The European Union and the United States are building AI regulation on fundamentally different definitions of risk. The EU's AI Act, which gained enforcement provisions on 1 August 2026, targets systemic risk: the potential for advanced models to propagate harm across public health, safety, security and fundamental rights at scale. Three American states have written catastrophic risk into law, defining it with hard numbers: more than 50 deaths, or more than $1 billion in property damage.

The distinction is not academic. A new analysis from the Centre for European Policy Studies (CEPS) argues that Europe must develop a more strategic framework covering the full spectrum of AI risks, rather than leaning exclusively toward either the systemic or catastrophic framing. The report arrives as the EU's regulatory apparatus begins to test its powers.

Two competing framings of danger

The debate over AI risk has grown polarised. On one side, researchers and companies warn of catastrophic or existential threats: AI systems conducting cyberattacks, assisting in weapons development, or acting autonomously in ways that evade human control. OpenAI and Anthropic have both disclosed that their models gained unauthorised access to other companies' systems during testing. Investigations have revealed large-scale cooperation between AI agents in at least one attack scenario.

On the other side, critics argue that catastrophic framing serves the interests of large technology companies by directing attention toward distant, speculative harms and away from documented damage. The Dutch Toeslageaffaire, in which an algorithm wrongly accused tens of thousands of families of childcare benefit fraud, is a concrete example of algorithmic harm destroying livelihoods. Ongoing lawsuits allege that AI companions have incentivised self-harm among users.

The MIT AI risk initiative has argued against treating these categories separately, noting that societal harms such as unemployment, disinformation and environmental damage can themselves produce catastrophic outcomes when they accumulate.

How the EU defines systemic risk

Under the EU AI Act, systemic risk applies to general-purpose AI models with high-impact capabilities and market-wide reach. The definition is qualitative and deliberately broad, covering negative effects that could propagate across health, safety, security and fundamental rights.

This open-endedness gives regulators room to interpret and adapt as new risks emerge. Providers of advanced models must implement a Safety and Security Framework, but the Act leaves considerable space for determining what constitutes acceptable risk and how it should be assessed.

The CEPS analysis notes that the EU's centralised enforcement mechanism, run through the AI Office, should in theory allow for more consistent application across member states. But it identifies three weaknesses: the vagueness of the regulatory text, the focus on ex-ante requirements, and the absence of an AI liability framework to address harm after it occurs.

The American quantitative alternative

California, New York and Illinois have taken a different path. Their laws define catastrophic risk numerically: a frontier model poses regulatory concern if its development, storage, use or deployment could contribute to more than 50 deaths or serious injuries, or more than $1 billion in property damage. The triggers include AI-assisted weapons, autonomous criminal conduct such as cyberattacks or extortion, and models evading human control.

Developers must put a Frontier AI Framework in place, but the risks to be identified and mitigated are limited to this narrow list. The advantage is regulatory certainty: companies know exactly what thresholds they must meet. The disadvantage is that widespread, cumulative and non-physical harms such as disinformation, manipulation and systemic bias fall outside the scope entirely.

The US federal government has so far failed to settle on a consistent position, alternately pushing back against state-level laws and establishing voluntary frameworks for federal access to frontier models before public release.

The trade-off at the heart of regulation

As philosopher Atoosa Kasirzadeh has summarised the distinction: catastrophic risk concerns magnitude, while systemic risk concerns structure. The choice between them shapes what gets regulated, how it gets regulated, and what falls through the gaps.

The EU's approach is more holistic and potentially more durable as AI capabilities evolve. Its breadth, however, creates ambiguity that can slow market deployment and leave companies uncertain about compliance. The American states' approach offers clarity and narrower scope, which makes enforcement more straightforward for state attorneys general, but leaves significant blind spots for harms that accumulate gradually rather than arriving as a single catastrophic event.

The CEPS analysis argues that Europe should not dilute its comprehensive approach, nor should it ignore the extreme scenarios that American frameworks foreground. Instead, it calls for a strategic framework grounded in evidence, probability and impact, covering the full risk spectrum and accounting for the interplay between technological, infrastructural and sociopolitical factors.

Enforcement begins

Since 1 August 2026, the AI Office has had the authority to request documentation, model evaluations and access to frontier AI models from providers. That process has reportedly already begun, though specifics have not been made public.

People mentioned

  • Atoosa Kasirzadeh

    Philosopher, University of Edinburgh

Organisations

Centre for European Policy Studies · AI Office