Real AI regulation does not judge a system by what algorithm it runs — it judges it by risk: how much autonomy it has over decisions, how sensitive the data it touches is, and how many people it can affect. The EU AI Act formalises exactly this into four legal tiers; the US and China weigh the same three factors differently.
Risk score: R = 0.40·autonomy + 0.35·sensitivity + 0.25·impact (0-100)
Tier thresholds (score → tier), by jurisdiction:
EU AI Act: R≥85 Prohibited · R≥60 High risk · R≥30 Limited (transparency) · else Minimal
USA: R≥95 Prohibited · R≥75 High risk (sector rules) · R≥45 Limited · else Minimal
China: R≥80 Prohibited (content/social control) · R≥55 High risk · R≥25 Limited · else Minimal
- Autonomy — how much a decision is delegated to the model versus a human (weight 0.40, the heaviest factor everywhere).
- Data sensitivity — personal, biometric or health data raises GDPR-style exposure (weight 0.35).
- Impact scope — how many people or how severe the consequence of an error is (weight 0.25).
- Jurisdiction — the EU AI Act is the strictest and most codified; the US leans on sector-specific rules (NIST, FDA) with higher bars before mandatory controls kick in; China's thresholds emphasise content and behavioural control over individual-rights language.
Each falling sphere is one hypothetical AI use-case; its resting ring is its legal risk tier, and the panel on the left shows the documentation, testing and human-oversight burden that tier carries in practice.