Skip to content
Topic Regulator-defined

AI Risk Assessment

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

The AI Act employs a risk-based regulatory approach to determine which practices are prohibited, requiring assessment and classification of AI system risks, which is distinct from general DPIA and needs dedicated coverage.

98 linked items 76 Laws2 Guidance6 News13 Literature1 Tools

Overview

12 sources · Jul 23, 2026

Legal Framework

The AI Act establishes a tiered, risk-based regulatory architecture under Recital 26, calibrating obligations to the intensity and scope of risks that AI systems generate. This approach produces three principal tiers: prohibited practices, high-risk systems subject to detailed requirements, and systems bearing transparency obligations. Risk classification is therefore the gateway determination that dictates the entire compliance burden.

Providers of high-risk AI systems carry the primary obligations under Article 16, including maintaining technical documentation, implementing quality management systems, ensuring conformity assessment, and affixing the CE marking. Article 72 supplements these ex ante duties with post-market monitoring obligations, requiring providers to actively track system performance in real-world deployment and report serious incidents.

The risk assessment framework intersects with GDPR protections where AI systems process special categories of personal data under Article 22 GDPR. The doctrinal commentary underscores that data inherently sensitive by virtue of its relationship to fundamental rights demands heightened protection, as the processing context can generate significant risks to those rights. Processing such data is presumptively prohibited unless a specific exception applies. Some exceptions — notably those under Article 22(2)(a), (c), (d), (e), and (f) GDPR — have direct effect under the Regulation and require no national implementing measure, while others demand a separate legal basis in national law. This layered structure means that AI risk assessment cannot simply rely on a single lawful ground; it must map the interplay between AI Act classification and GDPR substantive protections.

The concept of substantial effects on data subjects, relevant to cross-border processing analysis, requires case-by-case assessment rather than mechanical application based on the number of individuals affected across Member States. Where AI systems produce significant impacts on individuals — even at modest scale — the risk calculus shifts accordingly.

Key Developments

The interplay between AI Act risk classification and GDPR special-category protections remains nascent in enforcement practice, but the doctrinal emphasis on context-driven risk assessment signals that regulators will scrutinize whether AI deployers have properly evaluated the fundamental rights implications of processing sensitive data within AI systems. The recent legislative advocacy around preserving transparency safeguards in the AI Act, dated February 2026, reflects ongoing political pressure to weaken certain protective mechanisms — a development practitioners should monitor as it may alter the transparency tier's scope.

Practical Guidance

  • Classify before deploying. Conduct a formal AI Act risk classification for every system, documenting the rationale for placing it in the prohibited, high-risk, or transparency-only category. This determination drives all downstream obligations under Articles 16 and 72.

  • Map GDPR special-category intersections. Where an AI system processes data covered by Article 22 GDPR, identify the specific exception relied upon and verify whether it has direct effect or requires national implementing legislation. Do not assume a single GDPR lawful basis suffices for the AI Act's distinct risk assessment.

  • Assess substantial effects qualitatively. Evaluate whether the AI system produces significant consequences for data subjects on a contextual, case-by-case basis rather than relying on volume thresholds. Systems affecting few individuals can still trigger heightened obligations if the impact is severe.

  • Establish post-market monitoring protocols. Under Article 72, implement mechanisms to track deployed high-risk system performance, capture real-world failure modes, and report serious incidents to competent authorities within prescribed timelines.

  • Document joint controllership arrangements. Where multiple parties jointly determine purposes and means of AI processing, formalize the allocation of compliance responsibilities — including risk assessment duties — through explicit arrangements, as joint controllership extends to collaborative AI deployments.

Everything on this topic, by type links go to the exact provision / paragraph / section
Laws 76
Art. 111(2) Without prejudice to the application of Article 5 as referred to in Article 113(3), point (a), this Regulation shall apply to operators of high-risk A… AI Act Art. 112(1) The Commission shall assess the need for amendment of the list set out in Annex III and of the list of prohibited AI practices laid down in Article 5,… AI Act Art. 112(7) By 2 August 2028 and every three years thereafter, the Commission shall evaluate the impact and effectiveness of voluntary codes of conduct to foster … AI Act Art. 1(2)(c) specific requirements for high-risk AI systems and obligations for operators of such systems; AI Act rec 65 Recital 65 — high-risk AI risk management system AI Act Jun 2024 rec 26 Recital 26 — risk-based approach to AI regulation AI Act Jun 2024 rec 62 Recital 62 — high-risk classification election influencing AI AI Act Jun 2024 rec 91 Recital 91 — deployer responsibilities for high-risk AI systems AI Act Jun 2024 art 27 Fundamental rights impact assessment for high-risk AI systems AI Act Jun 2024 rec 79 Recital 79 — provider responsibility for high-risk AI systems AI Act Jun 2024 art 60 Testing of high-risk AI systems in real world conditions outside AI regulatory sandboxes AI Act Jun 2024 art 72 Post-market monitoring by providers and post-market monitoring plan for high-risk AI systems AI Act Jun 2024 rec 7 Recital 7 — common rules for high-risk AI systems AI Act Jun 2024 rec 177 Recital 177 — Transitional provisions existing high-risk AI systems AI Act Jun 2024 rec 64 Recital 64 — mandatory requirements for high-risk AI systems AI Act Jun 2024 rec 123 Recital 123 — conformity assessment for high-risk AI systems AI Act Jun 2024 rec 56 Recital 56 — high-risk AI systems in education AI Act Jun 2024 rec 52 Recital 52 — classification of standalone high-risk AI systems AI Act Jun 2024 art 22 Authorised representatives of providers of high-risk AI systems AI Act Jun 2024 rec 75 Recital 75 — technical robustness of high-risk AI systems AI Act Jun 2024 rec 125 Recital 125 — High-risk AI systems conformity assessment procedure AI Act Jun 2024 rec 129 Recital 129 — CE marking for high-risk AI systems AI Act Jun 2024 rec 72 Recital 72 — transparency requirements for high-risk AI systems AI Act Jun 2024 rec 63 Recital 63 — high-risk classification not implying lawfulness AI Act Jun 2024 Show 56 more →
Guidance 2
282024 on certain data protection aspects related to Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models EDPB Dec 2024 annual report 2021 EDPB Annual Report 2021 EDPB May 2022
News 6
Access Now A call to EU legislators: protect rights and reject the call to delete transparency safeguard in AI Act Access Now Feb 2026 European Digital Rights The AI Act isn’t enough: closing the dangerous loopholes that enable rights violations European Digital Rights Nov 2025 European Digital Rights The AI law is not sufficient: we must address the dangerous loopholes that enable abuse and violate people's rights. European Digital Rights Nov 2025 Hunton Andrews Kurth CNIL Proposes 60 Million Euros Fine Against French AdTech Company For Non-Compliance with GDPR Hunton Andrews Kurth Aug 2022 Datatilsynet Danish SA Declares Use of Google Analytics Unlawful Without Supplementary Measures Datatilsynet Sep 2022 Hunton Andrews Kurth Irish Data Protection Commissioner Fines Instagram EUR 405M for Children Privacy Violations Hunton Andrews Kurth Sep 2022
Literature 13
Athens Journal of Law Artificial Intelligence in Decision-making: A Test of Consistency between the “EU AI Act” and the “General Data Protection Regulation” Athens Journal of Law Jan 2025 Journal of AI Law and Regulation The Classification of High-Risk AI Systems Under the EU Artificial Intelligence Act Journal of AI Law and Regulation Jan 2024 Studies in Law and Justice The Path of Formulating the Basic Law of Artificial Intelligence in China — Analysis of the Desirability of the EU Artificial Intelligence Act Studies in Law and Justice Sep 2023 i-lex Perspectives for Open Source AI i-lex Jul 2026 Ethics & bioethics The ethics of regulation: Social contract insights on the 2024 European Union Artificial Intelligence Act Ethics & bioethics Jul 2026 American Journal Of Social Sciences And Humanity Research Regulating Algorithm-Based Contracts: How the Eu Artificial Intelligence Act Is Reshaping Risk Allocation in International B2b Transactions American Journal Of Social Sciences And Humanity Research Jun 2026 Law Innovation and Technology AI data governance – overlaps between the AI Act and the GDPR Law Innovation and Technology Jan 2026 Global Privacy Law Review The EU Artificial Intelligence (AI) Act: An Introduction Global Privacy Law Review Mar 2024 AI and Ethics Eu regulatory ecosystem for ethical AI AI and Ethics Jun 2025 Law and Economy Italy’s Artificial Intelligence Act and Global AI Governance: The EU Model’s Practice and Prospects Law and Economy Feb 2026 European Law Open The triple helix: markets, fundamental rights, and security in EU digital law European Law Open Jul 2026 Journal of Data Protection Privacy Is the GDPR efficient in protecting EU citizens against the privacy risks raised by social media? Journal of Data Protection Privacy Jun 2025 Journal of Ethics and Emerging Technologies The Magician’s Eye Journal of Ethics and Emerging Technologies Jul 2026
Tools 1
Future of Life Institute EU AI Act Compliance Checker Future of Life Institute Jul 2026