Direct answer
What does the Article 9 risk management system require from us?
This falls under Article 9: risk management system. That obligation applies from 2 December 2027. There is one exception you have to assess yourself.
This could go the other way
- Risks arising only from misuse beyond any reasonably foreseeable use fall outside the mandatory scope.
First step: Set up an iterative risk management process.
You describe: You are the provider of a high-risk AI system and must show that you structurally identify, mitigate and keep tracking risks to health, safety and fundamental rights. Likely role: provider (you place the system on the market).
This applies now
Coming up
- Article 9: risk management systemfrom 2 December 2027
- Annex III: high-risk AIfrom 2 December 2027
- Article 20: corrective actions and duty of informationfrom 2 December 2027
- Article 16: the twelve duties of a provider of a high-risk AI systemfrom 2 December 2027
Depends on your situation
- Article 61: informed consent of test subjects for testing in real world conditionsArticle 60(4), point (i), with Article 61(1)
These provisions only apply once the stated fact is established. The locator says which provision settles it.
Article 9 does not ask for a one-off risk analysis but for a continuous process across the entire lifecycle, with periodic review and attention to reasonably foreseeable misuse. The core obligations for Annex III systems apply from 2 December 2027; building the process takes longer than the remaining period suggests.
Your first actions
- Set up an iterative risk management process. Identify and analyse known and reasonably foreseeable risks, evaluate them and take measures, repeating the cycle on every change.
- Justify the Article 6(3) exception against each individual condition. Name which of the four Article 6(3) conditions you invoke, with facts, and separately justify why the system poses no significant risk of harm to health, safety or fundamental rights and does not materially influence the outcome of decision making.
- Complete the conformity route before market placement. Select the correct assessment procedure, draw up the EU declaration of conformity, affix the CE marking and register in the EU database.
Record this
- Risk management file
- Article 49(2) registration record for the system assessed as not high-risk
- Conformity file
recruitment and selection
Candidate recommendation that automatically becomes a decision
An employer uses a system that ranks applicants and recommends a candidate to hire. In one setup a recruiter weighs that recommendation in their own assessment; in the other the outcome is applied automatically and a candidate is rejected without anyone looking at it.
Provenance: The Commission draft guidelines of 19 May 2026 address this case when determining whether an application falls under Annex III. The document is a consultation version: non-binding and not yet final.
Assess a recruitment system on its intended purpose rather than on whether a recruiter reviews the output, because adding or removing human involvement does not change its high-risk classification.
Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III
biometrics and identification
Face comparison at the border gate: verification or identification
An automated border gate uses biometric facial recognition to compare a traveller’s face with the photo in the passport chip. The same camera could technically also compare against a law-enforcement database, and exactly that difference decides whether this biometrics is high-risk.
Provenance: The Commission draft guidelines of 19 May 2026 state that biometric verification falls outside the high-risk classification: one-to-one comparison of presented biometrics with previously stored biometrics, for the sole purpose of confirming that a person is who they claim to be. Where the same capture is additionally compared against a law-enforcement database, it does become remote biometric identification. The document is a consultation version: non-binding and not yet final.
Test your biometric application on purpose rather than technology: the same camera and the same model stay outside the high-risk route as long as the comparison is one-to-one and only confirms identity, and fall inside it as soon as that same capture is also held against a database. Record per application what the comparison runs against, because that single design choice moves the entire regime.
Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III, paragraph (136)
recruitment and selection
A CV filter that ranks applicants
An employer has an external recruitment system score and rank every incoming application, after which recruiters only review the top twenty percent by hand. The vendor puts the system on the market under its own name, and the employer uses it in its own selection process.
Provenance: The Commission draft guidelines of 19 May 2026 address this case when determining whether an application falls under Annex III. The document is a consultation version: non-binding and not yet final.
Recruiters keeping the final say does not help you, because once the system scores or ranks applicants and thereby shapes the shortlist it stays high-risk and no exemption applies.
Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III
education
Application file handling at an educational institution
An educational institution uses AI for application file handling: indexing, searching, text and speech processing, translation of documents submitted with applications, and extracting, transforming and organising the collected data into a usable format.
Provenance: The Commission draft guidelines of 19 May 2026 address this case when determining whether an application falls under Annex III. The document is a consultation version: non-binding and not yet final.
Indexing, searching, translating and reorganising application files remains preparatory work, as long as the system leaves the substantive judgment on the application entirely to the institution.
Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III
Integrating AI Act requirements into existing risk and quality systems
According to the draft guidelines of 19 May 2026, which are expressly published as a draft for stakeholder feedback and have no binding force, the AI Act provides mechanisms to reduce the compliance burden for economic operators. The draft guidelines cite Article 8(2) AI Act on the interplay with sectoral legislation, Article 9(10) AI Act on risk management and Article 17(3) AI Act on quality management, which allow economic operators to add, where necessary and appropriate, an assessment of AI-specific risks to already existing risk and quality management systems. Article 40 AI Act further requires that harmonised standards under the AI Act be consistent with standards developed under the Annex I harmonisation legislation. The draft guidelines state that these mechanisms enable economic operators to meet both the AI Act and the harmonisation legislation within a single compliance framework, thereby avoiding duplication of effort while maintaining a high level of protection of health, safety and fundamental rights.
Draft guidelines Annex I, points (61) and (62)
Annex I lists legislation, not products
The draft guidelines of 19 May 2026, published for consultation and expressly non-binding, clarify that Annex I AI Act does not list individual products to be classified as high-risk, but Union harmonisation legislation regulating the safety aspects of certain products. Whether an AI system falls within the scope of Annex I therefore depends on whether the system, or the product of which it is a safety component, falls within the material scope of one of the listed legislative acts. According to the draft guidelines the list in Annex I is exhaustive; products can only be added or removed by amending the scope of the harmonisation legislation itself or by adding new harmonisation legislation to Annex I. The draft guidelines also state that through Article 6(1) the AI Act does not itself extend the scope of harmonisation legislation to new or additional products, and that the AI Act does not determine or change the risk profile of a product but builds on the sectoral risk classification. Products mentioned include machinery, toys, lifts, equipment and protective systems for potentially explosive atmospheres, radio equipment, pressure equipment, recreational craft, cableway installations, appliances burning gaseous fuels, medical devices, in vitro diagnostic medical devices, and products in the automotive and aviation sectors.
Draft guidelines Annex I, points (23) to (26)
Section A and Section B of Annex I trigger different requirement sets
The Commission draft guidelines of 19 May 2026, which are non-binding as long as the final version has not been adopted, draw a distinction that is often missed in practice. AI systems classified as high-risk under Article 6(1) in respect of products covered by the harmonisation legislation in Section A of Annex I are subject to the requirements for high-risk systems in Section 2 of Chapter III AI Act. By contrast, for AI systems classified as high-risk under Article 6(1) in respect of products covered by the harmonisation legislation in Section B of Annex I, only Article 6(1), Articles 102 to 109 and Article 112 AI Act apply. The draft guidelines refer to Article 2(2) AI Act for this. Section A contains harmonisation legislation based on the New Legislative Framework, Section B the other Union harmonisation legislation.
Draft guidelines Annex I, point (60), referring to Article 2(2) AI Act
Two cumulative conditions for high-risk under Annex I
The European Commission draft guidelines of 19 May 2026, which are expressly non-binding and not final, read Article 6(1) as two cumulative conditions. First, the AI system must be intended to be used as a safety component of a product, or the AI system must itself be a product, covered by the Union harmonisation legislation listed in Annex I. Second, that product, or the AI system itself where it is the product, must be required to undergo a third-party conformity assessment. The draft guidelines state explicitly that not all AI systems that are components of regulated products are high-risk, but only the subset that satisfies both criteria.
Draft guidelines Annex I, points (27) and (21)
ISO/IEC 23894: guidance on risk management for AI
ISO/IEC 23894:2023 (Information technology: Artificial intelligence: Guidance on risk management) was published in February 2023 and is the first international standard dealing specifically with risk management for AI. It is non-prescriptive and built on the ISO 31000 structure. The text was adopted by CEN-CENELEC as EN ISO/IEC 23894:2024. It is not cited in the Official Journal and therefore confers no presumption of conformity under Article 40 of the AI Act. The deliverable intended to do so for Article 9 is prEN 18228.
prEN 18228: AI risk management for high-risk systems
prEN 18228 (AI risk management) is the JTC 21 deliverable under M/613 intended to confer presumption of conformity with Article 9 of the AI Act: the risk management system that providers of high-risk AI systems must establish, implement, document and maintain across the full lifecycle. The public Enquiry ran until 30 July 2026. The standard has not yet been published as an EN and is not cited in the Official Journal. The prEN designation means it is a draft text.
prEN 18285: conformity assessment framework for AI systems
prEN 18285 (Conformity assessment framework) is the JTC 21 deliverable under M/613 covering the conformity assessment of high-risk AI systems under Article 43 and Annex VII of the AI Act. As at June 2026 the deliverable was at the drafting stage. It has not yet been published as an EN and is not cited in the Official Journal. Standardisation request M/613 was amended by Implementing Decision C(2025)3871 of 23 June 2025 and expires on 28 February 2027.
General interpretation, not legal advice. Checked against Regulation (EU) 2024/1689 and the Digital Omnibus (EU) 2026/1744; the official source remains authoritative.
Full map for your situation