AI Risk Assessment
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.The AI Act employs a risk-based regulatory approach to determine which practices are prohibited, requiring assessment and classification of AI system risks, which is distinct from general DPIA and needs dedicated coverage.
Overview
12 sources · Jul 23, 2026Legal Framework
The AI Act establishes a tiered, risk-based regulatory architecture under Recital 26, calibrating obligations to the intensity and scope of risks that AI systems generate. This approach produces three principal tiers: prohibited practices, high-risk systems subject to detailed requirements, and systems bearing transparency obligations. Risk classification is therefore the gateway determination that dictates the entire compliance burden.
Providers of high-risk AI systems carry the primary obligations under Article 16, including maintaining technical documentation, implementing quality management systems, ensuring conformity assessment, and affixing the CE marking. Article 72 supplements these ex ante duties with post-market monitoring obligations, requiring providers to actively track system performance in real-world deployment and report serious incidents.
The risk assessment framework intersects with GDPR protections where AI systems process special categories of personal data under Article 22 GDPR. The doctrinal commentary underscores that data inherently sensitive by virtue of its relationship to fundamental rights demands heightened protection, as the processing context can generate significant risks to those rights. Processing such data is presumptively prohibited unless a specific exception applies. Some exceptions — notably those under Article 22(2)(a), (c), (d), (e), and (f) GDPR — have direct effect under the Regulation and require no national implementing measure, while others demand a separate legal basis in national law. This layered structure means that AI risk assessment cannot simply rely on a single lawful ground; it must map the interplay between AI Act classification and GDPR substantive protections.
The concept of substantial effects on data subjects, relevant to cross-border processing analysis, requires case-by-case assessment rather than mechanical application based on the number of individuals affected across Member States. Where AI systems produce significant impacts on individuals — even at modest scale — the risk calculus shifts accordingly.
Key Developments
The interplay between AI Act risk classification and GDPR special-category protections remains nascent in enforcement practice, but the doctrinal emphasis on context-driven risk assessment signals that regulators will scrutinize whether AI deployers have properly evaluated the fundamental rights implications of processing sensitive data within AI systems. The recent legislative advocacy around preserving transparency safeguards in the AI Act, dated February 2026, reflects ongoing political pressure to weaken certain protective mechanisms — a development practitioners should monitor as it may alter the transparency tier's scope.
Practical Guidance
Classify before deploying. Conduct a formal AI Act risk classification for every system, documenting the rationale for placing it in the prohibited, high-risk, or transparency-only category. This determination drives all downstream obligations under Articles 16 and 72.
Map GDPR special-category intersections. Where an AI system processes data covered by Article 22 GDPR, identify the specific exception relied upon and verify whether it has direct effect or requires national implementing legislation. Do not assume a single GDPR lawful basis suffices for the AI Act's distinct risk assessment.
Assess substantial effects qualitatively. Evaluate whether the AI system produces significant consequences for data subjects on a contextual, case-by-case basis rather than relying on volume thresholds. Systems affecting few individuals can still trigger heightened obligations if the impact is severe.
Establish post-market monitoring protocols. Under Article 72, implement mechanisms to track deployed high-risk system performance, capture real-world failure modes, and report serious incidents to competent authorities within prescribed timelines.
Document joint controllership arrangements. Where multiple parties jointly determine purposes and means of AI processing, formalize the allocation of compliance responsibilities — including risk assessment duties — through explicit arrangements, as joint controllership extends to collaborative AI deployments.