Lesson 24 / 25

Safety, Privacy and Regulation

Managing risks from misuse and failure.

Risks and rules

AI raises safety risks (errors in high-stakes uses, unexpected behaviour, misuse such as fraud or misinformation), privacy risks (training on or exposing personal data), security risks (manipulating models, prompt injection) and broader concerns (job changes, concentration of power, environmental cost, and long-term questions about very capable systems). Governments are responding with regulation, such as the EU AI Act's risk-based obligations, and with standards and frameworks such as the NIST AI Risk Management Framework. Specific obligations vary by country and use case and keep evolving, so check current rules for your context.

Risk-based thinking

Higher-stakes uses need stronger controls.

use case                         stakes   typical controls
spam filter                      low      monitoring, user feedback
product recommendations          medium   fairness checks, opt-out, monitoring
loan or hiring decisions         high     documentation, bias audits, human review, appeal
medical diagnosis support        high     clinical validation, regulatory approval, oversight
autonomous actions in the world  high     strict limits, testing, fail-safes, human control

Match controls to stakes

Do not apply the same light process to a medical tool as to a playlist recommender.

Quick check: What is the idea behind risk-based AI regulation?

  • No AI system needs controls
  • All AI is banned
  • Higher-risk uses face stronger obligations and controls
  • Only model size matters
Answer

Higher-risk uses face stronger obligations and controls — Controls scale with potential harm.