Skip to main content
Praxikon
All obligations
Upcomingv1.0.0

Article 9: risk management system

A continuous, documented risk management system across the entire lifecycle of a high-risk AI system.

Article 9 requires a risk management system as a continuous, iterative process across the entire lifecycle, with identification, analysis, evaluation and mitigation of risks to health, safety and fundamental rights, and testing to determine the most appropriate measures.

Praxikon tracks Article 9: risk management system under the EU AI Act, checked against the official source on 8 August 2026, citing the source for every statement.

Status
Upcoming
Application date
2 December 2027
Version
1.0.0
Last reviewed
8 August 2026

Review status: placed against the official source (8 August 2026). Next check due by 4 February 2027. The check date is the knowledge date of this version; no later recheck has been recorded.

From source to evidence

Why this obligation applies, what it asks of you, and what you show for it.

Applies

Upcoming · 2 December 2027

For whom

Provider of an AI system

What you do

Set up an iterative risk management process

What you record

Risk management file

Official source

Article 9(1)-(10)

Who this is relevant to

When this applies

  • Provider of an AI system

    A party that develops or has an AI system developed and places it on the market under its own name.

  1. 1The system is high-risk under Article 6 and the provider places it on the market or puts it into service.

What the official source establishes

For the Annex III route this requirement applies from 2 December 2027; for high-risk AI in regulated products (Annex I) from 2 August 2028.

Our interpretation

The official source remains authoritative. This general interpretation is not legal advice.

This is not a one-off risk analysis but a living process: most organisations have an assessment, but no cycle that reruns on every change. The cycle is what a supervisor will request.

What you can do now

Start the risk management file now for systems that will become high-risk towards 2 December 2027: today’s design and procurement choices determine tomorrow’s residual risks.

  1. 01

    Set up an iterative risk management process

    Identify and analyse known and reasonably foreseeable risks, evaluate them and take measures, repeating the cycle on every change.

What to retain

Risk management file

Versioned record of risk analyses, chosen measures, residual risks and test results per system version.

Control and reassessment

  • Reassessment on every material change

    Reopen the risk management process on changes in purpose, data, model or use context and before every release.

Public tools

Conditions and exceptions

  • Risks arising only from misuse beyond any reasonably foreseeable use fall outside the mandatory scope.

Official sources and locators

  • EU Artificial Intelligence Act 2024/1689

    European Parliament and Council | original-oj-2024-07-12

    Source locator: Article 9(1)-(10)

  • Digital Omnibus on AI 2026/1744

    European Parliament and Council | official-journal-2026-07-24

    Source locator: Amended Article 113 application dates

Referring to this object

Citation block

Copy this reference into your advice, article or file. The identifier, the version and the hash keep the statement findable later, even once the dataset has moved on.

Reference

Praxikon, "Article 9: risk management system",
praxikon:eu:ai-act:obligation:article-9-risk-management@1.0.0,
dataset praxikon:sys:registry:dataset:ai-act-implementation-graph 2.2.0 (schema 1.5.0),
effective_at 2026-07-27T00:00:00.000Z, known_at 2026-08-08T00:00:00.000Z,
sha256 dba4fb36d8780aa218d15aae4742d2183cfcf1fd6f85a6d4db5901b93c9e6c53,
https://www.praxikon.com/en/verplichtingen/article-9-risk-management
(https://www.praxikon.com/api/v1/obligations?id=praxikon%3Aeu%3Aai-act%3Aobligation%3Aarticle-9-risk-management&effective_at=2026-07-27&known_at=2026-08-08&lang=en, accessed 2026-09-07)

Short form

praxikon:eu:ai-act:obligation:article-9-risk-management@1.0.0 (sha256 dba4fb36)

BibTeX

@misc{praxikon-eu-ai-act-obligation-article-9-risk-management-1-0-0,
  author       = {{Praxikon}},
  title        = {Article 9: risk management system},
  year         = {2026},
  version      = {1.0.0},
  number       = {praxikon:eu:ai-act:obligation:article-9-risk-management},
  howpublished = {AI Act Change \& Evidence Graph, dataset 2.2.0, schema 1.5.0},
  note         = {effective_at 2026-07-27T00:00:00.000Z; known_at 2026-08-08T00:00:00.000Z; sha256 dba4fb36d8780aa218d15aae4742d2183cfcf1fd6f85a6d4db5901b93c9e6c53},
  url          = {https://www.praxikon.com/en/verplichtingen/article-9-risk-management},
  urldate      = {2026-09-07},
  language     = {en}
}

CSL JSON

[
  {
    "id": "praxikon:eu:ai-act:obligation:article-9-risk-management@1.0.0",
    "type": "dataset",
    "title": "Article 9: risk management system",
    "container-title": "AI Act Change & Evidence Graph",
    "publisher": "Praxikon",
    "version": "1.0.0",
    "number": "praxikon:eu:ai-act:obligation:article-9-risk-management",
    "URL": "https://www.praxikon.com/en/verplichtingen/article-9-risk-management",
    "language": "en",
    "issued": {
      "date-parts": [
        [
          2026,
          8,
          8
        ]
      ]
    },
    "accessed": {
      "date-parts": [
        [
          2026,
          9,
          7
        ]
      ]
    },
    "note": "dataset praxikon:sys:registry:dataset:ai-act-implementation-graph 2.2.0; schema 1.5.0; effective_at 2026-07-27T00:00:00.000Z; known_at 2026-08-08T00:00:00.000Z; sha256 dba4fb36d8780aa218d15aae4742d2183cfcf1fd6f85a6d4db5901b93c9e6c53; retrieved_from https://www.praxikon.com/api/v1/obligations?id=praxikon%3Aeu%3Aai-act%3Aobligation%3Aarticle-9-risk-management&effective_at=2026-07-27&known_at=2026-08-08&lang=en; licence https://www.praxikon.com/nl/legal/terms"
  }
]

How to verify a reference later is set out in the methodology. Terms

Version history

  1. v1.0.0

    27 July 2026

    Article 9: risk management system

    A continuous, documented risk management system across the entire lifecycle of a high-risk AI system.

Corrections to this obligation

No substantive correction to this object has been recorded.

Open the correction log
Zahed Ashkara, lawyer and AI governance specialist

Expert behind this page

Zahed Ashkara

Lawyer and AI governance specialist

Execution

From obligation to arranged and demonstrable

Knowing where you stand is step one. Embed AI translates this obligation into a concrete approach for your organisation: scope, ownership, register and evidence.

See the Embed AI approach

For AI agents and integrations

This page and the machine output derive from the same versioned object. Use the API for deterministic filters by role, topic and time.