# Risk management system — AI Act — context bundle

> Focused context for a single provision, curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/laws/ai-act/art-9
> Every item cites its source. Verify against the official text (EUR-Lex / wetten.overheid.nl) before relying on it.

## Provision

### Risk management system — Risk management system

*AI Act, aiact-art-9-en — https://overview.legal/laws/ai-act/art-9*

1. A risk management system shall be established, implemented, documented and maintained in relation to high-risk AI systems.

2. The risk management system shall be understood as a continuous iterative process planned and run throughout the entire lifecycle of a high-risk AI system, requiring regular systematic review and updating. It shall comprise the following steps:
   a) the identification and analysis of the known and the reasonably foreseeable risks that the high-risk AI system can pose to health, safety or fundamental rights when the high-risk AI system is used in accordance with its intended purpose;
   b) the estimation and evaluation of the risks that may emerge when the high-risk AI system is used in accordance with its intended purpose, and under conditions of reasonably foreseeable misuse;
   c) the evaluation of other risks possibly arising, based on the analysis of data gathered from the post-market monitoring system referred to in Article 72;
   d) the adoption of appropriate and targeted risk management measures designed to address the risks identified pursuant to point (a).

3. The risks referred to in this Article shall concern only those which may be reasonably mitigated or eliminated through the development or design of the high-risk AI system, or the provision of adequate technical information.

4. The risk management measures referred to in paragraph 2, point (d), shall give due consideration to the effects and possible interaction resulting from the combined application of the requirements set out in this Section, with a view to minimising risks more effectively while achieving an appropriate balance in implementing the measures to fulfil those requirements.

5. The risk management measures referred to in paragraph 2, point (d), shall be such that the relevant residual risk associated with each hazard, as well as the overall residual risk of the high-risk AI systems is judged to be acceptable.
   a) elimination or reduction of risks identified and evaluated pursuant to paragraph 2 in as far as technically feasible through adequate design and development of the high-risk AI system;
   b) where appropriate, implementation of adequate mitigation and control measures addressing risks that cannot be eliminated;
   c) provision of information required pursuant to Article 13 and, where appropriate, training to deployers.
   - In identifying the most appropriate risk management measures, the following shall be ensured:
   - With a view to eliminating or reducing risks related to the use of the high-risk AI system, due consideration shall be given to the technical knowledge, experience, education, the training to be expected by the deployer, and the presumable context in which the system is intended to be used.

6. High-risk AI systems shall be tested for the purpose of identifying the most appropriate and targeted risk management measures. Testing shall ensure that high-risk AI systems perform consistently for their intended purpose and that they are in compliance with the requirements set out in this Section.

7. Testing procedures may include testing in real-world conditions in accordance with Article 60.

8. The testing of high-risk AI systems shall be performed, as appropriate, at any time throughout the development process, and, in any event, prior to their being placed on the market or put into service. Testing shall be carried out against prior defined metrics and probabilistic thresholds that are appropriate to the intended purpose of the high-risk AI system.

9. When implementing the risk management system as provided for in paragraphs 1 to 7, providers shall give consideration to whether in view of its intended purpose the high-risk AI system is likely to have an adverse impact on persons under the age of 18 and, as appropriate, other vulnerable groups.

10. For providers of high-risk AI systems that are subject to requirements regarding internal risk management processes under other relevant provisions of Union law, the aspects provided in paragraphs 1 to 9 may be part of, or combined with, the risk management procedures established pursuant to that law.

## Related recitals

### Recital 39 — biometric data processing compliance requirements

Any processing of biometric data and other personal data involved in the use of AI systems for biometric identification, other than in connection to the use of real-time remote biometric identification systems in publicly accessible spaces for the purpose of law enforcement as regulated by this Regulation, should continue to comply with all requirements resulting from Article 10 of Directive (EU) 2016/680. For purposes other than law enforcement, Article 9(1) of Regulation (EU) 2016/679 and Article 10(1) of Regulation (EU) 2018/1725 prohibit the processing of biometric data subject to limited exceptions as provided in those Articles. In the application of Article 9(1) of Regulation (EU) 2016/679, the use of remote biometric identification for purposes other than law enforcement has already been subject to prohibition decisions by national data protection authorities.

### Recital 54 — high-risk biometric AI classification

As biometric data constitutes a special category of personal data, it is appropriate to classify as high-risk several critical-use cases of biometric systems, insofar as their use is permitted under relevant Union and national law. Technical inaccuracies of AI systems intended for the remote biometric identification of natural persons can lead to biased results and entail discriminatory effects. The risk of such biased results and discriminatory effects is particularly relevant with regard to age, ethnicity, race, sex or disabilities. Remote biometric identification systems should therefore be classified as high-risk in view of the risks that they pose. Such a classification excludes AI systems intended to be used for biometric verification, including authentication, the sole purpose of which is to confirm that a specific natural person is who that person claims to be and to confirm the identity of a natural person for the sole purpose of having access to a service, unlocking a device or having secure access to premises. In addition, AI systems intended to be used for biometric categorisation according to sensitive attributes or characteristics protected under Article 9(1) of Regulation (EU) 2016/679 on the basis of biometric data, in so far as these are not prohibited under this Regulation, and emotion recognition systems that are not prohibited under this Regulation, should be classified as high-risk. Biometric systems which are intended to be used solely for the purpose of enabling cybersecurity and personal data protection measures should not be considered to be high-risk AI systems.

### Recital 70 — bias detection special data processing

In order to protect the right of others from the discrimination that might result from the bias in AI systems, the providers should, exceptionally, to the extent that it is strictly necessary for the purpose of ensuring bias detection and correction in relation to the high-risk AI systems, subject to appropriate safeguards for the fundamental rights and freedoms of natural persons and following the application of all applicable conditions laid down under this Regulation in addition to the conditions laid down in Regulations (EU) 2016/679 and (EU) 2018/1725 and Directive (EU) 2016/680, be able to process also special categories of personal data, as a matter of substantial public interest within the meaning of Article 9(2), point (g) of Regulation (EU) 2016/679 and Article 10(2), point (g) of Regulation (EU) 2018/1725.

### Recital 140 — AI sandbox personal data reuse

This Regulation should provide the legal basis for the providers and prospective providers in the AI regulatory sandbox to use personal data collected for other purposes for developing certain AI systems in the public interest within the AI regulatory sandbox, only under specified conditions, in accordance with Article 6(4) and Article 9(2), point (g), of Regulation (EU) 2016/679, and Articles 5, 6 and 10 of Regulation (EU) 2018/1725, and without prejudice to Article 4(2) and Article 10 of Directive (EU) 2016/680. All other obligations of data controllers and rights of data subjects under Regulations (EU) 2016/679 and (EU) 2018/1725 and Directive (EU) 2016/680 remain applicable. In particular, this Regulation should not provide a legal basis in the meaning of Article 22(2), point (b) of Regulation (EU) 2016/679 and Article 24(2), point (b) of Regulation (EU) 2018/1725. Providers and prospective providers in the AI regulatory sandbox should ensure appropriate safeguards and cooperate with the competent authorities, including by following their guidance and acting expeditiously and in good faith to adequately mitigate any identified significant risks to safety, health, and fundamental rights that may arise during the development, testing and experimentation in that sandbox.

### Recital 160 — joint market surveillance and investigation activities

The market surveillance authorities and the Commission should be able to propose joint activities, including joint investigations, to be conducted by market surveillance authorities or market surveillance authorities jointly with the Commission, that have the aim of promoting compliance, identifying non-compliance, raising awareness and providing guidance in relation to this Regulation with respect to specific categories of high-risk AI systems that are found to present a serious risk across two or more Member States. Joint activities to promote compliance should be carried out in accordance with Article 9 of Regulation (EU) 2019/1020. The AI Office should provide coordination support for joint investigations.

## Guidance

### EDPB-EDPS Joint opinion 1/2026 on the Proposal for a Regulation as regards the simplification of the implementation of harmonised rules on artificial intelligence

*EDPB — https://overview.legal/posts/53738*

EDPB, EDPB-EDPS Joint opinion 1/2026 on the Proposal for a Regulation as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI)

### SPE Programma - AI Privacy Risks & Mitigations Large Language Models (LLMs) (Isabel BARBERÁ)

*EDPB — https://overview.legal/posts/50754*

"The AI Privacy Risks & Mitigations Large Language Models (LLMs) report puts forward a comprehensive risk management methodology for LLM systems with a number of practical mitigation measures for common privacy risks in LLM systems. In addition, the report provides use cases examples on the appli...

### Statement 3/2024 on data protection authorities’ role in the Artificial Intelligence Act framework

*EDPB — https://overview.legal/posts/125732*

Final 1 Statement 3/2024 on data protection authorities’ role in the Artificial Intelligence Act framework Adopted on 16 July 2024 The European Data Protection Board has adopted the following statement: 1 BACKGROUND AND PURPO SE OF THIS STATEMENT 1. On 12 July 2024, Regulation (EU) 2024/1689 laying down harmonised rules on a rtificial i ntelligence (Artificial Intelligence Act, hereinafter the “ AI Act ”) and amending certain Union Legislative Acts was published in the Official Journal 1 . 2.…

### EDPB Annual Report 2022

*EDPB — https://overview.legal/posts/125861*

EDPB Annual Report 2022 1 2022 ANNUAL REPORT STREAMLINING ENFORCEMENT THROUGH COOPERATION An Executive Summary of this report, which provides an overview of key EDPB activities in 2022, is also available. Further details about the EDPB can be found on our website at edpb.europa.eu. 1 GLOSSARY 4 2 FOREWORD 7 3 2022 – HIGHLIGHTS 9 3.1. ENFORCEMENT COOPERATION 9 3.1.1. Vienna statement on enforcement cooperation 10 3.1.2. Guidelines 02/2022 on the application of Art. 60 GDPR 10 3.1.3. Guidelines…

### EDPB-EDPS Joint Opinion 5/2021 on the proposal for a Regulation of the European Parliament and of the Council laying down harmonised rules on artificial intelligence (Artificial Intelligence Act)

*EDPB — https://overview.legal/posts/126016*

1 Adopted EDPB - EDPS Joint Opinion 5 /2021 on the proposal for a Regulation of the European Parliament and of the Council laying down harmo nised rules on artificial i ntelligence (Artificial Intelligence Act) 18 June 2021 2 Adopted Executive Summary On 2 1 April 2021, the European Commission presented its Proposal for a Regulation of the European Parliament and of the Council laying down harmonised rules on artificial intelligence (hereinafter “the Proposal”) . The EDPB and the EDPS welcome…

## Related topics

- **Provider Obligations for AI Systems** — https://overview.legal/topics/provider-obligations-ai
  ## Legal Framework
- **AI Act Requirements** — https://overview.legal/topics/ai-act-requirements
  ## Legal Framework
- **Risk Management System** — https://overview.legal/topics/risk-management-system
  ## Legal Framework

---
Generated by overview.legal · https://overview.legal/laws/ai-act/art-9 · 2026-08-22
