Comparison
Article 27 versus Article 9: FRIA and risk management system
The difference
The risk management system of Article 9 sits with the provider and concerns the risks of the system itself, across its whole lifecycle. The assessment of Article 27 sits with a subset of deployers and concerns the consequences for the fundamental rights of the people the system is applied to in their own use situation.
The official source remains authoritative. This is general interpretation and not legal advice about your situation.
The fields side by side
Every row comes from the objects themselves. Where a field is empty, it says so; we do not fill in an assumption where the source is silent.
Status
- Article 27, FRIA
- Upcoming
- Article 9, risk management system
- Upcoming
Applies from
- Article 27, FRIA
- 2 December 2027
- Article 9, risk management system
- 2 December 2027
Who carries the duty
- Article 27, FRIA
- Credit or insurance deployer, Body governed by public law, Private provider of public services
- Article 9, risk management system
- Provider of an AI system
Who is affected
- Article 27, FRIA
- Not recorded
- Article 9, risk management system
- Not recorded
Who supervises
- Article 27, FRIA
- Not recorded
- Article 9, risk management system
- Not recorded
When this applies
- Article 27, FRIA
- The system is high-risk under Article 6(2) and Annex III, excluding Annex III point 2. The deployer is a body governed by public law, a private provider of public services or uses a relevant system in Annex III point 5(b) or 5(c).
- Article 9, risk management system
- The system is high-risk under Article 6 and the provider places it on the market or puts it into service.
Exceptions
- Article 27, FRIA
- In the situation covered by Article 46(1), an exemption from notification may apply. This does not generally remove the assessment itself.
- Article 9, risk management system
- Risks arising only from misuse beyond any reasonably foreseeable use fall outside the mandatory scope.
First actions
- Article 27, FRIA
- Perform a FRIA before deployment
- Article 9, risk management system
- Set up an iterative risk management process
Evidence that belongs with it
- Article 27, FRIA
- FRIA report and notification
- Article 9, risk management system
- Risk management file
Control
- Article 27, FRIA
- Pre-deployment FRIA go/no-go
- Article 9, risk management system
- Reassessment on every material change
Version and review status
- Article 27, FRIA
- v1.0.0, placed against the official source
- Article 9, risk management system
- v1.0.0, placed against the official source
Official sources and locators
Per side, the provisions the statements above rest on.
Article 27, FRIA
EU Artificial Intelligence Act 2024/1689
Locator: Article 27(1)-(5)
Open official sourceDigital Omnibus on AI 2026/1744
Locator: Amended application schedule and Article 27 DPIA cross-reference
Open official sourceEU Artificial Intelligence Act 2024/1689
Locator: Article 27(1)
Open official sourceDigital Omnibus on AI 2026/1744
Locator: Article 27 amendment on DPIA inclusion or cross-reference
Open official source
Article 9, risk management system
EU Artificial Intelligence Act 2024/1689
Locator: Article 9(1)-(10)
Open official sourceDigital Omnibus on AI 2026/1744
Locator: Amended Article 113 application dates
Open official source
Referring to these two objects
Each side has its own stable identifier, version and hash. Take them separately; you cite a comparison by citing the two objects.
Referring to this object
Citation block
Copy this reference into your advice, article or file. The identifier, the version and the hash keep the statement findable later, even once the dataset has moved on.
Reference
Praxikon, "Article 27: FRIA", praxikon:eu:ai-act:obligation:article-27-fria@1.0.0, dataset praxikon:sys:registry:dataset:ai-act-implementation-graph 2.1.0 (schema 1.4.0), effective_at 2026-07-27T00:00:00.000Z, known_at 2026-08-08T00:00:00.000Z, sha256 498c93501f9972d34831aea9c643908d910568bd188c1f76ddb2786c3836b98e, https://www.praxikon.com/en/verplichtingen/article-27-fria (https://www.praxikon.com/api/v1/obligations?id=praxikon%3Aeu%3Aai-act%3Aobligation%3Aarticle-27-fria&effective_at=2026-07-27&known_at=2026-08-08&lang=en, accessed 2026-08-24)
Short form
praxikon:eu:ai-act:obligation:article-27-fria@1.0.0 (sha256 498c9350)
BibTeX
@misc{praxikon-eu-ai-act-obligation-article-27-fria-1-0-0,
author = {{Praxikon}},
title = {Article 27: FRIA},
year = {2026},
version = {1.0.0},
number = {praxikon:eu:ai-act:obligation:article-27-fria},
howpublished = {AI Act Change \& Evidence Graph, dataset 2.1.0, schema 1.4.0},
note = {effective_at 2026-07-27T00:00:00.000Z; known_at 2026-08-08T00:00:00.000Z; sha256 498c93501f9972d34831aea9c643908d910568bd188c1f76ddb2786c3836b98e},
url = {https://www.praxikon.com/en/verplichtingen/article-27-fria},
urldate = {2026-08-24},
language = {en}
}CSL JSON
[
{
"id": "praxikon:eu:ai-act:obligation:article-27-fria@1.0.0",
"type": "dataset",
"title": "Article 27: FRIA",
"container-title": "AI Act Change & Evidence Graph",
"publisher": "Praxikon",
"version": "1.0.0",
"number": "praxikon:eu:ai-act:obligation:article-27-fria",
"URL": "https://www.praxikon.com/en/verplichtingen/article-27-fria",
"language": "en",
"issued": {
"date-parts": [
[
2026,
8,
8
]
]
},
"accessed": {
"date-parts": [
[
2026,
8,
24
]
]
},
"note": "dataset praxikon:sys:registry:dataset:ai-act-implementation-graph 2.1.0; schema 1.4.0; effective_at 2026-07-27T00:00:00.000Z; known_at 2026-08-08T00:00:00.000Z; sha256 498c93501f9972d34831aea9c643908d910568bd188c1f76ddb2786c3836b98e; retrieved_from https://www.praxikon.com/api/v1/obligations?id=praxikon%3Aeu%3Aai-act%3Aobligation%3Aarticle-27-fria&effective_at=2026-07-27&known_at=2026-08-08&lang=en; licence https://www.praxikon.com/nl/legal/terms"
}
]How to verify a reference later is set out in the methodology. Terms
Referring to this object
Citation block
Copy this reference into your advice, article or file. The identifier, the version and the hash keep the statement findable later, even once the dataset has moved on.
Reference
Praxikon, "Article 9: risk management system", praxikon:eu:ai-act:obligation:article-9-risk-management@1.0.0, dataset praxikon:sys:registry:dataset:ai-act-implementation-graph 2.1.0 (schema 1.4.0), effective_at 2026-07-27T00:00:00.000Z, known_at 2026-08-08T00:00:00.000Z, sha256 dba4fb36d8780aa218d15aae4742d2183cfcf1fd6f85a6d4db5901b93c9e6c53, https://www.praxikon.com/en/verplichtingen/article-9-risk-management (https://www.praxikon.com/api/v1/obligations?id=praxikon%3Aeu%3Aai-act%3Aobligation%3Aarticle-9-risk-management&effective_at=2026-07-27&known_at=2026-08-08&lang=en, accessed 2026-08-24)
Short form
praxikon:eu:ai-act:obligation:article-9-risk-management@1.0.0 (sha256 dba4fb36)
BibTeX
@misc{praxikon-eu-ai-act-obligation-article-9-risk-management-1-0-0,
author = {{Praxikon}},
title = {Article 9: risk management system},
year = {2026},
version = {1.0.0},
number = {praxikon:eu:ai-act:obligation:article-9-risk-management},
howpublished = {AI Act Change \& Evidence Graph, dataset 2.1.0, schema 1.4.0},
note = {effective_at 2026-07-27T00:00:00.000Z; known_at 2026-08-08T00:00:00.000Z; sha256 dba4fb36d8780aa218d15aae4742d2183cfcf1fd6f85a6d4db5901b93c9e6c53},
url = {https://www.praxikon.com/en/verplichtingen/article-9-risk-management},
urldate = {2026-08-24},
language = {en}
}CSL JSON
[
{
"id": "praxikon:eu:ai-act:obligation:article-9-risk-management@1.0.0",
"type": "dataset",
"title": "Article 9: risk management system",
"container-title": "AI Act Change & Evidence Graph",
"publisher": "Praxikon",
"version": "1.0.0",
"number": "praxikon:eu:ai-act:obligation:article-9-risk-management",
"URL": "https://www.praxikon.com/en/verplichtingen/article-9-risk-management",
"language": "en",
"issued": {
"date-parts": [
[
2026,
8,
8
]
]
},
"accessed": {
"date-parts": [
[
2026,
8,
24
]
]
},
"note": "dataset praxikon:sys:registry:dataset:ai-act-implementation-graph 2.1.0; schema 1.4.0; effective_at 2026-07-27T00:00:00.000Z; known_at 2026-08-08T00:00:00.000Z; sha256 dba4fb36d8780aa218d15aae4742d2183cfcf1fd6f85a6d4db5901b93c9e6c53; retrieved_from https://www.praxikon.com/api/v1/obligations?id=praxikon%3Aeu%3Aai-act%3Aobligation%3Aarticle-9-risk-management&effective_at=2026-07-27&known_at=2026-08-08&lang=en; licence https://www.praxikon.com/nl/legal/terms"
}
]How to verify a reference later is set out in the methodology. Terms
Execution
Run the assessment and keep the file together
An assessment of fundamental rights consequences touches the DPIA, the register and human oversight, and in practice those four drift apart. Praxikon does not carry that out; Embed AI runs the assessment with your team and delivers the evidence file.
See the Embed AI approachOther comparisons
- Article 16 versus Article 26: what the provider owes and what the deployer owes
- Article 26 versus Article 27: using and assessing
- Article 4 versus Article 14: literacy and human oversight
- GPAI versus high-risk: the model or the use
- Article 5 versus Annex III: prohibited or high-risk
- Article 50 versus Article 13: two kinds of transparency
Unsure about your role itself rather than the duties that come with it? Work out whether you are a provider or a deployer