severity before probability, always","Quantifying EU AI Act risk without crippling rights"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.001302,"raw_usage":{"total_tokens":5331,"prompt_tokens":987,"completion_tokens":4344,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":603,"completion_tokens_details":{"reasoning_tokens":4267}},"tokens_in":603,"tokens_out":4344,"duration_ms":32063,"temperature":1.0,"reasoning_tokens":4267,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-14T04:30:31.475821+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"A concrete refutation would be any official interpretation or court ruling that classifies a high-severity, very-low-probability harm as minimal risk, or an Annex III addition justified by the high frequency of low-severity harm—either would show that combination is not severity-first.","supporting_citations":[{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Establishes the existing debate on whether risk-based approaches like the AI Act's are compatible with qualitative fundamental-rights protection, which this paper answers."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Supplies the technical definition of risk as a probability-severity combination that Art. 3(2) mirrors, framing the quantification puzzle."},{"cited_title":"and Bygrave, L","cited_arxiv_id":null,"evidence_quote":"Provides the view of fundamental rights as moral boundaries, which underlies the paper's severity-first claim that grave harms outweigh purpose and probability."},{"cited_title":"and Santos, C","cited_arxiv_id":null,"evidence_quote":"Supplies the ordinal, perception-inclusive method for assessing severity of impacts on fundamental rights, the paper's answer to the units problem."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Provides the prior analysis of the AI Act's risk-based approach as a balancing and classification decision, including the Art. 6(3) declassification logic this paper builds on."},{"cited_title":"and Dunn, P","cited_arxiv_id":null,"evidence_quote":"Frames the AI Act as combining risk regulation with risk-based calibration, grounding the two-step framework's structure."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Is the official Impact Assessment that declares fundamental-rights impacts not quantifiable in monetary terms, the position this paper argues against."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Explains the acceptable-residual-risk mechanism under Art. 9, which anchors Step 2's choice of regulatory intervention."}],"review_version":1}