Does EU AI Act require Risk Assessment?
European Union • phased enforcement
Yes — 2 provisions
Requirements at a glance
This regulation imposes 23 specific requirements for Risk Assessment across 2 provisions:
- Risk management system — Establish, implement, document, and maintain a risk management system (Article 9(1))
- Identify and analyze — Identify known and reasonably foreseeable risks to health, safety, and fundamental rights during intended use (Article 9(2)(a))
- Estimate and evaluate — Estimate and evaluate risks that may emerge under intended use and reasonably foreseeable misuse conditions (Article 9(2)(b))
- Post-market evaluation — Evaluate risks based on data from post-market monitoring (Article 9(2)(c))
- Risk mitigation — Adopt appropriate and targeted measures addressing the risks identified under Article 9(2)(a) (Article 9(2)(d))
- Risk boundary — Article 9 concerns only risks reasonably mitigated or eliminated through system development or design, or provision of adequate technical information (Article 9(3))
- Design-based reduction — Eliminate or reduce risks through adequate design and development where technically feasible (Article 9(5)(a))
- Residual risk — Ensure residual risk associated with each hazard and overall residual risk is judged acceptable (Article 9(5))
- Testing — Test to identify appropriate risk management measures and ensure consistent performance and compliance; tested against prior defined metrics and probabilistic thresholds (Article 9(6)-(8))
- Iterative review — Plan and run the risk management system as a continuous iterative process throughout the entire lifecycle, with regular systematic review and updating (Article 9(2))
- Children and vulnerable groups — When implementing the risk management system, providers must consider whether the system is likely to adversely affect persons under 18 and, as appropriate, other vulnerable groups (Article 9(9))
- Other Union-law risk processes — Providers subject to internal risk-management requirements under other Union law may include or combine Article 9(1)-(9) aspects in those procedures (Article 9(10))
- Pre-deployment assessment — Assess the impact on fundamental rights before putting the high-risk system into use (Article 27(1))
- Process description — Describe the deployer processes in which the system will be used, in line with its intended purpose (Article 27(1)(a))
- Period and frequency — Describe the period and frequency of intended use (Article 27(1)(b))
- Affected persons — Identify the categories of natural persons and groups likely to be affected in the specific context (Article 27(1)(c))
- Specific harms — Identify specific risks of harm to those categories, using the provider information supplied under Article 13 (Article 27(1)(d))
- Human oversight — Describe implementation of human oversight measures per the instructions for use (Article 27(1)(e))
- Response measures — Set out measures if risks materialise, including internal governance arrangements and complaint mechanisms (Article 27(1)(f))
- First use and updates — Applies to first use; earlier assessments (including a provider's) may be relied on in similar cases, and the assessment must be updated when elements change (Article 27(2))
- Notify authority — Notify the market surveillance authority of the results with the filled-out template; deployers may be exempt from notification in Article 46(1) cases (Article 27(3))
- DPIA cross-reference — Where an obligation is already met by a GDPR Article 35 or LED Article 27 data protection impact assessment, the deployer may cross-reference the relevant sections or incorporate parts of it (Article 27(4), as replaced by Regulation (EU) 2026/1744)
- AI Office template — The AI Office must develop a questionnaire template, including an automated tool, allowing DPIA cross-references (Article 27(5), as replaced)
Risk Management (Article 9)
Deferred with the rest of Chapter III Sections 1-3 by Regulation (EU) 2026/1744: 2027-12-02 for systems high-risk under Article 6(2) and Annex III, and 2028-08-02 for systems high-risk under Article 6(1) and Annex I. The `Effective` field carries the earlier of the two.
Requirements
| Requirement | Details |
|---|---|
| Risk management system | Establish, implement, document, and maintain a risk management system (Article 9(1)) |
| Identify and analyze | Identify known and reasonably foreseeable risks to health, safety, and fundamental rights during intended use (Article 9(2)(a)) |
| Estimate and evaluate | Estimate and evaluate risks that may emerge under intended use and reasonably foreseeable misuse conditions (Article 9(2)(b)) |
| Post-market evaluation | Evaluate risks based on data from post-market monitoring (Article 9(2)(c)) |
| Risk mitigation | Adopt appropriate and targeted measures addressing the risks identified under Article 9(2)(a) (Article 9(2)(d)) |
| Risk boundary | Article 9 concerns only risks reasonably mitigated or eliminated through system development or design, or provision of adequate technical information (Article 9(3)) |
| Design-based reduction | Eliminate or reduce risks through adequate design and development where technically feasible (Article 9(5)(a)) |
| Residual risk | Ensure residual risk associated with each hazard and overall residual risk is judged acceptable (Article 9(5)) |
| Testing | Test to identify appropriate risk management measures and ensure consistent performance and compliance; tested against prior defined metrics and probabilistic thresholds (Article 9(6)-(8)) |
| Iterative review | Plan and run the risk management system as a continuous iterative process throughout the entire lifecycle, with regular systematic review and updating (Article 9(2)) |
| Children and vulnerable groups | When implementing the risk management system, providers must consider whether the system is likely to adversely affect persons under 18 and, as appropriate, other vulnerable groups (Article 9(9)) |
| Other Union-law risk processes | Providers subject to internal risk-management requirements under other Union law may include or combine Article 9(1)-(9) aspects in those procedures (Article 9(10)) |
Penalties
| Violation | Fine |
|---|---|
| Provider non-compliance through Article 16(a) | Up to EUR 15 million; for undertakings, up to 3% of total worldwide annual turnover for the preceding financial year or EUR 15 million, whichever is higher. For SMEs (including start-ups) and SMCs, the lower of the amount or percentage applies (Article 99(4), (6), and (6a)). Applicability depends on the relevant duty and its application date. |
Fundamental Rights Impact Assessment (Article 27)
The deployer-side counterpart to the provider's Article 9 risk management system. Deferred with the rest of the Annex III high-risk regime, but the Digital Omnibus made it materially cheaper to run: relevant parts of a GDPR or LED data protection impact assessment may be cross-referenced where they already meet particular FRIA obligations; the remaining FRIA duties still apply, and the AI Office must ship a questionnaire template.
Requirements
| Requirement | Details |
|---|---|
| Pre-deployment assessment | Assess the impact on fundamental rights before putting the high-risk system into use (Article 27(1)) |
| Process description | Describe the deployer processes in which the system will be used, in line with its intended purpose (Article 27(1)(a)) |
| Period and frequency | Describe the period and frequency of intended use (Article 27(1)(b)) |
| Affected persons | Identify the categories of natural persons and groups likely to be affected in the specific context (Article 27(1)(c)) |
| Specific harms | Identify specific risks of harm to those categories, using the provider information supplied under Article 13 (Article 27(1)(d)) |
| Human oversight | Describe implementation of human oversight measures per the instructions for use (Article 27(1)(e)) |
| Response measures | Set out measures if risks materialise, including internal governance arrangements and complaint mechanisms (Article 27(1)(f)) |
| First use and updates | Applies to first use; earlier assessments (including a provider's) may be relied on in similar cases, and the assessment must be updated when elements change (Article 27(2)) |
| Notify authority | Notify the market surveillance authority of the results with the filled-out template; deployers may be exempt from notification in Article 46(1) cases (Article 27(3)) |
| DPIA cross-reference | Where an obligation is already met by a GDPR Article 35 or LED Article 27 data protection impact assessment, the deployer may cross-reference the relevant sections or incorporate parts of it (Article 27(4), as replaced by Regulation (EU) 2026/1744) |
| AI Office template | The AI Office must develop a questionnaire template, including an automated tool, allowing DPIA cross-references (Article 27(5), as replaced) |
Penalties
| Violation | Fine |
|---|---|
| Article 27 non-compliance under national enforcement | Member State penalties and enforcement measures under Article 99(1). Article 27 is not expressly listed in Article 99(4); there is no uniform Article 99(4) FRIA maximum established by that list. National rules determine the extent of fines on public authorities and bodies under Article 99(8) |
| Article 27 non-compliance within AI Office competence | Article 75c(4)(a) extends the Article 99(4) tier to applicable provisions otherwise unlisted: up to EUR 15M or, for an undertaking, 3% of preceding financial year worldwide turnover, whichever is higher, subject to the SME/SMC lower-cap rules in Article 99(6)/(6a). This route applies only within Article 75(1): specified same-undertaking GPAI-based systems (with listed exclusions), or systems constituting or integrated into designated very large online platforms/search engines; deployers must also be the provider or belong to the same undertaking |