Article 9: Risk management system
Application dates
- : Requirements for high-risk systems listed in Annex III
- : Requirements for high-risk systems linked to Annex I
Article 9 is the risk-management foundation for high-risk AI. Organisations must not only identify risks, but also mitigate, test, monitor and document them.
Official text
Source: EUR-Lex, Regulation (EU) 2024/1689. Text reproduced verbatim.
Download AI Act (PDF)→Official guidance on this article
4- Commission Implementing Decision C(2025) 3871 of 23.6.2025 on a standardisation request to CEN and CENELEC as regards high-risk AI systems in support of Regulation (EU) 2024/1689 and repealing Implementing Decision C(2023) 3215Explicitly requests a standard for the risk management system so that providers can implement the open standard of Article 9 with a concrete methodologyPublishedImplementing actEuropean Commission23 Jun 2025
- ISO/IEC 42005:2025 Information technology - Artificial intelligence (AI) - AI system impact assessmentSupplements the risk management system of Article 9 with an explicit focus on impacts on individuals and groups, making the risk process broader than product safety alone.PublishedStandardISO/IEC JTC 1/SC 42, Dutch adoption by NEN1 Jun 2025
- EN ISO/IEC 23894:2024 Information technology - Artificial intelligence - Guidance on risk managementCurrently provides a usable methodology for the risk management system of Article 9, as a bridge while the European prescriptive standard prEN 18228 remains in draft phase.PublishedStandardISO/IEC JTC 1/SC 42, European adoption through CEN-CENELEC, Dutch adoption by NEN1 Feb 2024
- prEN 18228 Artificial intelligence - Risk management (draft European standard, public enquiry)Provides the process that providers must follow to meet the obligation under Article 9 to maintain a risk management system throughout the entire lifecycle, including risks to fundamental rights.DraftStandardCEN-CENELEC JTC 21, national consultation through NEN18 May 2026
What does this mean for you?
Provider+
Deployer+
SME / Startup+
Public Sector+
Compliance checklist
- ☐Risk management system established and documented
- ☐Risk identification and analysis performed
- ☐Risk mitigation measures implemented
- ☐Residual risks assessed and deemed acceptable
- ☐Testing procedures performed before deployment
- ☐Continuous monitoring system established
Want to save your progress? Create an account
Related recitals
The risk-management system should consist of a continuous, iterative process that is planned and run throughout the entire lifecycle of a high-risk AI system. That process should be aimed at identifyi…
Requirements should apply to high-risk AI systems as regards risk management, the quality and relevance of data sets used, technical documentation and record-keeping, transparency and the provision of…
High-quality data and access to high-quality data plays a vital role in providing structure and in ensuring the performance of many AI systems, especially when techniques involving the training of mod…
Related tools
Related enforcement
No enforcement actions for this article yet. Follow developments via the Enforcement Tracker.