REVIEW 3 major objections 5 minor
Qualifying and Quantifying Risk Under the EU AI Act
T0 review · 3 major / 5 minor · reviewed 2026-08-14 · deepseek-v4-flash
Pith's one-line read The EU AI Act's risk definition, read carefully, is a severity-first balancing test, not an expected-risk formula, so protecting fundamental rights does not require monetising them.
desk verdict A clear and useful interpretive paper whose central 'severity-first' claim is a plausible normative recommendation, not something the AI Act's text actually implies; worth peer review with revisions. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
Two-step balancing framework with a severity-first combination rule. Step 1 balances potential harm to protected rights against the system's legitimate purpose; Step 2 balances the resulting risk without intervention against the impact of regulatory measures, choosing avoidance, reduction, or acceptance. The severity-first rule orders the analysis—severity threshold before probability—so high-severity harms cannot be traded away by low probability, and it makes the Act's classification provisions (Art. 5 prohibitions, Art. 6(3) declassification, Annex III use cases) cohere as one balancing analysis.
What would settle it
A concrete refutation would be any official interpretation or court ruling that classifies a high-severity, very-low-probability harm as minimal risk, or an Annex III addition justified by the high frequency of low-severity harm—either would show that combination is not severity-first.
Extended reading notes
Core claim
The paper's central claim is that the EU AI Act's risk-based approach is best understood as a severity-first balancing framework rather than an expected-risk calculation. The 'combination' in Art. 3(2) is not multiplication; it is a structured balance of four factors: the expected risk of the system without intervention, the benefits of its intended purpose, the risk reduction achieved by regulation, and the costs regulation imposes on providers, deployers, and regulators. Severity is assessed before probability because the Act protects fundamental rights: a sufficiently grave harm is unacceptable or high-risk even at extremely low probability, as with the ban on real-time remote biometric identification in public spaces, while a later finding of very low probability can declassify a system under Art. 6(3). The authors conclude that rights and quantification align if severity is measured on an ordinal scale rather than in monetary units, and that the choice of measurement methodology is a political decision with regulatory consequences.
Load-bearing premise
The argument assumes that the AI Act's separate risk provisions—prohibitions, declassification, and Annex III—instantiate one coherent severity-first balancing rule; if the Act is deliberately open-textured and other readings are equally valid, the inference from selected examples does not generalize.
Editorial extensions
If this is right
- Art. 5 prohibitions become severity-based: a harm grave enough is banned regardless of probability, with probability entering only as a secondary check.
- Art. 6(3) declassification becomes the probability stage: an Annex III system is high-risk by severity, but can drop to minimal risk if the concrete application shows no significant probability of harm.
- Fundamental-rights impact can be assessed ordinally (for example low, medium, high, very high) without monetary units, so the Commission's statement that rights cannot be monetised does not block risk assessment.
- Requiring providers and deployers to report risk under several interpretations of probability would limit 'risk hacking' through self-serving choices.
- The two-step balance can guide updates to Annex III under Art. 7 and the design of risk-management standards under Art. 9.
Reading between the lines
- Beyond the paper: an official severity-first reading would imply that conformity assessment resources should be spent mostly on systems that pass a severity screen, not across all systems uniformly.
- Beyond the paper: the two-step framework can be turned into a testable procedure for Art. 7—classify a candidate use case as high-risk if its severity ranking matches Annex III entries, independent of its probability.
- Beyond the paper: 'risk hacking' could be countered by dual reporting—asking firms to file both expected-risk and severity-first classifications and auditing cases where the two diverge.
- Beyond the paper: the same severity-first lens could be applied to risk provisions in adjacent EU data-protection and digital-services law, though the paper itself does not extend the claim there.
Signed reviews
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The paper addresses the tension between the EU AI Act's quantitative definition of risk ('the combination of probability and severity', Art. 3(2)) and the qualitative nature of harms to fundamental rights. It proposes a two-step balancing framework: first, balance the potential harm to fundamental rights against the intended purpose of the AI system; second, balance the resulting risk against the impact of regulatory intervention. It then analyzes the three components of risk (probability, severity, combination), arguing that the Act implicitly adopts a 'severity-first' approach in which severity is assessed before probability and the 'combination' is a balancing analysis rather than expected risk. The paper concludes with a warning about 'risk hacking' by providers who might exploit ambiguity in risk quantification to underclassify their systems.
Significance. If the paper's interpretation were accepted, it would provide a principled way to reconcile fundamental rights protection with risk quantification, implying that ordinal severity rankings can replace monetary valuation. The paper is clearly written, interdisciplinary, and engages seriously with both legal scholarship and technical literature; its discussion of ambiguity in probability and the notion of 'risk hacking' are valuable contributions. However, the central interpretive claim—that Art. 3(2) 'implies' a severity-first balancing analysis—is not robustly demonstrated, and the paper's practical utility depends on this claim. The two-step framework is a plausible normative proposal, but the paper overstates its textual support.
major comments (3)
- [Section 4] The claim that Art. 3(2) 'implies' a severity-first approach is not supported by the cited provisions. Art. 5(1)(h) is a categorical prohibition of a specific practice (real-time remote biometric identification); as a per se ban, it shows that the legislator singled out certain practices, but it does not demonstrate that the general definition of 'combination' is to be operationalized severity-first. Conversely, Art. 5(1)(a)-(b) include explicit probability elements ('causes or is reasonably likely to cause significant harm'), and the manuscript merely asserts that these are a 'secondary evaluation' without textual support. Art. 6(3) uses 'does not pose a significant risk of harm', which is a joint probability-severity standard, not a severity-first ordering. Because the manuscript does not systematically audit all risk-relevant provisions (e.g., Arts. 5, 6, 7, 9, 13, 14, Annex III), the inference from selected examples to a general severity-first principle is overreaching. I recommend either weakening the claim to 'consistent with' or adding a systematic analysis of the full set of risk-relevant provisions.
- [Sections 2.4 and 3.3] The interpretation of 'combination' as a balancing analysis that includes the system's purpose and the costs of regulatory intervention goes beyond the statutory definition. Art. 3(2) defines risk as a combination of probability and severity of harm; it does not mention purpose or regulatory burden. The manuscript infers these additional factors from the Act's objectives (Recitals 4-6) and from the existence of exceptions in Art. 5, but this is an interpretive construction rather than an implication of the text. The paper should present the balancing analysis explicitly as a normative framework for implementation, or ground it in specific provisions that mention acceptable risk levels and proportionality (e.g., Art. 9(5)), rather than presenting it as the Act's own reading.
- [Section 2.4] The two-step framework is described as 'the AI Act's risk-based approach,' but the Act does not prescribe this specific ordering. Step 1 (balancing harm vs. purpose) and Step 2 (balancing risk vs. regulatory intervention) are reconstructions that the authors impose onto the Act's structure. This is acceptable as an analytic proposal, but the paper should avoid stating that this is what the AI Act 'does' without precise statutory anchors. The strength of the severity-first claim depends on the reader accepting this framework as the Act's own, so the presentation should distinguish between textual mandate and authorial proposal.
minor comments (5)
- [Abstract / Section 1] The term 'risk hacking' appears in the abstract and in Section 1 but is not formally defined; consider providing a one-sentence definition at first use.
- [Section 3.1] The rain probability example is extensive; trimming it to the 'event definition' and 'accumulation' points would make the connection to the AI Act clearer.
- [Figure 2] The four panels are informative, but the text does not explain the axes beyond 'Severity' and 'Probability'; adding a brief legend and explicit labels for the 'blind spot' region would improve readability.
- [Section 5 (footnote 20)] Footnote 20 mentions the 'Digital Omnibus for AI' proposal without explaining what it is; a short parenthetical description would help the reader.
- [Section 4] The sentence citing Malgieri and Santos (2025) and Council of Europe (2024) as support for the severity-first approach would benefit from a brief statement of what those sources actually argue, as this is a key piece of external support.
Circularity Check
No circularity: the severity-first claim is an independent statutory interpretation, not a reduction of its inputs.
full rationale
The paper is a non-empirical legal analysis. Its central claim—that Art. 3(2)'s 'combination' is implicitly operationalized as a severity-first balancing analysis (Section 4, 'AI Act implies a severity-first approach')—is advanced by statutory examples (Art. 5(1)(h) categorical ban; Annex III high-risk list; Art. 6(3) declassification) and by independent authorities (Malgieri and Santos 2025; Council of Europe 2024; Yeung and Bygrave 2022). Nothing in the derivation chain is fitted to a subset of data and then relabeled as a prediction. The only formal object, Expected Risk = Σ E P(E) × s(E), is a standard definition used as a benchmark against which the Act's classification criteria are compared, not an input from which the Act's behavior is derived. The paper's own framework in Section 2.4 is presented as an interpretive proposal ('we argue that these two concepts are not at odds, suggesting a two-step framework'), and its conclusion is an inference about the statute's structure, not an equation that folds its assumptions back into its output. Self-citations to Gasiola (2025) appear for ancillary points—the non-inclusion of a distinct limited-risk level, the abstract risk assessment, and the balancing rationale for Art. 5 exceptions—but those points are also grounded in the statutory text and in non-self citations (e.g., De Gregorio and Dunn 2022; Mahler 2021). The severity-first reading is not supported by citing Gasiola alone. Whether the reading is the best interpretation of the Act is a substantive legal-correctness question, not a circularity question. I therefore find no significant circularity.
Assumptions & free parameters
assumptions (5)
- domain assumption The EU AI Act's definition of risk is intended to be operationalized and quantified.
- domain assumption Fundamental rights harms can be assessed on an ordinal scale, and such ordering is sufficient for risk quantification.
- domain assumption Courts' balancing decisions reveal a consistent preference ordering that can be used to scale severity.
- ad hoc to paper The AI Act's risk-based approach is coherent enough to be captured by a single two-step balancing framework.
- ad hoc to paper The 'combination' in Art. 3(2) AIA includes not only probability and severity but also the purpose of the system and the impact of regulation.
Cite this review
Pith. "Pith review of Qualifying and Quantifying Risk Under the EU AI Act." pith.science (2026). https://pith.science/paper/HOVHBOAI
@misc{pith2026260808564,
author = {Pith},
title = {Pith review of: Qualifying and Quantifying Risk Under the EU AI Act},
year = {2026},
howpublished = {\url{https://pith.science/paper/HOVHBOAI}},
note = {Machine review of arXiv:2608.08564}
}
read the original abstract
The EU AI Act uses a risk-based approach to regulate AI systems, calibrating the intensity of regulation according to the risks they pose. While the term 'risk' implies quantification, resulting from the combination of the probability and severity of harm, the AI Act refers to risks to fundamental rights, thereby engaging a qualitative perspective. In this piece, we address this puzzle using a two-step framework under which the EU AI Act balances risks with the protection of fundamental rights, the legitimate purposes of providers and deployers, and the impacts of regulatory measures on providers, deployers, and regulators. We discuss this framework against the backdrop of potential approaches to quantifying risks, with a specific focus on defining and measuring the main components of the concept of risk: probability, severity, and their combination. We suggest that the protection of fundamental rights and risk quantification can be aligned by incorporating quantification methodologies into the proposed framework. In particular, the AI Act implies a balancing analysis that uses a severity-first approach to classify and quantify the risks posed by AI systems. The integrated framework not only helps to clarify the AI Act's risk-based approach, but can also inform technical and implementation choices. Finally, we conclude that if the risk quantification methodology or its application to the protection of fundamental rights is left to providers and deployers, there is potential for 'risk hacking', which could lead to the underclassification of AI systems and subsequent regulatory shortcuts.
Figures
Reviewed August 14, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.