Only 16.4% of Italian businesses use AI effectively. Discover how to join them.

Download the whitepaper

When AI Risk Becomes Values-Based

July 29, 2026

Author: Prof.Enrico Zio - Scientific Director @Datrix & @Aramix

This article was originally published in MIT Technology Review Italia on July 27, 2026 (in Italian only).

From Algorithmic Bias to the Protection of Rights: A New Quantitative Model for Governing the Intangible Impacts of Artificial Intelligence

In recent years, we have witnessed an unprecedented acceleration in the adoption of Artificial Intelligence (AI) solutions across every market sector. This race towards AI is often portrayed as another chapter in digital evolution—a linear transition similar to the one experienced with the advent of cloud computing. This, however, is an optical illusion.

The widespread adoption of AI does not represent a mere technological leap in scale, but a paradigmatic discontinuity that challenges the very foundations of risk quantification.

The Paradigm Shift: From Tangible Risk to Values-Based Risk

Until now, risk management has operated primarily on engineering and probabilistic principles, focusing on the tangible nature of damage. The reasoning is straightforward: an industrial machine may fail and cause damage—but with what probability? And to what extent? The impact is visible, localised and often economically quantifiable.

With the advent of Artificial Intelligence, the paradigm changes radically. Risk becomes intangible, shifting from the physical sphere to the ethical and normative one: risk becomes values-based. Harm does not necessarily manifest itself through a physical impact. Instead, it may affect the legal, moral and constitutional principles upon which our societies are founded.

The Phenomenology of Intangible Risks

This transformation of risk is already observable in a number of AI adoption processes, in which the analytical and computational efficiency provided by AI mathematics comes into conflict with civil rights.

Examples include predictive algorithms used in recruitment screening, creditworthiness assessments and the underwriting of insurance policies. The use of AI does not produce visible physical harm. Nevertheless, when an algorithm is trained on incomplete or biased historical data, it may systematically exclude candidates on the basis of ethnicity or gender, violating their right to non-discrimination and personal dignity.

Similarly, automated systems designed to detect tax or welfare fraud may incorrectly label thousands of vulnerable families as “fraudulent” on the basis of misleading proxy variables. In this scenario, the AI algorithm’s error violates the right to good administration, social assistance and the presumption of innocence.

Every day, we interact with social media recommendation systems and generative AI models designed around a single objective: maximising engagement. The hidden cost of this optimisation is the polarisation of public debate and the proliferation of deepfakes capable of distorting our very perception of reality, undermining media pluralism and individuals’ cognitive and intellectual autonomy.

Even healthcare, where AI has enormous humanitarian potential, is not immune to conflicts involving fundamental values. Software capable of identifying cancer with an overall accuracy rate of 99% represents an extraordinary achievement. But what would happen if the remaining 1% of errors were systematically concentrated within an ethnic minority that is underrepresented in historical datasets?

This scenario directly affects the right to healthcare and equality before the law, confronting us with a dramatic ethical dilemma: should we accept a utilitarian approach that maximises the wellbeing of the majority at the expense of a few, or should we deactivate the algorithm in the name of an egalitarian concept of justice that allows no compromise when individual rights are at stake?

Looking Beneath the Surface: The Current State of European Regulation

The scenarios described above represent only the tip of the AI iceberg: the direct, first-order impacts of the technological transition driven by Artificial Intelligence.

Recognising the depth of this challenge, European lawmakers have understood that traditional privacy protection alone is no longer sufficient to address the full spectrum of emerging risks.

For this reason, the European Union has chosen to open a new regulatory chapter. From 2 August onward, the traditional Data Protection Impact Assessment (DPIA), a cornerstone of the GDPR, will be accompanied by one of the key instruments introduced by the AI Act: the obligation to conduct a Fundamental Rights Impact Assessment (FRIA), as established by Article 27 for specific high-risk AI systems.

This framework encourages rigorous structural analysis, requiring organisations to clearly define and analytically map the use of AI across different contexts:

Objectives: clearly defining the specific purposes for which AI is used;

Time dimension: precisely establishing the period and frequency of use;

Affected individuals: identifying the specific population involved;

Risk management: identifying potential violations of fundamental rights and developing the corresponding planned mitigation measures.

While this requirement represents a crucial step towards limiting the negative consequences of values-based risk, it also raises a profound methodological issue.

There is a danger that regulatory compliance may be reduced to a purely static and bureaucratic exercise. The current FRIA approach provides qualitative guidelines without standardised criteria. As a result, risk assessments may be inconsistent, subjective and difficult to quantify or compare.

This raises a natural question: can such a rigid instrument effectively govern a technological ecosystem that, by its very nature, is constantly evolving?

Looking Beneath the Surface: The Need for a New Strategic, Collective and Timely Perspective

The straightforward answer is no.

To prevent the FRIA from becoming yet another bureaucratic requirement, a strategic step change is needed.

While legal compliance has the merit of telling us what must be protected—our values—risk engineering must provide the quantitative tools needed to understand how those values can be protected dynamically, adaptively and in a timely manner.

Only by extending the analysis beyond regulatory compliance can we map and govern second-order risks and the systemic impacts that may arise from the adoption of AI.

The purpose of this article is to argue that assessing values-based risks is not merely an ethical obligation. It is also an urgent strategic necessity for ensuring the long-term resilience of organisations and society as a whole.

Towards an Engineering of Values: The HEV Paradigm

Conventional frameworks for assessing AI-related risk suffer from structural limitations in terms of time and context.

To overcome these limitations, the methodology developed by R. Sass, C. Novelli and E. Zio in Quantifying Values: The Problem of AI Risk proposes a paradigmatic transition inspired by industrial risk engineering.

The model is structured through a reconfiguration of the HEV paradigm—Hazard, Exposure and Vulnerability—extending physical failure metrics to variables of a values-based and socio-technical nature.

Mathematical Formulation
The risk associated with the adoption of an AI system, denoted as RAI, is modelled as a function of three fundamental macro-variables:

The risk associated with the adoption of an AI system, denoted as RAI, is modelled as a function of three fundamental macro-variables:

H — Hazard: the intrinsic, latent and potential source of harm encoded within the algorithm, such as the presence of bias in the training data;

E — Exposure: the context and scale in which the system is deployed, such as the number of decisions or citizens affected by the model each day;

V — Vulnerability: the intrinsic susceptibility of the system and the individuals involved to the algorithm’s negative impacts, such as potential harm in terms of fairness or dignity. This variable also takes into account the countermeasures adopted to prevent or mitigate those impacts.

The Two Methodological Challenges of Values-Based Risk

Introducing ethical principles and human rights into this equation disrupts traditional calculation models and confronts us with two conceptual challenges.

The Paradox of Qualitative Measurement

How can fairness or dignity be assessed? When safeguards are introduced to protect against potential harm to fairness and dignity, how can their benefit be quantified in terms of the residual risk to fundamental rights?

The Conflict Between Absolute Safety and Rational Decision-Making

We find ourselves at the centre of a profound operational dilemma.

On the one hand, the legal approach regards fundamental rights as absolute and non-negotiable values. On the other, technological and economic approaches are based on rational decision-making, in which every decision represents a practical and optimal trade-off between costs, benefits and the utility generated.

A Concrete Proposal for Risk Assessment

To address the challenges described above, the study Quantifying Values: The Problem of AI Risk proposes a structured operational methodology for translating the AI Act’s qualitative guidelines into an assessment process organised into a sequence of defined stages.

The Strategic Advantages of the Quantitative Analysis Model

Adopting the HEV analysis paradigm is not merely a theoretical exercise. It is a pragmatic solution that offers three immediate benefits for the governance of AI systems.

Moving Beyond Traditional Risk Matrices

Traditional two-dimensional risk matrices fail when applied to human rights and their underlying values because they rely on ordinal scales with linear progression.

The proposed model assesses the severity of harm through a geometric scale designed to evaluate impacts on fundamental rights. This prevents systematic, high-impact harm from being offset by a low frequency of occurrence.

Dynamic Assessment of Mitigation Measures

The model makes it possible to assess the countermeasures adopted by introducing a fundamental distinction between:

Effectiveness: the intrinsic ability of a measure to mitigate a specific hazard;

Reliability: the probability that the measure will maintain its effectiveness over time, despite changes in the operational context or shifts in the distribution of the data used to train AI algorithms.

Introducing Tail-Sensitive Impact Metrics

The real methodological breakthrough lies in moving beyond the traditional expected-risk approach, which tends to flatten risk profiles and, in doing so, may conceal or dilute extreme impacts.

By contrast, metrics such as Conditional Value-at-Risk (CVaR), borrowed from financial mathematics, make it possible to assign the appropriate strategic weight to events that have a low probability of occurring but could produce extremely serious values-based impacts, such as systematic violations of fundamental rights.

The implementation of the HEV paradigm provides decision-makers with an objective, standardised and verifiable control infrastructure.

Within this framework, ethical alignment—AI Alignment—ceases to be an abstract and external philosophical constraint. Instead, it becomes an endogenous control variable, directly integrated into corporate governance and risk-management systems.

Featured posts

  • Data Quality and AI Readiness: Why Artificial Intelligence Fails Before It Even Starts

    June, 24 2026

    This article was originally published in MIT Technology Review Italia on July 23 2026 (in Italian only). The public debate on AI…

    Read more
  • Increasingly Powerful Models and Stalled Adoption: The AI Paradox in Business

    June, 11 2026

    This article was originally published in Agenda Digitale on July 27, 2026 (in Italian only). AI models have never been more powerful.…

    Read more
  • Artificial Intelligence Enters Corporate Governance: What Changes with Legislative Decree 47/2026

    June, 10 2026

    As of April 29, 2026, artificial intelligence is no longer merely a technological lever or a topic to be managed…

    Read more