Regulatory philosophies: risk-based, rights-based, and the shape of scope

Lesson 2 of 5 in How AI Governance Works: Laws, Standards, and Everything Between.

Before a legislature writes a single obligation, it makes two architectural choices that determine everything downstream. Learn to spot them and you can read any AI law in the world in minutes.

Choice one: how wide? Horizontal versus sectoral. A horizontal law covers AI across the whole economy with one rulebook — the EU AI Act applies whether the system screens résumés, reads X-rays, or prices insurance. A sectoral approach instead lets each domain regulator handle AI inside its own turf: medical-device authorities govern diagnostic AI, financial regulators govern credit models, transport authorities govern autonomous vehicles. The US and UK largely chose this route — no omnibus AI statute, but the FDA, FTC, EEOC, and state insurance commissioners each policing their corner with the laws they already had.

Neither is simply better. Horizontal buys consistency and closes gaps, at the price of one-size-fits-all rules strained by very different contexts. Sectoral buys domain expertise and proportionality, at the price of gaps (who governs a general-purpose chatbot?), overlaps, and fifty inconsistent definitions.

Choice two: what triggers the rules? This is where philosophies diverge. The dominant answers in 2026 are risk-based and rights-based — and most real regimes blend them.

A risk-based law scales obligations to the danger of the use: trivial uses get nothing, risky uses get requirements, intolerable uses get banned. It concentrates regulatory effort where harm concentrates — and its weakness is the inverse: whoever writes the risk categories decides what counts, and harms outside the list go ungoverned.

A rights-based approach starts from the person, not the system: what entitlements does every affected individual hold regardless of how the risk was categorized? GDPR Article 22 gives you rights around automated decisions whether or not anyone called the system "high-risk". The Council of Europe Framework Convention (opened for signature September 2024) frames the whole field as protecting human rights, democracy, and the rule of law. Strength: no gaps in principle. Weakness: rights need enforcement machinery and individual assertion, which favours the well-resourced.

Risk-based

Regulate the use, proportionate to its danger.

The EU AI Act is the archetype: prohibited practices at the top, high-risk systems under heavy obligations, limited-risk systems under transparency duties, minimal-risk systems free. Canada’s AIDA proposal and Colorado’s original AI Act followed the same logic.

  • Bet: most AI is harmless; aim the machinery at the dangerous slice.
  • Fails when: the risk list ages badly, or real harm hides in “minimal-risk” uses nobody listed.
  • Tell: the statute’s heart is a classification scheme — tiers, annexes, lists of uses.

Rights-based

Start from what every person is owed.

GDPR’s automated-decision rights, the Council of Europe Framework Convention, and the human-rights framing UNESCO builds on are the archetypes. The EU AI Act absorbed the influence too: deployers of certain high-risk systems must run fundamental rights impact assessments (Article 27).

  • Bet: dignity and rights are non-negotiable whatever the risk tier says.
  • Fails when: rights exist on paper but individuals lack the knowledge, standing, or resources to assert them.
  • Tell: the text speaks of persons, rights, remedies, and redress before it speaks of systems.

Market-led

Intervene late, rely on existing law, protect innovation.

The post-2025 US federal posture is the archetype: EO 14110 revoked in January 2025, an AI Action Plan oriented to removing barriers, and enforcement flowing through existing consumer-protection, civil-rights, and sectoral law rather than a new AI statute. The UK’s “principles for existing regulators” white-paper approach is a cousin.

  • Bet: general law plus competition catches real harms without freezing a young technology.
  • Fails when: harms are diffuse, systemic, or fall between regulators’ mandates — nobody’s jurisdiction, so nobody’s job.
  • Tell: no new AI statute; instead guidance, enforcement actions, and heavy reliance on the word “existing”.

State-directed

License, register, and align content with state objectives.

China is the archetype: the Algorithm Recommendation Provisions (2022), Deep Synthesis Provisions (2023), Interim GenAI Measures (2023), and content-labeling rules (2025) require algorithm filings with the CAC, security assessments before public release, and alignment of generated content with state values.

  • Bet: information control and rapid iteration of targeted rules, instrument by instrument.
  • Fails when: judged by liberal-democratic yardsticks of expression and due process — different goals, different scorecard.
  • Tell: registration and filing regimes, content obligations, and a powerful central internet regulator.

Key terms: risk-based regulation, rights-based approach, horizontal regulation, sectoral regulation

Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.