AI Act, Article 9 (risk management system)
Regulation (EU) 2024/1689, Article 9
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force in 437 days, effective 2 December 2027.
An AI risk obligations rule binding public and private bodies.
As of 21 September 2026.
What it requires
- This duty does not yet apply. It takes effect on 2 December 2027 for a high-risk AI system classified under Article 6(2) and Annex III, and on 2 August 2028 for one classified under Article 6(1) and Annex I.
- If you are the provider of a high-risk AI system, establish, implement, document, and maintain a risk management system for it, run as a continuous process across its whole lifecycle with regular review and updates.
- Identify and analyze the known and reasonably foreseeable risks the system can pose to health, safety, or fundamental rights under its intended use, and estimate and evaluate risks that may emerge under intended use and reasonably foreseeable misuse.
- Fold in other risks surfaced by your post-market monitoring data, and adopt targeted risk management measures for the risks you identified.
- Bring residual risk, per hazard and overall, down to an acceptable level: eliminate or reduce risk through design and development where technically feasible, then mitigate or control what cannot be eliminated, then provide required information and, where appropriate, deployer training, taking the deployer's likely expertise and context of use into account.
- Test the system to confirm your risk management measures work, that the system performs consistently for its intended purpose, and that it meets the Section 2 requirements; you may use real-world testing under Article 60 for this. Test throughout development and, in any event, before placing the system on the market or putting it into service, against metrics and probabilistic thresholds set in advance.
- Consider whether the system is likely to adversely affect persons under 18 or other vulnerable groups, given its intended purpose, when implementing your risk management system.
- If you are already subject to an internal risk-management regime under other Union law, for example as a provider of a device covered by Annex I harmonisation legislation, you may combine this risk management system with your existing one rather than running two.
If you get it wrong
Private right of actionNo
What it reaches
Obligation class
Governance
Also on the record
EEA status
- Status
- Pending
- Source link
- https://www.efta.int/eea-lex/32024r1689
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Providers of a high-risk AI system must establish, implement, document and maintain a risk management system for it, run as a continuous process across the system's whole lifecycle with regular review and updating, covering the identification and analysis of known and reasonably foreseeable risks to health, safety or fundamental rights, the estimation and evaluation of risks under intended use and reasonably foreseeable misuse, the evaluation of other risks surfaced by post-market monitoring, and the adoption of targeted risk management measures for the risks identified.
Those measures must bring residual risk, per hazard and overall, to an acceptable level, first by eliminating or reducing risk through design and development where technically feasible, then by mitigating what cannot be eliminated, then by providing required information and, where appropriate, deployer training, taking the deployer's likely expertise and context of use into account.
The system must be tested throughout development and, in any event, before it is placed on the market or put into service, against pre-defined metrics and probabilistic thresholds, to confirm the measures work and the system performs consistently for its intended purpose, and testing may draw on real-world testing under Article 60.
A provider must also consider whether the system is likely to adversely affect persons under 18 or other vulnerable groups when implementing this process, and a provider already bound by an internal risk-management regime under other Union law, for example as a manufacturer of a device under Annex I harmonisation legislation, may combine this risk management system with the existing one rather than running two.
Article 9 sits in Chapter III, Section 2, so it takes effect on the schedule the Digital Omnibus on AI (Regulation (EU) 2026/1744, in force since 27 July 2026) wrote into Article 113: 2 December 2027 for a system classified as high-risk under Article 6(2) and Annex III, and 2 August 2028 for a system classified as high-risk under Article 6(1) and Annex I, rather than the Regulation's general 2 August 2026 application date.
When LexLint raises it
high_risk_decisions
Read the law
official consolidated Official Journal text, EUR-Lex
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.