cs.CY cs.AI cs.CR

How far do methods for AI risk assessment reach — mapping where the gaps sit against what regulation requires

cs.CY Javier Irigoyen, Roberto Daza, Aythami Morales, et al. (8) Jul 2026

Risk-based regulatory frameworks are taking shape while methods for actually assessing and managing risk remain unsettled. This overview surveys the regulatory landscape, the range of risks and the main assessment methodologies, and identifies where methodological gaps lie.

Paper overview (our summary)

  • Field (arXiv category)cs.CY(+2)
  • AuthorsJavier Irigoyen, Roberto Daza, Aythami Morales, et al. (8)
  • Submitted2026-07-02
  • arXiv ID2607.02197v1

Key points

  • An overview addressing the gap between risk-based regulatory frameworks taking shape and methods for assessment remaining unsettled.
  • It reviews the worldwide regulatory landscape, the range of AI-related risks and the main assessment methodologies in turn.
  • The range of risk runs from technical failures to ethical and social impacts, which no single method covers.
  • Highlighting best practices while illuminating methodological gaps is among its stated aims.
  • A six-page paper with eight authors, accepted at an international conference held in October 2026.

1Regulation arrives first, methods follow

Frameworks that vary regulatory weight by degree of risk are taking shape across jurisdictions. What they require is that risk be assessed and managed. Requiring assessment and having established methods for it, however, are different things. This paper maps that distance.

  1. 1FirstReview the worldwide regulatory landscape and establish what is required
  2. 2SecondCharacterize the range of AI-related risks, from technical failures to ethical and social impacts
  3. 3ThirdReview the assessment methodologies proposed, focusing on general frameworks
  4. 4FourthSet out best practices and where methodological gaps lie

An overview proposes no new method. Its contribution is showing what exists and what does not. Where a field is expanding quickly, that ordering has value in itself.

2The breadth of risk

Technical failureEthical and social impact
Behaviour departs from specificationBehaviour meets specification yet impact still arises
Relatively tractable to testThe design of a test is itself hard
Describable in engineering termsAssessment draws on other disciplines

The range the authors characterize runs from technical failures to ethical and social impacts. That breadth is what makes assessment difficult. No single method covers it, and different subjects call for different approaches.

3Showing the gaps as a contribution

The paper sets out to highlight best practices while illuminating methodological gaps. This site separately covers work reporting that at least 74 risk taxonomies exist while most stop at cataloguing. Frameworks proliferate while the part that actually measures and grades stays thin — a point both share.

4The link to regulatory documents

The standing of this workAn overview of six pagesAccepted at a conference held October 2026
AuthorsEightA form that brings several viewpoints together
ScopeRegulatory landscape, range of risks, methodologies, gapsStructured in four stages

This site covers many articles on how rules themselves are made. Where a rule requires that an assessment be carried out, the methods by which it might be carried out are not written into the rule. Work of this kind fills the space between rule and implementation. This article is our own summary of public research information and does not warrant its contents.

Why it matters

A rule requiring assessment does not write the method into its text. Understanding the space between what is required and what can actually be done is a precondition for planning a response.

FAQ

Does regulation make assessment possible?
Requiring assessment and having established methods are different things. The paper maps that distance and identifies where the gaps lie.
Why does no single method cover it?
Because the range runs from technical failures to ethical and social impacts, mixing what is tractable to test with what is hard even to design a test for.

Sources (primary)

Source: arXiv (descriptive metadata is CC0 public domain). Summaries are our own; see arXiv for the original text and PDF.

#AI#arXiv#Research papers#AI regulation#Risk assessment
Disclaimer: This site independently summarizes and classifies information based on official data sources. Always verify the latest and accurate information with the official sources. Content on finance, health, legal, and security is information, not advice. This site is not an official website of the U.S. government.