Chapter III · High-risk AI systems
Article 9 — Risk management system
Official text
Each paragraph records where its wording comes from. Only text reproduced unchanged from the Official Journal is authentic; consolidated text is editorial and has no legal value. Paragraphs, subparagraphs and points each have their own link.
A risk management system shall be established, implemented, documented and maintained in relation to high-risk AI systems.
Authentic — as published in the Official Journal
The risk management system shall be understood as a continuous iterative process planned and run throughout the entire lifecycle of a high-risk AI system, requiring regular systematic review and updating. It shall comprise the following steps:
- (a)
the identification and analysis of the known and the reasonably foreseeable risks that the high-risk AI system can pose to health, safety or fundamental rights when the high-risk AI system is used in accordance with its intended purpose;
- (b)
the estimation and evaluation of the risks that may emerge when the high-risk AI system is used in accordance with its intended purpose, and under conditions of reasonably foreseeable misuse;
- (c)
the evaluation of other risks possibly arising, based on the analysis of data gathered from the post-market monitoring system referred to in Article 72;
- (d)
the adoption of appropriate and targeted risk management measures designed to address the risks identified pursuant to point (a).
Authentic — as published in the Official Journal
The risks referred to in this Article shall concern only those which may be reasonably mitigated or eliminated through the development or design of the high-risk AI system, or the provision of adequate technical information.
Authentic — as published in the Official Journal
The risk management measures referred to in paragraph 2, point (d), shall give due consideration to the effects and possible interaction resulting from the combined application of the requirements set out in this Section, with a view to minimising risks more effectively while achieving an appropriate balance in implementing the measures to fulfil those requirements.
Authentic — as published in the Official Journal
The risk management measures referred to in paragraph 2, point (d), shall be such that the relevant residual risk associated with each hazard, as well as the overall residual risk of the high-risk AI systems is judged to be acceptable.
In identifying the most appropriate risk management measures, the following shall be ensured:
- (a)
elimination or reduction of risks identified and evaluated pursuant to paragraph 2 in as far as technically feasible through adequate design and development of the high-risk AI system;
- (b)
where appropriate, implementation of adequate mitigation and control measures addressing risks that cannot be eliminated;
- (c)
provision of information required pursuant to Article 13 and, where appropriate, training to deployers.
With a view to eliminating or reducing risks related to the use of the high-risk AI system, due consideration shall be given to the technical knowledge, experience, education, the training to be expected by the deployer, and the presumable context in which the system is intended to be used.
Authentic — as published in the Official Journal
High-risk AI systems shall be tested for the purpose of identifying the most appropriate and targeted risk management measures. Testing shall ensure that high-risk AI systems perform consistently for their intended purpose and that they are in compliance with the requirements set out in this Section.
Authentic — as published in the Official Journal
Testing procedures may include testing in real-world conditions in accordance with Article 60.
Authentic — as published in the Official Journal
The testing of high-risk AI systems shall be performed, as appropriate, at any time throughout the development process, and, in any event, prior to their being placed on the market or put into service. Testing shall be carried out against prior defined metrics and probabilistic thresholds that are appropriate to the intended purpose of the high-risk AI system.
Authentic — as published in the Official Journal
When implementing the risk management system as provided for in paragraphs 1 to 7, providers shall give consideration to whether in view of its intended purpose the high-risk AI system is likely to have an adverse impact on persons under the age of 18 and, as appropriate, other vulnerable groups.
Authentic — as published in the Official Journal
For providers of high-risk AI systems that are subject to requirements regarding internal risk management processes under other relevant provisions of Union law, the aspects provided in paragraphs 1 to 9 may be part of, or combined with, the risk management procedures established pursuant to that law.
Authentic — as published in the Official Journal
The formal analysis of Article 9
Article 6 is formalised first. The remaining articles follow.
Article 9 is formalised node by node: each rule as a deontic position with its operator, each exception with its rank, each predicate resolved against the definitions in Article 3.
What members get, per article
- the rule logic: every norm as a formal position, with the defeater chain that decides which exception wins
- the competency questions and their answers, every unanswered one marked as a gap and named
- the ontology: predicates bound to AISV (AI Standardisation Vocabulary) and to the definitions they depend on, exportable as JSON-LD and OWL
- the documentation: the Article 6(4) assessment record generated from a fact set, with its derivation and the version of the law it was decided against
Built for providers claiming the 6(3) derogation, for the counsel who has to defend that claim, and for the auditor who reads it afterwards.
Access is invite-only and opening in stages. Article 6 is formalised first; the remaining articles follow.
No mail client? Write to hello@signatu.com
Already a member? Sign in
What the article requiresUnder review
- 01Establish, implement, document and maintain a risk management system as a continuous iterative process across the whole lifecycle, with regular systematic review and updating.
- 02Identify and analyse the known and the reasonably foreseeable risks the system can pose to health, safety or fundamental rights when used as intended.
- 03Estimate and evaluate the risks that may emerge under reasonably foreseeable misuse.
- 04Evaluate other risks that emerge from the data gathered in post-market monitoring under Article 72.
- 05Adopt appropriate and targeted risk management measures, judged against the state of the art, so that residual risk is acceptable.
- 06Eliminate or reduce risks by design and development as far as technically feasible; take mitigation and control measures for risks that cannot be eliminated; provide information under Article 13 and, where appropriate, training for deployers.
- 07Test the system to identify the most appropriate measures, against prior defined metrics and probabilistic thresholds; testing may take place up to the point of placing on the market and in real world conditions under Article 60.
- 08Give specific consideration to whether the system is likely to adversely affect persons under 18 or other vulnerable groups.
In practiceUnder review
Article 9 is the article that drives the rest: the risks it identifies determine data governance choices under Article 10, the residual risk statements in the technical documentation under Article 11, the oversight measures under Article 14, and what post-market monitoring under Article 72 must look for. A risk management file that does not close that loop fails at the first inspection.
Standards addressing this articleUnder review
- prEN 18228AI risk managementRejected at public enquiry (closed 30 July 2026) by a majority of national standards bodies. The Commission's preliminary assessment found it a valid candidate for harmonisation.
- prEN 18283Concepts, measures and requirements for managing bias in AI systemsSent to the Commission in July 2026 for its pre-enquiry check. Commission comments received in August are under review.