Under active development Content is continuously updated and improved

Art. 9Risk Management System

>Control Description

High-risk AI systems shall have a risk management system established, implemented, documented and maintained as a continuous iterative process throughout the entire lifecycle. The system shall identify and analyse known and reasonably foreseeable risks, estimate and evaluate risks, adopt appropriate management measures, and ensure residual risks are acceptable.

Risk Tier

High-Risk

Article

Art. 9

Deadline

August 2, 2026

Penalty

€15M or 3% of global turnover

>Applies To

providers

>Key Requirements

  • Continuous iterative risk management throughout lifecycle
  • Identification and analysis of known and foreseeable risks
  • Risk estimation and evaluation
  • Adoption of appropriate risk management measures
  • Testing to identify most appropriate risk management measures
  • Consideration of effects on marginalized groups and children

>Cross-Framework Mappings

Ask AI

Configure your API key to use AI features.