Skip to main content
Praxikon
Comparisons

Comparison

Article 27 versus Article 9: FRIA and risk management system

The difference

The risk management system of Article 9 sits with the provider and concerns the risks of the system itself, across its whole lifecycle. The assessment of Article 27 sits with a subset of deployers and concerns the consequences for the fundamental rights of the people the system is applied to in their own use situation.

The official source remains authoritative. This is general interpretation and not legal advice about your situation.

The fields side by side

Every row comes from the objects themselves. Where a field is empty, it says so; we do not fill in an assumption where the source is silent.

Status

Article 27, FRIA
Upcoming
Article 9, risk management system
Upcoming

Applies from

Article 27, FRIA
2 December 2027
Article 9, risk management system
2 December 2027

Who carries the duty

Article 27, FRIA
Credit or insurance deployer, Body governed by public law, Private provider of public services
Article 9, risk management system
Provider of an AI system

Who is affected

Article 27, FRIA
Not recorded
Article 9, risk management system
Not recorded

Who supervises

Article 27, FRIA
Not recorded
Article 9, risk management system
Not recorded

When this applies

Article 27, FRIA
The system is high-risk under Article 6(2) and Annex III, excluding Annex III point 2. The deployer is a body governed by public law, a private provider of public services or uses a relevant system in Annex III point 5(b) or 5(c).
Article 9, risk management system
The system is high-risk under Article 6 and the provider places it on the market or puts it into service.

Exceptions

Article 27, FRIA
In the situation covered by Article 46(1), an exemption from notification may apply. This does not generally remove the assessment itself.
Article 9, risk management system
Risks arising only from misuse beyond any reasonably foreseeable use fall outside the mandatory scope.

First actions

Article 27, FRIA
Perform a FRIA before deployment
Article 9, risk management system
Set up an iterative risk management process

Evidence that belongs with it

Article 27, FRIA
FRIA report and notification
Article 9, risk management system
Risk management file

Control

Article 27, FRIA
Pre-deployment FRIA go/no-go
Article 9, risk management system
Reassessment on every material change

Version and review status

Article 27, FRIA
v1.0.0, placed against the official source
Article 9, risk management system
v1.0.0, placed against the official source

Official sources and locators

Per side, the provisions the statements above rest on.

Article 27, FRIA

  • EU Artificial Intelligence Act 2024/1689

    Locator: Article 27(1)-(5)

    Open official source
  • Digital Omnibus on AI 2026/1744

    Locator: Amended application schedule and Article 27 DPIA cross-reference

    Open official source
  • EU Artificial Intelligence Act 2024/1689

    Locator: Article 27(1)

    Open official source
  • Digital Omnibus on AI 2026/1744

    Locator: Article 27 amendment on DPIA inclusion or cross-reference

    Open official source

Article 9, risk management system

Referring to these two objects

Each side has its own stable identifier, version and hash. Take them separately; you cite a comparison by citing the two objects.

Referring to this object

Citation block

Copy this reference into your advice, article or file. The identifier, the version and the hash keep the statement findable later, even once the dataset has moved on.

Reference

Praxikon, "Article 27: FRIA",
praxikon:eu:ai-act:obligation:article-27-fria@1.0.0,
dataset praxikon:sys:registry:dataset:ai-act-implementation-graph 2.1.0 (schema 1.4.0),
effective_at 2026-07-27T00:00:00.000Z, known_at 2026-08-08T00:00:00.000Z,
sha256 498c93501f9972d34831aea9c643908d910568bd188c1f76ddb2786c3836b98e,
https://www.praxikon.com/en/verplichtingen/article-27-fria
(https://www.praxikon.com/api/v1/obligations?id=praxikon%3Aeu%3Aai-act%3Aobligation%3Aarticle-27-fria&effective_at=2026-07-27&known_at=2026-08-08&lang=en, accessed 2026-08-24)

Short form

praxikon:eu:ai-act:obligation:article-27-fria@1.0.0 (sha256 498c9350)

BibTeX

@misc{praxikon-eu-ai-act-obligation-article-27-fria-1-0-0,
  author       = {{Praxikon}},
  title        = {Article 27: FRIA},
  year         = {2026},
  version      = {1.0.0},
  number       = {praxikon:eu:ai-act:obligation:article-27-fria},
  howpublished = {AI Act Change \& Evidence Graph, dataset 2.1.0, schema 1.4.0},
  note         = {effective_at 2026-07-27T00:00:00.000Z; known_at 2026-08-08T00:00:00.000Z; sha256 498c93501f9972d34831aea9c643908d910568bd188c1f76ddb2786c3836b98e},
  url          = {https://www.praxikon.com/en/verplichtingen/article-27-fria},
  urldate      = {2026-08-24},
  language     = {en}
}

CSL JSON

[
  {
    "id": "praxikon:eu:ai-act:obligation:article-27-fria@1.0.0",
    "type": "dataset",
    "title": "Article 27: FRIA",
    "container-title": "AI Act Change & Evidence Graph",
    "publisher": "Praxikon",
    "version": "1.0.0",
    "number": "praxikon:eu:ai-act:obligation:article-27-fria",
    "URL": "https://www.praxikon.com/en/verplichtingen/article-27-fria",
    "language": "en",
    "issued": {
      "date-parts": [
        [
          2026,
          8,
          8
        ]
      ]
    },
    "accessed": {
      "date-parts": [
        [
          2026,
          8,
          24
        ]
      ]
    },
    "note": "dataset praxikon:sys:registry:dataset:ai-act-implementation-graph 2.1.0; schema 1.4.0; effective_at 2026-07-27T00:00:00.000Z; known_at 2026-08-08T00:00:00.000Z; sha256 498c93501f9972d34831aea9c643908d910568bd188c1f76ddb2786c3836b98e; retrieved_from https://www.praxikon.com/api/v1/obligations?id=praxikon%3Aeu%3Aai-act%3Aobligation%3Aarticle-27-fria&effective_at=2026-07-27&known_at=2026-08-08&lang=en; licence https://www.praxikon.com/nl/legal/terms"
  }
]

How to verify a reference later is set out in the methodology. Terms

Referring to this object

Citation block

Copy this reference into your advice, article or file. The identifier, the version and the hash keep the statement findable later, even once the dataset has moved on.

Reference

Praxikon, "Article 9: risk management system",
praxikon:eu:ai-act:obligation:article-9-risk-management@1.0.0,
dataset praxikon:sys:registry:dataset:ai-act-implementation-graph 2.1.0 (schema 1.4.0),
effective_at 2026-07-27T00:00:00.000Z, known_at 2026-08-08T00:00:00.000Z,
sha256 dba4fb36d8780aa218d15aae4742d2183cfcf1fd6f85a6d4db5901b93c9e6c53,
https://www.praxikon.com/en/verplichtingen/article-9-risk-management
(https://www.praxikon.com/api/v1/obligations?id=praxikon%3Aeu%3Aai-act%3Aobligation%3Aarticle-9-risk-management&effective_at=2026-07-27&known_at=2026-08-08&lang=en, accessed 2026-08-24)

Short form

praxikon:eu:ai-act:obligation:article-9-risk-management@1.0.0 (sha256 dba4fb36)

BibTeX

@misc{praxikon-eu-ai-act-obligation-article-9-risk-management-1-0-0,
  author       = {{Praxikon}},
  title        = {Article 9: risk management system},
  year         = {2026},
  version      = {1.0.0},
  number       = {praxikon:eu:ai-act:obligation:article-9-risk-management},
  howpublished = {AI Act Change \& Evidence Graph, dataset 2.1.0, schema 1.4.0},
  note         = {effective_at 2026-07-27T00:00:00.000Z; known_at 2026-08-08T00:00:00.000Z; sha256 dba4fb36d8780aa218d15aae4742d2183cfcf1fd6f85a6d4db5901b93c9e6c53},
  url          = {https://www.praxikon.com/en/verplichtingen/article-9-risk-management},
  urldate      = {2026-08-24},
  language     = {en}
}

CSL JSON

[
  {
    "id": "praxikon:eu:ai-act:obligation:article-9-risk-management@1.0.0",
    "type": "dataset",
    "title": "Article 9: risk management system",
    "container-title": "AI Act Change & Evidence Graph",
    "publisher": "Praxikon",
    "version": "1.0.0",
    "number": "praxikon:eu:ai-act:obligation:article-9-risk-management",
    "URL": "https://www.praxikon.com/en/verplichtingen/article-9-risk-management",
    "language": "en",
    "issued": {
      "date-parts": [
        [
          2026,
          8,
          8
        ]
      ]
    },
    "accessed": {
      "date-parts": [
        [
          2026,
          8,
          24
        ]
      ]
    },
    "note": "dataset praxikon:sys:registry:dataset:ai-act-implementation-graph 2.1.0; schema 1.4.0; effective_at 2026-07-27T00:00:00.000Z; known_at 2026-08-08T00:00:00.000Z; sha256 dba4fb36d8780aa218d15aae4742d2183cfcf1fd6f85a6d4db5901b93c9e6c53; retrieved_from https://www.praxikon.com/api/v1/obligations?id=praxikon%3Aeu%3Aai-act%3Aobligation%3Aarticle-9-risk-management&effective_at=2026-07-27&known_at=2026-08-08&lang=en; licence https://www.praxikon.com/nl/legal/terms"
  }
]

How to verify a reference later is set out in the methodology. Terms

Execution

Run the assessment and keep the file together

An assessment of fundamental rights consequences touches the DPIA, the register and human oversight, and in practice those four drift apart. Praxikon does not carry that out; Embed AI runs the assessment with your team and delivers the evidence file.

See the Embed AI approach

Unsure about your role itself rather than the duties that come with it? Work out whether you are a provider or a deployer