EU AI Act article explainer · Last verified 2026-08-02

EU AI Act Art. 9Risk management system

Article 9 requires providers of high-risk AI to run an iterative, documented risk management system across the whole lifecycle — from design through post-market monitoring. It is the spine of the Act's quality obligations.

Regulation (EU) 2024/1689Plain-English explainer · Not legal advice

At a glance

What this article requires

  • The risk management system runs continuously from design to post-market phase.
  • Risk identification, estimation, and evaluation must cover both reasonably foreseeable misuse and the interaction of the AI with the surrounding system.
  • Mitigations must follow the safety hierarchy: eliminate or reduce risk by design, then safeguard measures, then information for deployers.
  • Residual risk must be judged acceptable — the system cannot pose significant risk to health, safety, or fundamental rights.
  • Testing must be defined and proportionate, including real-world piloting where relevant.

Scope

Who this applies to

Providers of high-risk AI systems. Deployers should still ask to see the risk management documentation before procuring — it is the single best signal of a serious vendor.

Obligations

What you must actually do

Maintain a living risk file

Identify, document, and periodically update hazards and risks, including foreseeable misuse and system-environment interaction. This is an ongoing process, not a one-off assessment.

Apply the mitigation hierarchy

Prefer eliminating risk in design; where that is impossible, add safeguards; and always inform deployers about the residual risks and limitations.

Verify and report

Run proportionate testing and validation, then verify the residual risk is acceptable. Report serious incidents to market surveillance authorities and any affected deployer.

Action plan

Practical first steps

  1. 1

    Create a risk register for each high-risk system: hazards, likelihood, severity, mitigations, owner, review date.

  2. 2

    Document foreseeable misuse explicitly — regulators expect you to have thought about how users will break it.

  3. 3

    Define testing plans up front, tied to the risk profile (simulation, real-world pilots, synthetic data).

  4. 4

    Set a cadence to revisit the register: after each release, after incidents, and at least annually.

Penalty exposure

Failures of Article 9 fall in the general tier: up to €15 million or 3% of global annual turnover.

FAQ

Questions about Art. 9

Does Article 9 apply to low-risk AI?

No — the risk management system is mandatory only for high-risk AI. Limited-risk systems (chatbots, deepfakes) carry lighter transparency duties under Article 50 instead.

How detailed does my risk file need to be?

Proportionate to the system's risk: a hiring screener needs a rigorous file with bias analyses; a low-severity decision-support tool needs a lighter one. The standard is 'accepted state of the art' risk management.

Sources

Citations & further reading

Related

More article explainers

Wondering which articles apply to your AI?

Describe your system in the free Risk Scanner and get a preliminary risk read with the obligations that likely apply — in seconds.

Check my use case

Preliminary EU AI Act clarity summary. Not legal advice.