Does Law on Artificial Intelligence require Risk Assessment?
Kazakhstan • enforcing
Yes — 1 provision
Requirements at a glance
This regulation imposes 7 specific requirements for Risk Assessment across 1 provision:
- Risk classification — Owners and holders classify their systems as minimum, medium, or high risk under the digital-object classification rules, using the Article 17(1) consequences of malfunction or cessation
- Lifecycle risk management — Owners and holders must identify and analyse known and foreseeable risks, evaluate intended and foreseeable misuse, adopt targeted measures, and update risks at least annually
- Prohibited-function risk response — If risks of an Article 17(3) prohibited circumstance are identified, owners and holders must take immediate prevention and harm-minimisation measures, including suspension or complete cessation where appropriate
- Documentation — Owners and holders must maintain system documentation according to the system's degree of impact and the documentation list approved by the authorised body
- Trusted-list audit — Owners or holders seeking inclusion in a trusted high-risk systems list must conduct an AI-system audit
- Audit framework — Article 20 applies the digital-system audit rules and additionally assesses training-data-library quality and lawfulness and the presence of prohibited functionality
- National platform boundary — Article 25 establishes a controlled environment and delegates platform-service interaction rules; it does not impose universal high-risk platform use
Risk-Based Classification and Management
Owners and holders classify AI systems as minimum, medium, or high risk and perform lifecycle risk management. Article 19(2) requires an audit when an owner or holder seeks inclusion in an industry authority's trusted high-risk list; Article 20 specifies the audit framework and added assessment topics. Article 25 describes the National AI Platform as a controlled environment for platform software products and models, but does not require every high-risk system to be developed or tested there.
Penalties qualification: Article 30 states that violations incur liability established by the laws of Kazakhstan. The AI Act itself does not set a 15–200 MCI fine range.
Requirements
| Requirement | Details |
|---|---|
| Risk classification | Owners and holders classify their systems as minimum, medium, or high risk under the digital-object classification rules, using the Article 17(1) consequences of malfunction or cessation |
| Lifecycle risk management | Owners and holders must identify and analyse known and foreseeable risks, evaluate intended and foreseeable misuse, adopt targeted measures, and update risks at least annually |
| Prohibited-function risk response | If risks of an Article 17(3) prohibited circumstance are identified, owners and holders must take immediate prevention and harm-minimisation measures, including suspension or complete cessation where appropriate |
| Documentation | Owners and holders must maintain system documentation according to the system's degree of impact and the documentation list approved by the authorised body |
| Trusted-list audit | Owners or holders seeking inclusion in a trusted high-risk systems list must conduct an AI-system audit |
| Audit framework | Article 20 applies the digital-system audit rules and additionally assesses training-data-library quality and lawfulness and the presence of prohibited functionality |
| National platform boundary | Article 25 establishes a controlled environment and delegates platform-service interaction rules; it does not impose universal high-risk platform use |