AI Risk Assessment
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.The AI Act employs a risk-based regulatory approach to determine which practices are prohibited, requiring assessment and classification of AI system risks, which is distinct from general DPIA and needs dedicated coverage.
Overview
15 sources · Sep 25, 2026Legal Framework
The AI Act establishes a tiered, risk-based regulatory architecture for AI systems. Recital 26 sets the foundational logic: the type and content of binding rules must be tailored to the intensity and scope of risks an AI system can generate. This produces three principal tiers — prohibited practices, high-risk systems subject to detailed obligations, and systems subject to transparency obligations only.
Classification is governed by Article 6. A system is high-risk under Article 6(1) where it serves as a safety component of a product covered by Union harmonisation legislation listed in Annex I, and that product requires third-party conformity assessment. Independently, Article 6(2) designates AI systems listed in Annex III as high-risk. Article 6(3) provides a narrow derogation: an Annex III system escapes high-risk classification where it "does not pose a significant risk of harm to the health, safety or fundamental rights of natural persons, including by not materially influencing the outcome of decision making."
"The risk-management system should consist of a continuous, iterative process that is planned and run throughout the entire lifecycle of a high-risk AI system."
— AI Act Recital 65
Once classified as high-risk, providers must satisfy the obligations in Article 16, including compliance with Section 2 requirements, maintaining a quality management system under Article 17, keeping technical documentation and logs, undergoing conformity assessment under Article 43, drawing up an EU declaration of conformity, and affixing the CE marking.
Key Developments
No case law yet tests the AI Act's risk classification or risk-management obligations. The interpretive landscape is shaped by regulatory guidance. The EDPB-EDPS Joint Opinion signals that the high-risk list is inherently non-exhaustive and that systems outside Annex III can still generate substantial harm to individuals' rights.
"the list of high-risk AI systems can never be exhaustive in referencing all possible AI systems that present substantial risks to the rights and freedoms of individuals"
— EDPB-EDPS Joint Opinion 1/2026 §13
This positions data protection authorities to scrutinise AI systems that fall below the high-risk threshold but still process special categories of personal data under GDPR Article 9. The EDPB also emphasises that registration obligations serve a proactive enforcement function, enabling national competent authorities and fundamental-rights bodies to request documentation and act before harm materialises.
Status of the Debate
This topic is regulator-defined. The AI Act's risk-classification and risk-management provisions are newly in force, with application dates staggered through 2027–2028. No court or DPA decision has yet interpreted Article 6's classification thresholds or Article 16's provider obligations. The EDPB-EDPS guidance fills part of the interpretive gap, but core questions remain open — particularly the scope of the Article 6(3) derogation and how "reasonably foreseeable misuse" should be bounded in practice. Resolution will likely come through the first wave of conformity-assessment decisions by notified bodies and, subsequently, through national competent authority enforcement actions.
Practical Guidance
- Classify before deploying. Map each AI system against Article 6(1) (Annex I safety components) and Article 6(2) (Annex III use cases) to determine high-risk status. Document the classification rationale, including any reliance on the Article 6(3) derogation.
- Implement a lifecycle risk-management system. Recital 65 requires a continuous, iterative process covering intended use and reasonably foreseeable misuse. Document mitigation choices and involve external stakeholders where relevant.
- Prepare provider obligations early. Article 16 requires quality management, technical documentation, log retention, conformity assessment, CE marking, and EU declaration of conformity — all before placing the system on the market.
- Do not assume non-high-risk means low risk. The EDPB-EDPS explicitly warns that systems outside the high-risk list can still harm individuals, particularly where special-category data is involved. Assess GDPR Article 9 implications independently.
- Track application dates. Annex III high-risk obligations apply from 2 August 2026 (or later per Commission delay); Annex I obligations from 2 August 2027. Build compliance timelines accordingly.
Nothing of this type on this topic.
This is the top of each pile — all 76 Laws