Risk management in the risk society: between algorithms and fundamental rights

In a highly uncertain and rapidly changing historical period, one characterized by great complexity, risk is a constant factor; its management proves successful to the extent that it enables us to interpret warning signs in advance and, therefore, identify threats before they materialize.

Risk management is, in fact, one of the pillars of any organization, precisely because, on the one hand, it helps protect the business from potentially devastating (and inadequately anticipated) impacts; on the other hand, it supports a safer innovation process in the medium and long term—precisely because it is capable of systematizing the possible future impacts of a specific business decision within its given context. 

From this perspective, it is clear that, in a risk-based society, it is essential to view the list of corporate risks as a living document, capable of rapidly integrating new categories that may emerge from the ongoing changes taking place, including—first and foremost—technological ones. 

Thus, today, the rapid spread of artificial intelligence within many organizations requires companies to integrate ‘algorithmic risk’ into their corporate risk management strategy: not only to comply with the European regulation on artificial intelligence (due in the coming weeks), but precisely because this is one of the most slippery areas for organizations that are often unaware of the actual risks that can arise from a “blanket” implementation of AI. 

The socio-technical nature of artificial intelligence, however, requires that algorithmic risk be assessed not only in terms of traditional reputational, financial, and legal considerations, but also in terms of the ethical risks it may pose.  

It is now well established, in fact, that artificial intelligence models and systems interact with humans and society at every stage of their development and use; and that they also shape the social context in which they operate, generating immediate and concrete risks such as discrimination, surveillance, and misinformation.  It is clear that this perspective has shaped the risk-based approach—adopted, for example, by the AI ACT—which aims to hold producers and users accountable regarding the governance of AI systems by classifying artificial intelligence applications into four categories based on the risks they may pose in terms of health, safety, and human rights, thereby triggering corresponding levels of compliance. 

From an ethical perspective, therefore, algorithmic risk requires, first and foremost, the identification, analysis, and assessment of the impacts that the application of a single AI model or system (in that specific context of use) may have on society and fundamental human rights. 

Secondly, it will be possible to assess the actual emerging ethical risk; when integrated into a more structured risk management system, this will enable the prioritization of intervention and mitigation efforts, while continuously monitoring the AI model or system to identify any new impacts and previously unforeseeable consequences.

 

Unlike other risk areas, which in many cases can follow a purely quantitative approach, the assessment of ethical impacts and risks must be capable of combining qualitative and quantitative analysis, precisely because while measuring the protection of rights “quantitatively” is an exercise that conflicts with the very concept of fundamental human rights, on the other hand – if we do not translate qualitative measures into quantitative ones – it will be nearly impossible to effectively manage emerging risks.


Among the main challenges posed by algorithmic risk is, in fact, the issue of its impact: this can manifest itself in various forms, many of which are still unknown or little understood, affecting not only values such as health and safety, but also principles such as non-discrimination and other fundamental rights that we must—and wish to—ensure are respected.

The goal of this risk-based approach to technology (now widespread in many regulatory frameworks—even outside the European Union) is certainly not to hinder innovation or blame technology, but, on the contrary, it is designed to be flexible and thus suited to the current historical moment; as well as to foster the adoption of a reflective, governed, and human-driven model of technological development.

— RICHIESTA INVIATA ✅ ✉️ —

Grazie per il tuo messaggio.