Skip to main content
Praxikon
Back to the explorer
StandardGuidancev1.0.0

prEN 18228: AI risk management for high-risk systems

The draft European standard filling in the Article 9 risk management system, built on a product-safety logic rather than an enterprise-risk logic.

The official source remains authoritative. This is general information about obligations and not legal advice. See this object on the map

Address and citation

This object has an address of its own that is never renamed or reused. Store the identifier in your own file, not the title or the link.

Identifier
praxikon:eu:ai-act:standard:standard-pren-18228-ai-risk-management
Payload hash (sha256)
efc0d590e74fcc9850050e3c063c288082c701a96530ffc6c49dcaaea71ea1b4

Citation line

Praxikon, "prEN 18228: AI risk management for high-risk systems", praxikon:eu:ai-act:standard:standard-pren-18228-ai-risk-management@1.0.0, dataset praxikon:sys:registry:dataset:ai-act-implementation-graph 2.1.0 (schema 1.4.0), effective_at 2026-08-08T00:00:00.000Z, known_at 2026-08-14T00:00:00.000Z, sha256 efc0d590e74fcc9850050e3c063c288082c701a96530ffc6c49dcaaea71ea1b4
Version
1.0.0
Legal time (effective_at)
8 August 2026
Knowledge time (known_at)
8 August 2026
Closed on
Not closed
Topics
standards

Review status: Placed against the official source (8 August 2026). Next check due by 4 February 2027. The check date is the knowledge date of this version; no later recheck has been recorded.

What this object links to

Every relation appears below as a path: from the source with its locator, through the conditions and exceptions of the object carrying the relation, to the consequence. A locator belongs to a statement in the data and not to a relation, so the source is the source anchor of the carrying object.

The obligation this hangs off

1 of 1 shown

The object belongs to this obligation. The source line it hangs off sits there.

  1. Source

    Official fact on this object, with its locator.

    • CEN-CENELEC JTC 21: European standards under standardisation request M/613

      Locator: prEN 18228 (draft standard), CEN/CLC/JTC 21 under M/613

      praxikon:eu:ai-act:source:cen-cenelec-jtc21

      Open official source
    • EU Artificial Intelligence Act 2024/1689

      Locator: Article 9; Article 40

      praxikon:eu:ai-act:source:reg-eu-2024-1689

      Open official source

    Via

    • Condition | allRelevant to providers preparing for the high-risk obligations applying from 2 December 2027 (Annex III) or 2 August 2028 (Annex I).

    Consequence

What this object is about

1 of 1 shown

The object is about this role. Undifferentiated: it does not follow that the duty rests on this role.

  1. Source

    Official fact on this object, with its locator.

    • CEN-CENELEC JTC 21: European standards under standardisation request M/613

      Locator: prEN 18228 (draft standard), CEN/CLC/JTC 21 under M/613

      praxikon:eu:ai-act:source:cen-cenelec-jtc21

      Open official source
    • EU Artificial Intelligence Act 2024/1689

      Locator: Article 9; Article 40

      praxikon:eu:ai-act:source:reg-eu-2024-1689

      Open official source

    Via

    • Condition | allRelevant to providers preparing for the high-risk obligations applying from 2 December 2027 (Annex III) or 2 August 2028 (Annex I).

    Consequence

What this object states

Official fact

Attributable to a named primary source, with a locator. Where they differ, the official source prevails.

  • prEN 18228 (AI risk management) is the JTC 21 deliverable under M/613 intended to confer presumption of conformity with Article 9 of the AI Act: the risk management system that providers of high-risk AI systems must establish, implement, document and maintain across the full lifecycle. The public Enquiry ran until 30 July 2026. The standard has not yet been published as an EN and is not cited in the Official Journal. The prEN designation means it is a draft text.

    • Locator: prEN 18228 (draft standard), CEN/CLC/JTC 21 under M/613praxikon:eu:ai-act:source:cen-cenelec-jtc21Open official source
    • Locator: Article 9; Article 40praxikon:eu:ai-act:source:reg-eu-2024-1689Open official source

Our interpretation

Our own reading. It can change without the law changing, and it is not the position of a supervisory authority.

  • The distinguishing feature is the perspective. prEN 18228 is written from product safety: it concerns risks to the health, safety and fundamental rights of third parties, not risks to your organisation. Anyone filling an Article 9 dossier with an existing ISO 31000 or ERM register makes exactly the mistake this standard exposes: that register looks inward, Article 9 looks outward. And a draft standard is not yet evidence: you can adopt the method, but you cannot prove anything with it towards a supervisory authority today.

    • Locator: prEN 18228 (draft standard), CEN/CLC/JTC 21 under M/613praxikon:eu:ai-act:source:cen-cenelec-jtc21Open official source
    • Locator: Article 9; Article 40praxikon:eu:ai-act:source:reg-eu-2024-1689Open official source

Recommended step

A practical step we consider appropriate. Not an obligation following from the Regulation.

  • Build your Article 9 risk register now with an outward view: for each foreseeable use and foreseeable misuse, name the person or group who can be affected, the measure that reduces the risk, and the residual risk that remains. Keep the structure separate from your ERM register so the final EN 18228 can be mapped over it later without rewriting the content.

    • Locator: prEN 18228 (draft standard), CEN/CLC/JTC 21 under M/613praxikon:eu:ai-act:source:cen-cenelec-jtc21Open official source
    • Locator: Article 9; Article 40praxikon:eu:ai-act:source:reg-eu-2024-1689Open official source

When this applies

  1. 1Relevant to providers preparing for the high-risk obligations applying from 2 December 2027 (Annex III) or 2 August 2028 (Annex I).

When this does not apply

No exception recorded on this object.

Referring to this object

Citation block

Copy this reference into your advice, article or file. The identifier, the version and the hash keep the statement findable later, even once the dataset has moved on.

Reference

Praxikon, "prEN 18228: AI risk management for high-risk systems",
praxikon:eu:ai-act:standard:standard-pren-18228-ai-risk-management@1.0.0,
dataset praxikon:sys:registry:dataset:ai-act-implementation-graph 2.1.0 (schema 1.4.0),
effective_at 2026-08-08T00:00:00.000Z, known_at 2026-08-08T00:00:00.000Z,
sha256 efc0d590e74fcc9850050e3c063c288082c701a96530ffc6c49dcaaea71ea1b4,
https://www.praxikon.com/en/verkenner/standard/standard-pren-18228-ai-risk-management
(https://www.praxikon.com/api/v1/entities?id=praxikon%3Aeu%3Aai-act%3Astandard%3Astandard-pren-18228-ai-risk-management&effective_at=2026-08-08&known_at=2026-08-08&lang=en, accessed 2026-08-25)

Short form

praxikon:eu:ai-act:standard:standard-pren-18228-ai-risk-management@1.0.0 (sha256 efc0d590)

BibTeX

@misc{praxikon-eu-ai-act-standard-standard-pren-18228-ai-risk-management-1-0-0,
  author       = {{Praxikon}},
  title        = {prEN 18228: AI risk management for high-risk systems},
  year         = {2026},
  version      = {1.0.0},
  number       = {praxikon:eu:ai-act:standard:standard-pren-18228-ai-risk-management},
  howpublished = {AI Act Change \& Evidence Graph, dataset 2.1.0, schema 1.4.0},
  note         = {effective_at 2026-08-08T00:00:00.000Z; known_at 2026-08-08T00:00:00.000Z; sha256 efc0d590e74fcc9850050e3c063c288082c701a96530ffc6c49dcaaea71ea1b4},
  url          = {https://www.praxikon.com/en/verkenner/standard/standard-pren-18228-ai-risk-management},
  urldate      = {2026-08-25},
  language     = {en}
}

CSL JSON

[
  {
    "id": "praxikon:eu:ai-act:standard:standard-pren-18228-ai-risk-management@1.0.0",
    "type": "dataset",
    "title": "prEN 18228: AI risk management for high-risk systems",
    "container-title": "AI Act Change & Evidence Graph",
    "publisher": "Praxikon",
    "version": "1.0.0",
    "number": "praxikon:eu:ai-act:standard:standard-pren-18228-ai-risk-management",
    "URL": "https://www.praxikon.com/en/verkenner/standard/standard-pren-18228-ai-risk-management",
    "language": "en",
    "issued": {
      "date-parts": [
        [
          2026,
          8,
          8
        ]
      ]
    },
    "accessed": {
      "date-parts": [
        [
          2026,
          8,
          25
        ]
      ]
    },
    "note": "dataset praxikon:sys:registry:dataset:ai-act-implementation-graph 2.1.0; schema 1.4.0; effective_at 2026-08-08T00:00:00.000Z; known_at 2026-08-08T00:00:00.000Z; sha256 efc0d590e74fcc9850050e3c063c288082c701a96530ffc6c49dcaaea71ea1b4; retrieved_from https://www.praxikon.com/api/v1/entities?id=praxikon%3Aeu%3Aai-act%3Astandard%3Astandard-pren-18228-ai-risk-management&effective_at=2026-08-08&known_at=2026-08-08&lang=en; licence https://www.praxikon.com/nl/legal/terms"
  }
]

How to verify a reference later is set out in the methodology. Terms

For agents and integrations

This page and the machine output come from the same object and the same two time axes.