Article 9
UpcomingConditional timingEstablish and Maintain a Risk Management System for High-Risk AI
Applies to Provider; High-Risk AI.
- Actors
- Provider
- AI class
- High-Risk AI
- Themes
- Risk & Assurance
Tracker Guidance
For each high-risk AI system in scope, establish, implement, document and maintain a continuous and iterative risk-management process throughout the system lifecycle. Periodically review and update it. Address risks that can reasonably be mitigated or eliminated through system development or design, or through appropriate technical information.
Official text
1. A risk management system shall be established, implemented, documented and maintained in relation to high-risk AI systems. 2. The risk management system shall be understood as a continuous iterative process planned and run throughout the entire lifecycle of a high-risk AI system, requiring regular systematic review and updating. It shall comprise the following steps: (a) the identification and analysis of the known and the reasonably foreseeable risks that the high-risk AI system can pose to health, safety or fundamental rights when the high-risk AI system is used in accordance with its intended purpose; (b) the estimation and evaluation of the risks that may emerge when the high-risk AI system is used in accordance with its intended purpose, and under conditions of reasonably foreseeable misuse; (c) the evaluation of other risks possibly arising, based on the analysis of data gathered from the post-market monitoring system referred to in Article 72; (d) the adoption of appropriate and targeted risk management measures designed to address the risks identified pursuant to point (a). 3. The risks referred to in this Article shall concern only those which may be reasonably mitigated or eliminated through the development or design of the high-risk AI system, or the provision of adequate technical information. 4. The risk management measures referred to in paragraph 2, point (d), shall give due consideration to the effects and possible interaction resulting from the combined application of the requirements set out in this Section, with a view to minimising risks more effectively while achieving an appropriate balance in implementing the measures to fulfil those requirements. [Excerpt - see official source for complete provision]
Excerpt stored at a complete legal-unit boundary. See the official source for the full provision.
Timing depends on the system
- 2 Dec 2027 — Article 6(2) / Annex III high-risk AI
- 2 Aug 2028 — Article 6(1) / Annex I Section A high-risk AI
- 2 Dec 2027 — Pre-existing Annex III high-risk AI type/model first placed on the market or put into service before 2027-12-02
- 2 Aug 2028 — Pre-existing Article 6(1) / Annex I high-risk AI type/model first placed on the market or put into service before 2028-08-02
- 2 Aug 2030 — Pre-existing high-risk AI intended to be used by public authorities
Sub-obligations
These are independently assessable parts of the parent requirement.
Article 9(2)(a)
UpcomingIdentify and Analyse Known and Reasonably Foreseeable High-Risk AI Risks
Tracker Guidance
Identify and analyse the known and reasonably foreseeable risks that the high-risk AI system may pose to health, safety or fundamental rights when it is used for its intended purpose.
Official text
Article 9(2)(a)Official source (a) the identification and analysis of the known and the reasonably foreseeable risks that the high-risk AI system can pose to health, safety or fundamental rights when the high-risk AI system is used in accordance with its intended purpose;
Article 9(2)(b)-(c)
UpcomingEstimate and Evaluate Risks From Intended Use, Foreseeable Misuse and Post-Market Information
Tracker Guidance
Estimate and evaluate risks arising from intended use and reasonably foreseeable misuse, and reassess risks that emerge from information gathered through post-market monitoring.
Official text
Article 9(2)(b)-(c)Official source (b) the estimation and evaluation of the risks that may emerge when the high-risk AI system is used in accordance with its intended purpose, and under conditions of reasonably foreseeable misuse; (c) the evaluation of other risks possibly arising, based on the analysis of data gathered from the post-market monitoring system referred to in Article 72;
Article 9(2)(d), 9(4)-(5)
UpcomingImplement Targeted Risk Measures and Judge Residual Risk Acceptable
Tracker Guidance
Adopt targeted risk-management measures for the risks identified. Where technically feasible, first eliminate or reduce risks through design and development, then implement appropriate mitigation and control measures for remaining risks and provide relevant information or training. Ensure the overall residual risk is judged acceptable.
Official text
Article 9(2)(d)Official source (d) the adoption of appropriate and targeted risk management measures designed to address the risks identified pursuant to point (a).
Article 9(4)-(5)Official source 4. The risk management measures referred to in paragraph 2, point (d), shall give due consideration to the effects and possible interaction resulting from the combined application of the requirements set out in this Section, with a view to minimising risks more effectively while achieving an appropriate balance in implementing the measures to fulfil those requirements. 5. The risk management measures referred to in paragraph 2, point (d), shall be such that the relevant residual risk associated with each hazard, as well as the overall residual risk of the high-risk AI systems is judged to be acceptable. In identifying the most appropriate risk management measures, the following shall be ensured: (a) elimination or reduction of risks identified and evaluated pursuant to paragraph 2 in as far as technically feasible through adequate design and development of the high-risk AI system; (b) where appropriate, implementation of adequate mitigation and control measures addressing risks that cannot be eliminated; (c) provision of information required pursuant to Article 13 and, where appropriate, training to deployers. With a view to eliminating or reducing risks related to the use of the high-risk AI system, due consideration shall be given to the technical knowledge, experience, education, the training to be expected by the deployer, and the presumable context in which the system is intended to be used.
Article 9(6)-(8)
UpcomingTest High-Risk AI Systems Against Defined Metrics and Thresholds
Tracker Guidance
Test the high-risk AI system to identify appropriate risk-management measures and demonstrate that it performs consistently for its intended purpose and complies with the high-risk requirements. Define suitable metrics and probabilistic thresholds and perform testing during development as appropriate and before market placement or putting into service.
Official text
Article 9(6)-(8)Official source 6. High-risk AI systems shall be tested for the purpose of identifying the most appropriate and targeted risk management measures. Testing shall ensure that high-risk AI systems perform consistently for their intended purpose and that they are in compliance with the requirements set out in this Section. 7. Testing procedures may include testing in real-world conditions in accordance with Article 60. 8. The testing of high-risk AI systems shall be performed, as appropriate, at any time throughout the development process, and, in any event, prior to their being placed on the market or put into service. Testing shall be carried out against prior defined metrics and probabilistic thresholds that are appropriate to the intended purpose of the high-risk AI system.
Article 9(9)
UpcomingConsider Impacts on Children and Other Vulnerable Groups in High-Risk AI Risk Management
Tracker Guidance
As part of the risk-management process, consider whether the high-risk AI system is likely to adversely affect people under 18 and, where appropriate, other vulnerable groups.
Official text
Article 9(9)Official source 9. When implementing the risk management system as provided for in paragraphs 1 to 7, providers shall give consideration to whether in view of its intended purpose the high-risk AI system is likely to have an adverse impact on persons under the age of 18 and, as appropriate, other vulnerable groups.