The European Union should shape its policy on artificial intelligence risks without choosing between harms already being observed and scenarios with extreme consequences, argue Susana Aires and Robert Praas of the Centre for European Policy Studies (CEPS). The two researchers propose an evidence-based framework that considers the likelihood of a risk occurring and its potential impact, at a time when AI systems are becoming more autonomous and the AI Office is beginning to receive stronger tools for supervising general-purpose models with advanced capabilities.
In brief, Susana Aires and Robert Praas argue that the EU should not set “catastrophic” risks against already visible social harms such as disinformation, manipulation, algorithmic discrimination and violations of fundamental rights. The AI Act uses the concept of “systemic risk” for high-impact general-purpose models, while some U.S. states use quantitative thresholds for what they define as “catastrophic risk.” The authors consider the European model more flexible and broader, but also more ambiguous, while U.S. approaches offer greater legal certainty but may overlook cumulative and non-physical harms. They recommend a European framework that compares risks based on evidence, likelihood and impact, and tracks the interaction between technological, infrastructural and socio-political factors. From 1 August 2026, the AI Office may request documentation, model evaluations and access to advanced models, and the authors believe this stage gives the EU an opportunity to test a more active form of anticipatory governance.
The debate over artificial intelligence risks has become increasingly polarised as models acquire new capabilities and can perform tasks with less human intervention. At one end are concerns about risks with potentially very serious effects, ranging from the use of AI to develop weapons or conduct cyberattacks to scenarios in which systems pursue their own objectives and become difficult to control.
At the other end are critics of this perspective, who argue that focusing on extreme scenarios can divert attention from harms already being observed. These include disinformation, manipulation, user exploitation, algorithmic discrimination and effects on fundamental rights.
Aires and Praas consider this divide mistaken. In their assessment, social risks and risks with extreme impacts should be analysed together, because effects such as unemployment, disinformation or environmental degradation can themselves become severe when they accumulate or spread on a large scale.
The debate has intensified with the development of agentic systems capable of planning and executing sequences of actions. The authors cite information recently published by OpenAI and Anthropic about situations in which tested models gained unauthorised access to companies’ systems, as well as investigations into cooperation among multiple agents in at least one attack.
The two researchers use these examples to support the need for a forward-looking policy, without assuming that future risks can be known precisely. In their view, uncertainty about future AI capabilities is a reason for anticipatory planning, not for postponing it.
The European Union and the United States have already begun building different responses around the same general idea: risk-based regulation.
In the EU, the AI Act regulates systems used in areas considered high-risk and imposes additional obligations on providers of general-purpose models with capabilities powerful enough to create systemic risks.
The European concept is qualitative. Systemic risk is linked to models with high impact and sufficiently broad dissemination for negative effects to spread widely across public health, safety, security or fundamental rights.
Some U.S. states, including California, New York and Illinois, have chosen a more quantitative approach to frontier models. In the examples analysed by the CEPS authors, catastrophic risk is associated with thresholds such as more than 50 deaths or serious injuries, or material damage exceeding one billion dollars resulting from loss of control, AI-assisted weapons or autonomous criminal activity.
The difference matters for how developers must assess their systems. Numerical thresholds can make it clearer when an obligation applies, but they limit the analysis to a relatively narrow set of extreme outcomes.
The European model leaves more room to assess different risks and adapt to new technologies. Providers must develop safety and security frameworks and assess systemic risks in an area that is not defined exclusively by numerical thresholds.
For Aires and Praas, this flexibility is one of the AI Act’s advantages, but it is also a vulnerability. The open-ended nature of the definitions can create uncertainty for companies and make enforcement more difficult when authorities and providers must determine what level of risk is acceptable.
The authors also point to structural limitations in the European framework. Centralised enforcement of rules for general-purpose models may allow for more consistent interpretation across the Union, but the system’s effectiveness may be reduced by its focus on preventive obligations and the absence of a European liability framework for harm caused by AI.
In the United States, a narrower and quantified definition of risk may make it easier for authorities to intervene in cases that clearly fall within established thresholds. However, the lack of a uniform framework across states can create a different form of fragmentation, with requirements and standards varying from one jurisdiction to another.
The two researchers describe the choice between these models as a trade-off between adaptability and certainty.
The European approach based on systemic risks is more comprehensive and may be better prepared for problems that are not yet known, but it can create ambiguity for developers and make it harder to bring products to market.
The U.S. approach based on catastrophic risks provides clearer criteria, but may leave a range of effects outside the scope of protection if they do not immediately cause casualties or quantifiable material damage.
Disinformation, manipulation and systemic discrimination are the examples the authors use for such risks. Each can cause widespread harm without reaching, in a single incident, the threshold associated with a major physical disaster.
Aires and Praas believe the EU should not address this problem by narrowing its current definition. Instead, the Union should retain its broad perspective on risks and develop a more strategic method for setting priorities.
This method should start from three elements: the available evidence, the likelihood that a risk will materialise and the scale of its consequences.
Such an assessment would allow authorities to distinguish between highly serious but unlikely scenarios, more frequent risks with moderate effects, and harms that could become systemic through accumulation or spread.
The authors also call for examination of the relationship between technology and the environment in which it is used. The same model can produce different consequences depending on the infrastructure it can access, its level of autonomy, the sector in which it is deployed and the social or political conditions in which it operates.
This approach should also help allocate oversight resources. Authorities cannot investigate all possible risks with the same intensity, and an assessment based on likelihood and impact could determine where additional testing, monitoring or intervention is needed.
The timing is important because the AI Act has entered a new phase of implementation. From 1 August 2026, the AI Office may request documentation, model evaluations and access to relevant frontier models for supervising obligations applicable to general-purpose models.
Aires and Praas say this new level of access gives the Union a concrete opportunity to turn the principles of risk anticipation into practice.
Model testing, analysis of documentation and direct access by the supervisory authority could help build an evidence base on capabilities and vulnerabilities, in a field where many public policy decisions have so far been made with limited information.
For the two researchers, the objective is not to choose between a Europe concerned with fundamental rights and an approach focused exclusively on catastrophic scenarios. They argue that a mature governance system must be able to analyse both categories simultaneously and set priorities according to the actual risk each presents.
The Centre for European Policy Studies (CEPS) is an independent Brussels-based think tank that produces research and analysis on European Union policies. The material is authored by Susana Aires and Robert Praas and represents the authors’ analysis of how the EU should develop its policy for managing AI risks.
The AI Act uses risk as its central regulatory principle and introduces different obligations depending on how systems are used and the potential impact of general-purpose models. For models with systemic risk, the European framework allows centralised supervision through the AI Office.
The CEPS authors’ position is that this architecture should be complemented by a strategic prioritisation method combining harms already demonstrated with rarer scenarios that could nevertheless have potentially very serious consequences.»,
In brief, Susana Aires and Robert Praas argue that the EU should not set “catastrophic” risks against already visible social harms such as disinformation, manipulation, algorithmic discrimination and violations of fundamental rights. The AI Act uses the concept of “systemic risk” for high-impact general-purpose models, while some U.S. states use quantitative thresholds for what they define as “catastrophic risk.” The authors consider the European model more flexible and broader, but also more ambiguous, while U.S. approaches offer greater legal certainty but may overlook cumulative and non-physical harms. They recommend a European framework that compares risks based on evidence, likelihood and impact, and tracks the interaction between technological, infrastructural and socio-political factors. From 1 August 2026, the AI Office may request documentation, model evaluations and access to advanced models, and the authors believe this stage gives the EU an opportunity to test a more active form of anticipatory governance.
The debate over artificial intelligence risks has become increasingly polarised as models acquire new capabilities and can perform tasks with less human intervention. At one end are concerns about risks with potentially very serious effects, ranging from the use of AI to develop weapons or conduct cyberattacks to scenarios in which systems pursue their own objectives and become difficult to control.
At the other end are critics of this perspective, who argue that focusing on extreme scenarios can divert attention from harms already being observed. These include disinformation, manipulation, user exploitation, algorithmic discrimination and effects on fundamental rights.
Aires and Praas consider this divide mistaken. In their assessment, social risks and risks with extreme impacts should be analysed together, because effects such as unemployment, disinformation or environmental degradation can themselves become severe when they accumulate or spread on a large scale.
The debate has intensified with the development of agentic systems capable of planning and executing sequences of actions. The authors cite information recently published by OpenAI and Anthropic about situations in which tested models gained unauthorised access to companies’ systems, as well as investigations into cooperation among multiple agents in at least one attack.
The two researchers use these examples to support the need for a forward-looking policy, without assuming that future risks can be known precisely. In their view, uncertainty about future AI capabilities is a reason for anticipatory planning, not for postponing it.
The European Union and the United States have already begun building different responses around the same general idea: risk-based regulation.
In the EU, the AI Act regulates systems used in areas considered high-risk and imposes additional obligations on providers of general-purpose models with capabilities powerful enough to create systemic risks.
The European concept is qualitative. Systemic risk is linked to models with high impact and sufficiently broad dissemination for negative effects to spread widely across public health, safety, security or fundamental rights.
Some U.S. states, including California, New York and Illinois, have chosen a more quantitative approach to frontier models. In the examples analysed by the CEPS authors, catastrophic risk is associated with thresholds such as more than 50 deaths or serious injuries, or material damage exceeding one billion dollars resulting from loss of control, AI-assisted weapons or autonomous criminal activity.
The difference matters for how developers must assess their systems. Numerical thresholds can make it clearer when an obligation applies, but they limit the analysis to a relatively narrow set of extreme outcomes.
The European model leaves more room to assess different risks and adapt to new technologies. Providers must develop safety and security frameworks and assess systemic risks in an area that is not defined exclusively by numerical thresholds.
For Aires and Praas, this flexibility is one of the AI Act’s advantages, but it is also a vulnerability. The open-ended nature of the definitions can create uncertainty for companies and make enforcement more difficult when authorities and providers must determine what level of risk is acceptable.
The authors also point to structural limitations in the European framework. Centralised enforcement of rules for general-purpose models may allow for more consistent interpretation across the Union, but the system’s effectiveness may be reduced by its focus on preventive obligations and the absence of a European liability framework for harm caused by AI.
In the United States, a narrower and quantified definition of risk may make it easier for authorities to intervene in cases that clearly fall within established thresholds. However, the lack of a uniform framework across states can create a different form of fragmentation, with requirements and standards varying from one jurisdiction to another.
The two researchers describe the choice between these models as a trade-off between adaptability and certainty.
The European approach based on systemic risks is more comprehensive and may be better prepared for problems that are not yet known, but it can create ambiguity for developers and make it harder to bring products to market.
The U.S. approach based on catastrophic risks provides clearer criteria, but may leave a range of effects outside the scope of protection if they do not immediately cause casualties or quantifiable material damage.
Disinformation, manipulation and systemic discrimination are the examples the authors use for such risks. Each can cause widespread harm without reaching, in a single incident, the threshold associated with a major physical disaster.
Aires and Praas believe the EU should not address this problem by narrowing its current definition. Instead, the Union should retain its broad perspective on risks and develop a more strategic method for setting priorities.
This method should start from three elements: the available evidence, the likelihood that a risk will materialise and the scale of its consequences.
Such an assessment would allow authorities to distinguish between highly serious but unlikely scenarios, more frequent risks with moderate effects, and harms that could become systemic through accumulation or spread.
The authors also call for examination of the relationship between technology and the environment in which it is used. The same model can produce different consequences depending on the infrastructure it can access, its level of autonomy, the sector in which it is deployed and the social or political conditions in which it operates.
This approach should also help allocate oversight resources. Authorities cannot investigate all possible risks with the same intensity, and an assessment based on likelihood and impact could determine where additional testing, monitoring or intervention is needed.
The timing is important because the AI Act has entered a new phase of implementation. From 1 August 2026, the AI Office may request documentation, model evaluations and access to relevant frontier models for supervising obligations applicable to general-purpose models.
Aires and Praas say this new level of access gives the Union a concrete opportunity to turn the principles of risk anticipation into practice.
Model testing, analysis of documentation and direct access by the supervisory authority could help build an evidence base on capabilities and vulnerabilities, in a field where many public policy decisions have so far been made with limited information.
For the two researchers, the objective is not to choose between a Europe concerned with fundamental rights and an approach focused exclusively on catastrophic scenarios. They argue that a mature governance system must be able to analyse both categories simultaneously and set priorities according to the actual risk each presents.
The Centre for European Policy Studies (CEPS) is an independent Brussels-based think tank that produces research and analysis on European Union policies. The material is authored by Susana Aires and Robert Praas and represents the authors’ analysis of how the EU should develop its policy for managing AI risks.
The AI Act uses risk as its central regulatory principle and introduces different obligations depending on how systems are used and the potential impact of general-purpose models. For models with systemic risk, the European framework allows centralised supervision through the AI Office.
The CEPS authors’ position is that this architecture should be complemented by a strategic prioritisation method combining harms already demonstrated with rarer scenarios that could nevertheless have potentially very serious consequences.»,
Latest News
10:54
Kawhi Leonard returns to Toronto, the team with which he won the NBA title
10:54
The dredging works in the Cernavodă area have been reduced, although the Danube's water level has fallen and the power plant needs water to cool the reactors. What is the reason
10:48
Gavin Newsom announces that he will not run in the 2028 presidential election if Kamala Harris decides to enter the race: “I will not run if she does”
10:48
A Russian frigate launched two flares at a Danish military helicopter in international waters south of Denmark
10:37
Nepalese authorities have recovered the remains of 1,399 people, while more than 4,000 remain missing after the August 26 flood
See more news