RESEARCH. CONNECTED.

Explore the scholarly record.

Discover prefix ownership, publishers, journals and DOI metadata. Understand the data behind every publication.

A Review-Based Regulatory Framework for AI: Drawing on IRB and FDA Precedent

Antonio Llopis iD, Gregory Prastacos iD, Nicholas Vonortas iD

DOI10.2139/ssrn.7593779
PublisherElsevier BV
Journal / Source—
Published2026
Metadata Deposited2026-10-10 (updated: 2026-10-10)
Subject—
Language—
ISSN—
Typeposted-content
Volume / Issue / Pages— / — / —
Citations0
References deposited65
Access / license metadataAccess not determined License 1 ↗A reuse license does not by itself establish whether the full text is freely readable.

Abstract

Artificial intelligence regulation faces a challenge that is not new: how to govern a rapidly evolving technology whose long-term capability and risk space cannot be enumerated in advance. Human and pharmaceutical R&D faced the same challenge in the twentieth century. The response — centering regulation on expert review boards operating under principled ethical frameworks and evolving through precedent — produced a regulatory architecture that has successfully accommodated technologies, such as CRISPR, that could not have been anticipated when the framework was established. This paper argues that AI regulation requires the same response and develops a Review-Board-Based (RBB) framework for AI built on that precedent. The framework is designed as an input to risk-based AI regulation. We focus on the most well-known such regulation, the EU AI Act, preserving its risk-tier architecture while replacing codified classification with expert-review-based precedent evolution. The paper makes two primary conceptual contributions: the first operationalizes the concept of an object of research which parallels the human-subject framework found in the Belmont Report — the 1979 National Commission report defining guidelines for ethical human research — extending ethical protection to the affected communities of AI systems, including direct users, third parties acted upon, and populations affected by systemic deployments. Without this reformulation, the Belmont Report's three principles — Respect, Beneficence, and Justice — are mismatched with AI's affected populations. The second is a precedent-based classification mechanism that allows risk categorization to evolve with technology rather than lag it. A worked case study demonstrates both contributions in operation.