Does EU AI Act require Risk Assessment?

European Union • phased enforcement

Yes — 2 provisions

Requirements at a glance

This regulation imposes 23 specific requirements for Risk Assessment across 2 provisions:

Risk Management (Article 9)

Copy link to this provision

Obligation:
Risk Assessment
enacted
Effective:
Dec 2, 2027
Risk tier:
high-risk
Scope:
Providers of high-risk AI systems within Article 2 scope; Article 2(2) limits direct application for Article 6(1) systems related to Annex I Section B products
Deferred with the rest of Chapter III Sections 1-3 by Regulation (EU) 2026/1744: 2027-12-02 for systems high-risk under Article 6(2) and Annex III, and 2028-08-02 for systems high-risk under Article 6(1) and Annex I. The `Effective` field carries the earlier of the two.

Requirements

RequirementDetails
Risk management systemEstablish, implement, document, and maintain a risk management system (Article 9(1))
Identify and analyzeIdentify known and reasonably foreseeable risks to health, safety, and fundamental rights during intended use (Article 9(2)(a))
Estimate and evaluateEstimate and evaluate risks that may emerge under intended use and reasonably foreseeable misuse conditions (Article 9(2)(b))
Post-market evaluationEvaluate risks based on data from post-market monitoring (Article 9(2)(c))
Risk mitigationAdopt appropriate and targeted measures addressing the risks identified under Article 9(2)(a) (Article 9(2)(d))
Risk boundaryArticle 9 concerns only risks reasonably mitigated or eliminated through system development or design, or provision of adequate technical information (Article 9(3))
Design-based reductionEliminate or reduce risks through adequate design and development where technically feasible (Article 9(5)(a))
Residual riskEnsure residual risk associated with each hazard and overall residual risk is judged acceptable (Article 9(5))
TestingTest to identify appropriate risk management measures and ensure consistent performance and compliance; tested against prior defined metrics and probabilistic thresholds (Article 9(6)-(8))
Iterative reviewPlan and run the risk management system as a continuous iterative process throughout the entire lifecycle, with regular systematic review and updating (Article 9(2))
Children and vulnerable groupsWhen implementing the risk management system, providers must consider whether the system is likely to adversely affect persons under 18 and, as appropriate, other vulnerable groups (Article 9(9))
Other Union-law risk processesProviders subject to internal risk-management requirements under other Union law may include or combine Article 9(1)-(9) aspects in those procedures (Article 9(10))

Penalties

ViolationFine
Provider non-compliance through Article 16(a)Up to EUR 15 million; for undertakings, up to 3% of total worldwide annual turnover for the preceding financial year or EUR 15 million, whichever is higher. For SMEs (including start-ups) and SMCs, the lower of the amount or percentage applies (Article 99(4), (6), and (6a)). Applicability depends on the relevant duty and its application date.

Fundamental Rights Impact Assessment (Article 27)

Copy link to this provision

Obligation:
Risk Assessment
enacted
Effective:
Dec 2, 2027
Risk tier:
high-risk
Scope:
Deployers that are bodies governed by public law or private entities providing public services, and any deployer of Annex III point 5(b)-(c) systems (creditworthiness assessment, life and health insurance risk assessment and pricing); Annex III point 2 (critical infrastructure) systems are excluded
upcominghigh-impact
The deployer-side counterpart to the provider's Article 9 risk management system. Deferred with the rest of the Annex III high-risk regime, but the Digital Omnibus made it materially cheaper to run: relevant parts of a GDPR or LED data protection impact assessment may be cross-referenced where they already meet particular FRIA obligations; the remaining FRIA duties still apply, and the AI Office must ship a questionnaire template.

Requirements

RequirementDetails
Pre-deployment assessmentAssess the impact on fundamental rights before putting the high-risk system into use (Article 27(1))
Process descriptionDescribe the deployer processes in which the system will be used, in line with its intended purpose (Article 27(1)(a))
Period and frequencyDescribe the period and frequency of intended use (Article 27(1)(b))
Affected personsIdentify the categories of natural persons and groups likely to be affected in the specific context (Article 27(1)(c))
Specific harmsIdentify specific risks of harm to those categories, using the provider information supplied under Article 13 (Article 27(1)(d))
Human oversightDescribe implementation of human oversight measures per the instructions for use (Article 27(1)(e))
Response measuresSet out measures if risks materialise, including internal governance arrangements and complaint mechanisms (Article 27(1)(f))
First use and updatesApplies to first use; earlier assessments (including a provider's) may be relied on in similar cases, and the assessment must be updated when elements change (Article 27(2))
Notify authorityNotify the market surveillance authority of the results with the filled-out template; deployers may be exempt from notification in Article 46(1) cases (Article 27(3))
DPIA cross-referenceWhere an obligation is already met by a GDPR Article 35 or LED Article 27 data protection impact assessment, the deployer may cross-reference the relevant sections or incorporate parts of it (Article 27(4), as replaced by Regulation (EU) 2026/1744)
AI Office templateThe AI Office must develop a questionnaire template, including an automated tool, allowing DPIA cross-references (Article 27(5), as replaced)

Penalties

ViolationFine
Article 27 non-compliance under national enforcementMember State penalties and enforcement measures under Article 99(1). Article 27 is not expressly listed in Article 99(4); there is no uniform Article 99(4) FRIA maximum established by that list. National rules determine the extent of fines on public authorities and bodies under Article 99(8)
Article 27 non-compliance within AI Office competenceArticle 75c(4)(a) extends the Article 99(4) tier to applicable provisions otherwise unlisted: up to EUR 15M or, for an undertaking, 3% of preceding financial year worldwide turnover, whichever is higher, subject to the SME/SMC lower-cap rules in Article 99(6)/(6a). This route applies only within Article 75(1): specified same-undertaking GPAI-based systems (with listed exclusions), or systems constituting or integrated into designated very large online platforms/search engines; deployers must also be the provider or belong to the same undertaking
View full regulation View obligation Obligation matrix