Skip to content
Topic Contested in court

Risk Management System

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

This new topic is needed because risk management systems are a distinct and mandatory requirement under the AI Act, encompassing systematic processes for identifying, assessing, mitigating, and monitoring risks throughout an AI system's lifecycle, which is not adequately covered by existing topics.

26 linked items 9 Laws3 Guidance3 Enforcement4 News7 Literature

Overview

24 sources · Jul 23, 2026

Legal Framework

The AI Act establishes a dedicated risk management system obligation for high-risk AI systems in Article 9, making it one of the core compliance pillars alongside the quality management system in Article 17. Article 9 applies exclusively to high-risk AI systems and requires providers to establish, implement, document, and maintain a structured risk management process. Article 8(1) explicitly ties compliance with all Section 2 requirements to the risk management system:

"The risk management system referred to in Article 9 shall be taken into account when ensuring compliance with those requirements."
AI Act Art. 8(1)

The system is not a one-time assessment but a continuous obligation. Article 9(2) defines it as an iterative process spanning the entire lifecycle of the AI system, covering four sequential steps: identification and analysis of known and reasonably foreseeable risks; estimation and evaluation of risks under intended use and reasonably foreseeable misuse; evaluation of emerging risks through post-market monitoring data under Article 72; and adoption of appropriate, targeted risk management measures. Critically, Article 9(3) scopes the obligation to risks that can be reasonably mitigated through development, design, or adequate technical information — not all conceivable risks.

The definition of "risk" in Article 3(2) provides the operative threshold:

Key Developments

Because the AI Act is newly in force, no court has yet interpreted Article 9's risk management requirements. However, enforcement authorities have developed a mature risk-assessment methodology under the GDPR that provides a practical template. The EDPB's breach notification guidelines demonstrate how regulators calibrate "risk" using probability and severity — the same dual-axis definition the AI Act adopts. In one illustrative ransomware scenario involving a hospital, the EDPB concluded:

"The unavailability of the data has a high impact on a substantial part of the data subjects. Moreover, there is a residual risk of high severity to the confidentiality of the patient data."
EDPB Guidelines 01/2021 §37

Dutch courts have confirmed that supervisory authorities exercise discretion in enforcement — corrective measures are a power, not a mandatory obligation for every infringement. The Rechtbank held that GDPR Article 58(2) frames corrective measures as a competence rather than a duty, meaning authorities can prioritise based on risk severity. This enforcement-discretion framework will likely carry over to AI Act supervisory authorities when assessing whether a provider's risk management system is adequate.

Status of the Debate

This topic is contested and actively emerging. The AI Act's risk management obligation is doctrinally novel — it imposes a lifecycle-wide, iterative process that blends product-safety logic with fundamental-rights protection, a combination no prior EU instrument has operationalised in exactly this way. Courts have not yet ruled on Article 9, and no enforcement decisions have tested its boundaries. The open questions are: what constitutes "reasonably foreseeable misuse" in adaptive AI systems; how post-market monitoring data feeds back into risk evaluation; and how Article 9 interacts with the quality management system under Article 17. Resolution will likely come through the first wave of conformity assessments and supervisory authority enforcement decisions, potentially reaching courts when providers challenge corrective measures.

Practical Guidance

  • Treat risk management as a lifecycle process, not a pre-market checkpoint. Article 9(2) requires regular systematic review and updating throughout the system's entire lifecycle — build feedback loops from post-market monitoring into your risk register.

  • Document all four steps separately and sequentially. Identify and analyse known risks (Art. 9(2)(a)), estimate and evaluate under intended use and foreseeable misuse (Art. 9(2)(b)), incorporate post-market data (Art. 9(2)(c)), and adopt targeted measures (Art. 9(2)(d)). Each step must produce auditable evidence.

  • Scope risks to what is reasonably mitigable. Article 9(3) limits the obligation to risks addressable through design, development, or technical information — do not over-include speculative risks that cannot be mitigated through these levers.

  • Integrate with the quality management system. Article 17 requires the QMS to cover design control, testing, and data management — align your risk management documentation with QMS procedures to avoid duplication and demonstrate coherence.

  • Use the probability-severity matrix from Article 3(2). Adopt the Act's own definition of "risk" as your internal scoring methodology, ensuring consistency between your risk assessments and the regulator's analytical framework.

Everything on this topic, by type links go to the exact provision / paragraph / section
Laws 9
Art. 3(25) ‘post-market monitoring system’ means all activities carried out by providers of AI systems to collect and review experience gained from the use of AI… AI Act Art. 8(1) High-risk AI systems shall comply with the requirements laid down in this Section, taking into account their intended purpose as well as the generally… AI Act Art. 9(1) A risk management system shall be established, implemented, documented and maintained in relation to high-risk AI systems. AI Act Art. 9(2) The risk management system shall be understood as a continuous iterative process planned and run throughout the entire lifecycle of a high-risk AI sys… AI Act rec 65 Recital 65 — high-risk AI risk management system AI Act Jun 2024 art 9 Risk management system AI Act Jun 2024 rec 179 Recital 179 — regulation phased application dates AI Act Jun 2024 rec 115 Recital 115 — systemic risk management for general-purpose AI AI Act Jun 2024 rec 155 Recital 155 — high-risk AI post-market monitoring systems AI Act Jun 2024 rec 164 Recital 164 — AI Office monitoring and enforcement powers AI Act Jun 2024 rec 81 Recital 81 — provider quality management system AI Act Jun 2024 rec 138 Recital 138 — national AI regulatory sandboxes for innovation AI Act Jun 2024 rec 163 Recital 163 — scientific panel monitoring support for AI Office AI Act Jun 2024
Guidance 3
privacy risks and mitigations in llms SPE Programma - AI Privacy Risks & Mitigations Large Language Models (LLMs) (Isabel BARBERÁ) EDPB Apr 2025 32024 on data protection authorities role in the Statement 3/2024 on data protection authorities’ role in the Artificial Intelligence Act framework EDPB Jul 2024 annual report 2022 EDPB Annual Report 2022 EDPB Apr 2023
Enforcement 3
Garante per la protezione dei dati personali (Italy) Italian DPA sanctions Lusha Systems for processing contact data without consent in B2B Garante per la protezione dei dati personali (Italy) Jul 2026 Garante per la protezione dei dati personali (Italy) Italian DPA: AgID's automatic transfer of PEC addresses to INAD index unlawful Garante per la protezione dei dati personali (Italy) May 2026 EDPS EDPS finds Commission infringed purpose limitation and data transfer rules in Microsoft EDPS Mar 2024
News 4
European Data Protection Board One-Stop-Shop case digest on right to object and right to erasure updated European Data Protection Board Jun 2026 Gaming Tech Law Is the AI Act caging ChatGPT and other General Purpose Artificial Intelligence systems? Gaming Tech Law Mar 2023 SSRN Het reguleren van de risico's van kunstmatige intelligentie. SSRN Aug 2022 NL eucrim CJEU: PNR Directive Valid if Limited to the “Strictly Necessary” eucrim Aug 2022
Literature 7
AFMN Biomedicine REGULATION OF APPLIED ARTIFICIAL INTELLIGENCE IN BIOMEDICAL ENGINEERING AS A HIGH-RISK ARTIFICIAL INTELLIGENCE SYSTEM IN THE EU AI ACT AFMN Biomedicine Jul 2026 Ethics & bioethics The ethics of regulation: Social contract insights on the 2024 European Union Artificial Intelligence Act Ethics & bioethics Jul 2026 Law and Economy Italy’s Artificial Intelligence Act and Global AI Governance: The EU Model’s Practice and Prospects Law and Economy Feb 2026 AI and Ethics Eu regulatory ecosystem for ethical AI AI and Ethics Jun 2025 International Journal of Computer Applications A Comparative Analysis of the EU AI Act and the Colorado AI Act: Regulatory Approaches to Artificial Intelligence Governance International Journal of Computer Applications Sep 2024 International Journal of Law and Information Technology Artificial intelligence co-regulation? The role of standards in the EU AI Act International Journal of Law and Information Technology Jan 2024 Studies in Law and Justice The Path of Formulating the Basic Law of Artificial Intelligence in China — Analysis of the Desirability of the EU Artificial Intelligence Act Studies in Law and Justice Sep 2023