• Skip to main content
  • Skip to secondary menu
  • Skip to primary sidebar
  • Skip to footer
Montreal AI Ethics Institute

Montreal AI Ethics Institute

Democratizing AI ethics literacy

  • Articles
    • Public Policy
    • Privacy & Security
    • Human Rights
      • Ethics
      • JEDI (Justice, Equity, Diversity, Inclusion
    • Climate
    • Design
      • Emerging Technology
    • Application & Adoption
      • Health
      • Education
      • Government
        • Military
        • Public Works
      • Labour
    • Arts & Culture
      • Film & TV
      • Music
      • Pop Culture
      • Digital Art
  • Columns
    • AI Policy Corner
    • Recess
    • Tech Futures
  • The AI Ethics Brief
  • AI Literacy
    • Research Summaries
    • AI Ethics Living Dictionary
    • Learning Community
  • The State of AI Ethics Report
    • State of AI Ethics Report Volume 8 (2026): Call for Contributors
    • Volume 7 (November 2025)
    • Volume 6 (February 2022)
    • Volume 5 (July 2021)
    • Volume 4 (April 2021)
    • Volume 3 (Jan 2021)
    • Volume 2 (Oct 2020)
    • Volume 1 (June 2020)
  • About
    • Our Contributions Policy
    • Our Open Access Policy
    • Contact
    • Donate

Acceptable Risks in Europe’s Proposed AI Act: Reasonableness and Other Principles for Deciding How Much Risk Management Is Enough

September 7, 2023

🔬 Research Summary by Dr. Henry Fraser, a Research Fellow in Law, Accountability, and Data Science at the Centre of Excellence for Automated Decision-Making and Society.

[Original paper by Henry Fraser and José-Miguel Bello y Villarino]


Overview: The European Union’s draft ‘AI Act’ aims to promote “trustworthy” AI with a proportionate regulatory burden. The final text of the Act is currently under negotiation between the European Commission, the European Parliament, and the Council of the European. This paper critically evaluates competing approaches to risk acceptability that are up for negotiation, explaining why any obligation to render risks from AI systems “acceptable” must be qualified by considering what is reasonable in all the circumstances.


Introduction

You are the developer of an AI system that will evaluate University applications throughout Europe. Under Article 9 of Europe’s draft AI Act, which may become law as early as 2024, you have an obligation to implement risk management because the system is “high-risk”.  Risk management must ensure that any remaining risks are “acceptable.” What does that even mean? How do you decide when risks from high-risk AI systems (with potential impacts on safety, rights, health, or the environment) are acceptable?

The final text of the Act (actually called a Proposal for a Regulation Laying Down Harmonised Rules on Artificial Intelligence) is currently under negotiation between the three main branches of the European government: the Commission, the Council, and the Parliament. Among many other thorny issues for negotiation, negotiators choose between two competing approaches to risk acceptability. One approach, proposed by the European Commission, would require risks to be reduced “as far as possible” (AFAP) in design and development, with remaining risks subject to further mitigation. The Parliament, by contrast, proposes to introduce considerations of what is “reasonably” acceptable. 

This paper critically evaluates the two approaches, exploring how AFAP has been interpreted in other contexts and drawing on negligence and other laws to understand what “reasonably acceptable” risks might mean. It finds that the Parliament’s approach is more compatible with the AI Act’s overarching goals of promoting trustworthy AI with a proportionate regulatory burden. 

Key Insights

Why does risk acceptability matter?

Trustworthiness and proportionate regulatory burden are the AI Act’s two main goals. Because there are so many issues under consideration in negotiations about the Act – from the definition of AI to the responsibilities of foundation model developers – the approach to risk acceptability has mostly flown under the radar. That belies its importance. The rules about when risks are acceptable and when they do not determine how “trustworthy” AI systems really are and how much burden the AI Act will place on AI development.  

It’s a bad idea to require AI risks to be reduced or eliminated “as far as possible.”

A requirement to reduce risks as far as possible, which the Commission’s version of the Act contemplates, is exacting if taken literally. AI outputs are known to be “emergent” (unpredictable), and it is always possible to implement just one more measure to reduce risk. Our research shows that the European Commission has historically taken a very narrow approach to the AFAP risk criterion in the context of medical devices. The Commission went so far as to require a change to the ISO standard for medical device risk management, stating that in Europe, medical device risks had to be reduced as far as possible “without there being room for economic considerations.” Our survey of industry responses to this change indicated that such a narrow risk acceptability criterion created uncertainty on where to draw the line for risk management. It seemed to encourage businesses to conceal their cost-benefit analysis around risk management rather than disregard economic considerations. The same problems are likely to arise in the AI context.

It makes sense to factor in the costs and benefits of risk management when judging the acceptability of AI risks

The Parliament’s proposed approach to risk management for high-risk AI would introduce considerations of reasonableness, proportionality, and the impact of risk management on the potential benefits of the AI system into risk acceptability judgments. Drawing lessons from negligence law (par excellence about when risks are unacceptable) and medical device regulation, our paper explains how principles of reasonableness could allow AI developers to make more principled risk acceptability judgments. It would allow them to factor in various kinds of cost-benefit and risk-benefit analyses, including whether the cost of a given risk management measure is worth the risk reduction, whether risk management negatively impacts the overall benefit of an AI system, and whether risks are significant enough to warrant expenditure of finite risk management resources.

Between the lines

The choice between the stringent “as far as possible” risk acceptability criterion and the more flexible approach permitted by introducing reasonableness should be informed by the overall architecture of the AI Act and by the issues of public policy that are at stake. The Act contemplates that its requirements, including risk management, will be met through certification against technical standards – mostly self-certification. It also states that risk management should consider the “state of the art,” including as reflected in standards. In effect, this means that technical standards and the state of the art play the role of a pressure valve: once you meet the state of the art, you can say you’ve reduced a risk “as far as possible.” 

But why should it fall to technical standards bodies or to the big tech companies whose practices shape the state of the art to decide when risks to fundamental rights from AI are acceptable? It is not clear they have the expertise in human rights or the political legitimacy to exercise this kind of discretion over matters of public policy. 

The benefit of a reasonableness approach is that it brings all the trade-offs involved in risk acceptability judgments to the fore. It assumes value-laden judgments. Ultimately, the legitimacy of these judgments will need to be supported by input from stakeholders and affected groups and by guidance from regulators with the requisite expertise and legitimacy.

Want quick summaries of the latest research & reporting in AI ethics delivered to your inbox? Subscribe to the AI Ethics Brief. We publish bi-weekly.

Primary Sidebar

SAIER Volume 8 (2026)

SAIER Volume 8 (2026) Call for Contributors

🔍 SEARCH

Spotlight

Vertically- and horizontally-placed chess boards and chess pieces

Tech Futures: At the Frontier of Fear, Uncertainty and Doubt

Tech Futures: Introducing the Resist List

An abstract spiral of dark circles appears at the centre, resembling a tornado. Several vintage magazine covers and advertisements are being drawn toward the spiral. The artworks that have already been pulled into it are becoming distorted and replaced with clusters of numbers representing their numerical embeddings.

Tech Futures: Better Imagination for Better Tech Futures

This image is a collage with a colourful Japanese vintage landscape showing a mountain, hills, flowers and other plants and a small stream. There are 3 large black data servers placed in the bottom half of the image, with a cloud of black smoke emitting from them, partly obscuring the scenery.

Tech Futures: Crafting Participatory Tech Futures

A network diagram with lots of little emojis, organised in clusters.

Tech Futures: AI For and Against Knowledge

related posts

  • The Watsons Meet Watson: A Call for Carative AI

    The Watsons Meet Watson: A Call for Carative AI

  • Why was your job application rejected: Bias in Recruitment Algorithms? (Part 2)

    Why was your job application rejected: Bias in Recruitment Algorithms? (Part 2)

  • ABScribe: Rapid Exploration of Multiple Writing Variations in Human-AI Co-Writing Tasks using Large ...

    ABScribe: Rapid Exploration of Multiple Writing Variations in Human-AI Co-Writing Tasks using Large ...

  • A Case Study: Increasing AI Ethics Maturity in a Startup

    A Case Study: Increasing AI Ethics Maturity in a Startup

  • Beyond Dependency: The Hidden Risk of Social Comparison in Chatbot Companionship

    Beyond Dependency: The Hidden Risk of Social Comparison in Chatbot Companionship

  • Research summary: Algorithmic Accountability

    Research summary: Algorithmic Accountability

  • Defending Against Authorship Identification Attacks

    Defending Against Authorship Identification Attacks

  • Adding Structure to AI Harm

    Adding Structure to AI Harm

  • How Tech Companies are Helping Big Oil Profit from Climate Destruction

    How Tech Companies are Helping Big Oil Profit from Climate Destruction

  • The Impact of the GDPR on Artificial Intelligence

    The Impact of the GDPR on Artificial Intelligence

Partners

  •  
    U.S. Artificial Intelligence Safety Institute Consortium (AISIC) at NIST

  • Partnership on AI

  • The LF AI & Data Foundation

  • The AI Alliance

Footer


Articles

Columns

AI Literacy

The State of AI Ethics Report


 

About Us


Founded in 2018, the Montreal AI Ethics Institute (MAIEI) is an international non-profit organization equipping citizens concerned about artificial intelligence and its impact on society to take action.

Contact

Donate


  • © 2025 MONTREAL AI ETHICS INSTITUTE.
  • This work is licensed under a Creative Commons Attribution 4.0 International License.
  • Learn more about our open access policy here.
  • Creative Commons License

    Save hours of work and stay on top of Responsible AI research and reporting with our bi-weekly email newsletter.