# AI Risk Assessment — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/ai-risk-assessment
> Sources are cited per item. Verify against the official texts before relying on them.

The AI Act employs a risk-based regulatory approach to determine which practices are prohibited, requiring assessment and classification of AI system risks, which is distinct from general DPIA and needs dedicated coverage.

## Overview

## Legal Framework

The AI Act establishes a tiered, risk-based regulatory architecture under Recital 26, calibrating obligations to the intensity and scope of risks that AI systems generate. This approach produces three principal tiers: prohibited practices, high-risk systems subject to detailed requirements, and systems bearing transparency obligations. Risk classification is therefore the gateway determination that dictates the entire compliance burden.

Providers of high-risk AI systems carry the primary obligations under Article 16, including maintaining technical documentation, implementing quality management systems, ensuring conformity assessment, and affixing the CE marking. Article 72 supplements these ex ante duties with post-market monitoring obligations, requiring providers to actively track system performance in real-world deployment and report serious incidents.

The risk assessment framework intersects with GDPR protections where AI systems process special categories of personal data under Article 22 GDPR. The doctrinal commentary underscores that data inherently sensitive by virtue of its relationship to fundamental rights demands heightened protection, as the processing context can generate significant risks to those rights. Processing such data is presumptively prohibited unless a specific exception applies. Some exceptions — notably those under Article 22(2)(a), (c), (d), (e), and (f) GDPR — have direct effect under the Regulation and require no national implementing measure, while others demand a separate legal basis in national law. This layered structure means that AI risk assessment cannot simply rely on a single lawful ground; it must map the interplay between AI Act classification and GDPR substantive protections.

The concept of substantial effects on data subjects, relevant to cross-border processing analysis, requires case-by-case assessment rather than mechanical application based on the number of individuals affected across Member States. Where AI systems produce significant impacts on individuals — even at modest scale — the risk calculus shifts accordingly.

## Key Developments

The interplay between AI Act risk classification and GDPR special-category protections remains nascent in enforcement practice, but the doctrinal emphasis on context-driven risk assessment signals that regulators will scrutinize whether AI deployers have properly evaluated the fundamental rights implications of processing sensitive data within AI systems. The recent legislative advocacy around preserving transparency safeguards in the AI Act, dated February 2026, reflects ongoing political pressure to weaken certain protective mechanisms — a development practitioners should monitor as it may alter the transparency tier's scope.

## Practical Guidance

- **Classify before deploying.** Conduct a formal AI Act risk classification for every system, documenting the rationale for placing it in the prohibited, high-risk, or transparency-only category. This determination drives all downstream obligations under Articles 16 and 72.

- **Map GDPR special-category intersections.** Where an AI system processes data covered by Article 22 GDPR, identify the specific exception relied upon and verify whether it has direct effect or requires national implementing legislation. Do not assume a single GDPR lawful basis suffices for the AI Act's distinct risk assessment.

- **Assess substantial effects qualitatively.** Evaluate whether the AI system produces significant consequences for data subjects on a contextual, case-by-case basis rather than relying on volume thresholds. Systems affecting few individuals can still trigger heightened obligations if the impact is severe.

- **Establish post-market monitoring protocols.** Under Article 72, implement mechanisms to track deployed high-risk system performance, capture real-world failure modes, and report serious incidents to competent authorities within prescribed timelines.

- **Document joint controllership arrangements.** Where multiple parties jointly determine purposes and means of AI processing, formalize the allocation of compliance responsibilities — including risk assessment duties — through explicit arrangements, as joint controllership extends to collaborative AI deployments.

## Legislation (full text of key provisions)

### Fundamental rights impact assessment for high-risk AI systems

*Source: AI Act, aiact-art-27-en, 2024-06-12 — https://overview.legal/posts/92424*

### Testing of high-risk AI systems in real world conditions outside AI regulatory sandboxes

*Source: AI Act, aiact-art-60-en, 2024-06-12 — https://overview.legal/posts/92962*

### Post-market monitoring by providers and post-market monitoring plan for high-risk AI systems

*Source: AI Act, aiact-art-72-en, 2024-06-12 — https://overview.legal/posts/93175*

### Authorised representatives of providers of high-risk AI systems

*Source: AI Act, aiact-art-22-en, 2024-06-12 — https://overview.legal/posts/92312*

### EU database for high-risk AI systems listed in Annex III

*Source: AI Act, aiact-art-71-en, 2024-06-12 — https://overview.legal/posts/93161*

### Obligations of providers of high-risk AI systems

*Source: AI Act, aiact-art-16-en, 2024-06-12 — https://overview.legal/posts/92242*

Providers of high-risk AI systems shall:

### Prohibited AI practices

*Source: AI Act, aiact-art-5-en, 2024-06-12 — https://overview.legal/posts/91996*

### Classification rules for high-risk AI systems

*Source: AI Act, aiact-art-6-en, 2024-06-12 — https://overview.legal/posts/92035*

### Obligations of deployers of high-risk AI systems

*Source: AI Act, aiact-art-26-en, 2024-06-12 — https://overview.legal/posts/92382*

### Classification of general-purpose AI models as general-purpose AI models with systemic risk

*Source: AI Act, aiact-art-51-en, 2024-06-12 — https://overview.legal/posts/92764*

## Guidance

### Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models

*Source: EDPB, opinion-282024-on-certain-data-protection-aspects-related-to-en, 2024-12-18 — https://overview.legal/posts/125697 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-282024-on-certain-data-protection-aspects-related-to_en*

Adopted 1 Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models Adopted on 17 December 2024 Adopted 2 Executive summary AI technologies create many opportunities and benefits across a wide range of sectors and social activities. By protecting the fundamental right to data protection, GDPR supports these opportunities and promotes other EU fundamental rights, including the right to freedom of thought, expression and information,…

### EDPB Annual Report 2021

*Source: EDPB, edpb-annual-report-2021-en, 2022-05-12 — https://overview.legal/posts/125941 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/edpb-annual-report-2021_en*

Enhancing the depth and breadth of data protection 2 EDPB Annual Report 2021 2 ENHANCING THE DEPTH AND BREADTH OF DATA PROTECTION An Executive Summary of this report, which provides an overview of key EDPB activities in 2021, is also available. Further details about the EDPB can be found on our website at edpb.europa.eu. 3 EDPB Annual Report 2021 3 GLOSSARY 7 FOREWORD 10 2021 - HIGHLIGHTS 13 3.1. STRATEGY 2021-2023 AND WORK PROGRAMME 2021-2022 13 3.2. EDPB OPINIONS ON DRAFT UK ADEQUACY…

## Recent developments

### A call to EU legislators: protect rights and reject the call to delete transparency safeguard in AI Act

*Source: Access Now, 2026-02-10 — https://overview.legal/posts/52552 — original: https://www.accessnow.org/press-release/a-call-to-eu-legislators-protect-transparency-safeguard-in-ai-act/*

We, the undersigned organisations and individuals, urge you in the strongest possible terms to reject the deletion of the Article 49(2) transparency safeguard for high-risk AI systems that is proposed in the AI Omnibus. This transparency safeguard ensures that providers of AI systems cannot circumvent the core obligations of the AI Act.

### The AI Act isn&#8217;t enough: closing the dangerous loopholes that enable rights violations

*Source: European Digital Rights, 2025-11-13 — https://overview.legal/posts/49203 — original: https://edri.org/our-work/the-ai-act-isnt-enough-closing-the-dangerous-loopholes-that-enable-rights-violations/*

While the EU's AI Act aims to regulate high-risk AI systems, it is undermined by major loopholes that allow their unchecked use in the context of national security and law enforcement. These exemptions risk enabling, among others, mass surveillance of protests and discriminatory migration practices. To prevent this, EDRi affiliate Danes je nov dan has published recommendations for Slovenia to adopt stricter national safeguards and transparent oversight mechanisms. The post The AI Act isn&#8217;t

### The AI law is not sufficient: we must address the dangerous loopholes that enable abuse and violate people's rights.

*Source: European Digital Rights, 2025-11-13 — https://overview.legal/posts/52095*

While the EU's AI legislation aims to regulate high-risk AI systems, it is undermined by significant exceptions that allow for their uncontrolled application in the context of national security and law enforcement. These exceptions risk, among other things, enabling mass surveillance of protests and discriminatory migration practices. To prevent this, the EDRi partner Danes je nov has published recommendations for Slovenia to implement stricter national safeguards and transparent oversight mechanisms. The post "The AI legislation is not..."

### CNIL Proposes 60 Million Euros Fine Against French AdTech Company For Non-Compliance with GDPR

*Source: Hunton Andrews Kurth, 2022-08-05 — https://overview.legal/posts/6291 — original: https://www.huntonprivacyblog.com/2022/08/17/cnil-proposes-60-million-euros-fine-against-french-adtech-company-for-non-compliance-with-gdpr/#entry-12*

> The proposed fine follows complaints filed by privacy NGO ‘Privacy International’ against Criteo. […]
Under the CNIL’s sanction procedure, Criteo has the right to respond to the report, both with respect to the alleged infringements and the proposed sanction.

### Danish SA Declares Use of Google Analytics Unlawful Without Supplementary Measures

*Source: Datatilsynet, 2022-09-21 — https://overview.legal/posts/6276 — original: https://www.datatilsynet.dk/english/google-analytics/use-of-google-analytics-for-web-analytics#entry-800*

The Danish Data Protection Agency has looked into the tool Google Analytics and its settings, and the terms under which the tool is provided. On the basis of this review, the Danish Data Protection Agency concludes that the tool cannot, without more, be used lawfully. Lawful use requires the implementation of supplementary measures in addition to the settings provided by Google.

## Literature

### Artificial Intelligence in Decision-making: A Test of Consistency between the “EU AI Act” and the “General Data Protection Regulation”

*Source: Athens Journal of Law, 2025-01-02 — https://overview.legal/posts/132443 — original: https://doi.org/10.30958/ajl.11-1-3*

The recent Regulation that sets down harmonised rules on Artificial Intelligence in the European Union, known as the "AI Act," includes a significant requirement for human oversight in high-risk AI systems during their use (art. 14). This requirement embodies the "human-in-command" approach, ensuring both legal and ethical compliance. The AI Act is intended to complement the General Data Protection Regulation (hereinafter GDPR), thereby forming a consistent and comprehensive legal framework. Thi

### The Classification of High-Risk AI Systems Under the EU Artificial Intelligence Act

*Source: Journal of AI Law and Regulation, 2024-01-01 — https://overview.legal/posts/132436 — original: https://doi.org/10.21552/aire/2024/3/4*

### The Path of Formulating the Basic Law of Artificial Intelligence in China — Analysis of the Desirability of the EU Artificial Intelligence Act

*Source: Studies in Law and Justice, 2023-09-01 — https://overview.legal/posts/132567 — original: https://doi.org/10.56397/slj.2023.09.09*

The European Commission released the proposed Regulation on Artificial Intelligence (the EU AI Act) on 21 April 2021, which reflects the EU’s leadership orientation in establishing norms and standards in emerging fields, and also reflects the urgent need for legal unity of the EU as a unified market entity. The Act sets out harmonized rules for the development, placing on the market, and use of AI in the European Union. The ideas of a risk-based approach and experimental governance are of great

### Perspectives for Open Source AI

*Source: i-lex, 2026-07-07 — https://overview.legal/posts/83512 — original: https://doi.org/10.60923/issn.1825-1927/23382*

The world’s first most comprehensive law regulating artificial intelligence, the EU Artificial Intelligence Act, has been enacted in June 2024 and entered into force in August 2024. The AI Act aims to provide transparency and ensure safe use of AI systems by introducing obligations and requirements for developers and deployers based on the risk posed by AI systems. Despite the long legislation process that launched in 2020 and multiple negotiations, the final version of the Act includes a number

### The ethics of regulation: Social contract insights on the 2024 European Union Artificial Intelligence Act

*Source: Ethics & bioethics, 2026-07-06 — https://overview.legal/posts/83515 — original: https://doi.org/10.2478/ebce-2026-0014*

Abstract The paper provides a critical analysis of the EU AI Act (Regulation 2024/1689) within the broader context of contemporary AI developments. Starting from an historical overview on the development of advanced AI systems, it moves the focus onto the intrinsic meaning of Artificial Intelligence to highlight how, despite such fascinating wording, there cannot be a shift of responsibility onto the systems themselves—as was proposed, for example, by the European Parliament resolution of 16 Feb

## Tools

### EU AI Act Compliance Checker

*Source: Future of Life Institute, 2026-07-17 — https://overview.legal/posts/125619 — original: https://artificialintelligenceact.eu/assessment/eu-ai-act-compliance-checker/*

Interactive self-assessment that walks providers, deployers and importers through the AI Act's scoping questions: whether a system is in scope, its risk classification (prohibited / high-risk / limited / minimal), and which obligations and deadlines follow from that classification.

## Related topics

- **High-Risk AI Classification** — https://overview.legal/topics/high-risk-ai-classification
  The content specifically addresses classification rules for high-risk AI systems under the AI Act, which is a distinct regulatory concept requiring its own dedi
- **Annex III Amendments** — https://overview.legal/topics/annex-iii-amendments
  This new topic is needed because amendments to Annex III represent specific regulatory changes to the AI Act's classification framework that warrant dedicated t
- **AI Value Chain Actors and Roles** — https://overview.legal/topics/ai-value-chain-actors
  The content focuses on responsibilities distributed across different actors in the AI value chain. A dedicated topic for understanding the various actors, their
- **Artificial Intelligence** — https://overview.legal/topics/ai
  AI systems and their implications for data protection
- **Provider Obligations for AI Systems** — https://overview.legal/topics/provider-obligations-ai
  The content specifically addresses obligations imposed on providers of high-risk AI systems, which is a distinct and important category of requirements that des
- **Monitoring** — https://overview.legal/topics/monitoring
  Systematic observation and tracking of individuals

---
Generated by overview.legal · https://overview.legal/topics/ai-risk-assessment · 2026-08-22
