Build a board-ready risk heatmap in minutes — free, no account required

Open tool

Article 9

UpcomingConditional timing

Establish and Maintain a Risk Management System for High-Risk AI

Applies to Provider; High-Risk AI.

Actors
Provider
AI class
High-Risk AI
Themes
Risk & Assurance

Tracker Guidance

For each high-risk AI system in scope, establish, implement, document and maintain a continuous and iterative risk-management process throughout the system lifecycle. Periodically review and update it. Address risks that can reasonably be mitigated or eliminated through system development or design, or through appropriate technical information.

Official text

Article 9Official source
1. A risk management system shall be established, implemented, documented and maintained in relation to high-risk AI systems. 2. The risk management system shall be understood as a continuous iterative process planned and run throughout the entire lifecycle of a high-risk AI system, requiring regular systematic review and updating. It shall comprise the following steps: (a) the identification and analysis of the known and the reasonably foreseeable risks that the high-risk AI system can pose to health, safety or fundamental rights when the high-risk AI system is used in accordance with its intended purpose; (b) the estimation and evaluation of the risks that may emerge when the high-risk AI system is used in accordance with its intended purpose, and under conditions of reasonably foreseeable misuse; (c) the evaluation of other risks possibly arising, based on the analysis of data gathered from the post-market monitoring system referred to in Article 72; (d) the adoption of appropriate and targeted risk management measures designed to address the risks identified pursuant to point (a). 3. The risks referred to in this Article shall concern only those which may be reasonably mitigated or eliminated through the development or design of the high-risk AI system, or the provision of adequate technical information. 4. The risk management measures referred to in paragraph 2, point (d), shall give due consideration to the effects and possible interaction resulting from the combined application of the requirements set out in this Section, with a view to minimising risks more effectively while achieving an appropriate balance in implementing the measures to fulfil those requirements. [Excerpt - see official source for complete provision]

Excerpt stored at a complete legal-unit boundary. See the official source for the full provision.

Timing depends on the system

  • 2 Dec 2027Article 6(2) / Annex III high-risk AI
  • 2 Aug 2028Article 6(1) / Annex I Section A high-risk AI
  • 2 Dec 2027Pre-existing Annex III high-risk AI type/model first placed on the market or put into service before 2027-12-02
  • 2 Aug 2028Pre-existing Article 6(1) / Annex I high-risk AI type/model first placed on the market or put into service before 2028-08-02
  • 2 Aug 2030Pre-existing high-risk AI intended to be used by public authorities

Sub-obligations

These are independently assessable parts of the parent requirement.

  1. Article 9(2)(a)

    Upcoming

    Identify and Analyse Known and Reasonably Foreseeable High-Risk AI Risks

    Tracker Guidance

    Identify and analyse the known and reasonably foreseeable risks that the high-risk AI system may pose to health, safety or fundamental rights when it is used for its intended purpose.

    Official text

    Article 9(2)(a)Official source
    (a) the identification and analysis of the known and the reasonably foreseeable risks that the high-risk AI system can pose to health, safety or fundamental rights when the high-risk AI system is used in accordance with its intended purpose;
  2. Article 9(2)(b)-(c)

    Upcoming

    Estimate and Evaluate Risks From Intended Use, Foreseeable Misuse and Post-Market Information

    Tracker Guidance

    Estimate and evaluate risks arising from intended use and reasonably foreseeable misuse, and reassess risks that emerge from information gathered through post-market monitoring.

    Official text

    Article 9(2)(b)-(c)Official source
    (b) the estimation and evaluation of the risks that may emerge when the high-risk AI system is used in accordance with its intended purpose, and under conditions of reasonably foreseeable misuse; (c) the evaluation of other risks possibly arising, based on the analysis of data gathered from the post-market monitoring system referred to in Article 72;
  3. Article 9(2)(d), 9(4)-(5)

    Upcoming

    Implement Targeted Risk Measures and Judge Residual Risk Acceptable

    Tracker Guidance

    Adopt targeted risk-management measures for the risks identified. Where technically feasible, first eliminate or reduce risks through design and development, then implement appropriate mitigation and control measures for remaining risks and provide relevant information or training. Ensure the overall residual risk is judged acceptable.

    Official text

    Article 9(2)(d)Official source
    (d) the adoption of appropriate and targeted risk management measures designed to address the risks identified pursuant to point (a).
    Article 9(4)-(5)Official source
    4. The risk management measures referred to in paragraph 2, point (d), shall give due consideration to the effects and possible interaction resulting from the combined application of the requirements set out in this Section, with a view to minimising risks more effectively while achieving an appropriate balance in implementing the measures to fulfil those requirements. 5. The risk management measures referred to in paragraph 2, point (d), shall be such that the relevant residual risk associated with each hazard, as well as the overall residual risk of the high-risk AI systems is judged to be acceptable. In identifying the most appropriate risk management measures, the following shall be ensured: (a) elimination or reduction of risks identified and evaluated pursuant to paragraph 2 in as far as technically feasible through adequate design and development of the high-risk AI system; (b) where appropriate, implementation of adequate mitigation and control measures addressing risks that cannot be eliminated; (c) provision of information required pursuant to Article 13 and, where appropriate, training to deployers. With a view to eliminating or reducing risks related to the use of the high-risk AI system, due consideration shall be given to the technical knowledge, experience, education, the training to be expected by the deployer, and the presumable context in which the system is intended to be used.
  4. Article 9(6)-(8)

    Upcoming

    Test High-Risk AI Systems Against Defined Metrics and Thresholds

    Tracker Guidance

    Test the high-risk AI system to identify appropriate risk-management measures and demonstrate that it performs consistently for its intended purpose and complies with the high-risk requirements. Define suitable metrics and probabilistic thresholds and perform testing during development as appropriate and before market placement or putting into service.

    Official text

    Article 9(6)-(8)Official source
    6. High-risk AI systems shall be tested for the purpose of identifying the most appropriate and targeted risk management measures. Testing shall ensure that high-risk AI systems perform consistently for their intended purpose and that they are in compliance with the requirements set out in this Section. 7. Testing procedures may include testing in real-world conditions in accordance with Article 60. 8. The testing of high-risk AI systems shall be performed, as appropriate, at any time throughout the development process, and, in any event, prior to their being placed on the market or put into service. Testing shall be carried out against prior defined metrics and probabilistic thresholds that are appropriate to the intended purpose of the high-risk AI system.
  5. Article 9(9)

    Upcoming

    Consider Impacts on Children and Other Vulnerable Groups in High-Risk AI Risk Management

    Tracker Guidance

    As part of the risk-management process, consider whether the high-risk AI system is likely to adversely affect people under 18 and, where appropriate, other vulnerable groups.

    Official text

    Article 9(9)Official source
    9. When implementing the risk management system as provided for in paragraphs 1 to 7, providers shall give consideration to whether in view of its intended purpose the high-risk AI system is likely to have an adverse impact on persons under the age of 18 and, as appropriate, other vulnerable groups.

Recognized by G2 as a Leader

Trusted by customers and rated highly across all categories

Article 9: Establish and Maintain a Risk Management System for High-Risk AI | EU AI Act Library