Mindful Machines Press

Journal · Governing the Machine
Governing the Machine · Chapter 02 of 05

Risk or Rights: Two Instincts for Protecting People from AI

Viveka Mohan Das · Aug 29, 2026

When a legislature sets out to protect people from artificial intelligence, it must first decide what it is protecting them from. Two instincts dominate the world's AI laws, and they answer that question differently. One asks how dangerous a system is; the other asks what a person is owed regardless of danger. This article examines the risk-based and mandatory rights-based approaches, and the quiet disagreement between them.

Introduction

The two approaches are not opposites so much as different starting points. A risk-based law begins with the system and works outward to the person; a rights-based law begins with the person and works back to the system. UNESCO's 2026 brief presents both as legitimate members of its nine-approach taxonomy, and notes that many statutes blend them (UNESCO, 2026). Yet the choice of starting point has consequences for who is protected, when, and how reliably.

The Risk-Based Instinct: Scale the Rules to the Danger

The risk-based approach tailors obligations to an assessment of the harm a given use might cause. Its most prominent expression is the European Union's AI Act, which sorts systems into four bands - unacceptable, high, limited and minimal - where risk is defined as the combination of the probability of harm and its severity (UNESCO, 2026). Systems in the unacceptable band are prohibited outright; Article 5, for example, bans the use of real-time remote biometric identification in publicly accessible spaces for law enforcement, save for narrowly defined exceptions. High-risk systems are not banned but must satisfy demanding duties: risk-management systems, data governance, technical documentation, record-keeping, human oversight, accuracy and cybersecurity.

The logic is proportionality. Regulatory attention flows to where harm is most likely and most severe, and away from trivial uses. South Korea adopts a comparable structure through the category of high-impact AI, requiring operators to identify, assess and mitigate risks across the AI lifecycle and to run a risk-management system that monitors safety incidents (UNESCO, 2026).

The Rights-Based Instinct: Fix a Floor Beneath Everyone

The mandatory rights-based approach starts from a different premise. It assumes that market failures are not the only reason to regulate, and that binding rules are justified to protect human rights and advance social objectives (UNESCO, 2026). Rather than asking how risky a system is, it enshrines rights that hold whenever AI touches a person's life. The Philippines' House Bill 7913 proposes an AI bill of rights comprising four guarantees: protection from unsafe and ineffective systems, protection against algorithmic discrimination, privacy, and a right to know. Brazil's Bill No. 2238 of 2023 similarly grants affected persons rights to explanation, to contest decisions and to request human intervention, and Kenya's Data Protection Act of 2019 gives every data subject the right not to be subject to a decision based solely on automated processing (UNESCO, 2026).

The crucial difference is universality. As some civil-society organisations argue, a rights-based approach may protect more reliably than a risk-based one, because human rights obligations apply regardless of any assessed risk level; they are, in this reading, non-negotiable and must be respected whatever a risk model concludes (UNESCO, 2026).

RISK-BASED Obligations scale with risk Unacceptable prohibited outright High risk strict duties Limited transparency only Minimal largely unregulated RIGHTS-BASED Protections apply regardless of risk Right to know Right against algorithmic discrimination Right to human review Right to privacy and safety ONE FLOOR FOR EVERYONE Source: UNESCO (2026), Governing AI: Nine Emerging Approaches for Lawmakers Worldwide
Figure 1. Two logics of protection: obligations that scale with risk, and rights that apply to everyone. Source: UNESCO (2026), Governing AI: Nine Emerging Approaches for Lawmakers Worldwide.

Why the Starting Point Matters

The disagreement is, at root, about human judgement. Paul Slovic's research on the perception of risk showed that people do not weigh danger the way a formula does; estimates are shaped by dread, familiarity, controllability and who bears the harm (Slovic, 1987). A risk-based regime is only as sound as its risk assessments, and those assessments are made by fallible institutions with incomplete information about a moving target. When a novel harm is under-estimated, the protections calibrated to it are under-scaled.

A rights-based regime sidesteps that fragility by refusing to make protection contingent on a correct forecast. Its floor holds even when the risk model is wrong. The trade-off is that universal rights can impose uniform duties on low-stakes uses, which is exactly the inflexibility that risk-tiering was designed to avoid. This is why the two instincts increasingly appear together: the risk pyramid concentrates scrutiny where harm is gravest, while a rights floor guarantees that no one falls through the gaps the pyramid leaves behind. Managing danger and protecting dignity, it turns out, are not the same task - and a mature AI law attends to both.

References
  1. European Union. (2024). Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act). eur-lex.europa.eu/eli/reg/2024/1689/oj
  2. Republic of Kenya. (2019). Data Protection Act, No. 24 of 2019.
  3. Slovic, P. (1987). Perception of risk. Science, 236(4799), 280-285.
  4. UNESCO. (2026). Governing AI: Nine emerging approaches for lawmakers worldwide. United Nations Educational, Scientific and Cultural Organization.

This article was drafted with the research assistance of AI (Claude) and edited under human editorial oversight. Its factual claims are drawn from UNESCO's 2026 policy brief and the public legal instruments it cites. Full sourcing practice for this site follows the standing Corrections & Sources approach - the author's own research process lives at vivekamohandas.com →

← Governing the Machine contents About the author →