Skip to content
Topic Contested in court

AI Risk Mitigation

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

Risk management systems include specific measures to mitigate identified risks. This concept deserves dedicated coverage as it encompasses the practical implementation of risk reduction strategies beyond general risk assessment.

24 linked items 5 Laws2 Guidance2 Enforcement9 News6 Literature

Overview

14 sources · Sep 25, 2026

Legal Framework

AI risk mitigation is governed primarily by Article 9 of the AI Act, which mandates a risk management system for high-risk AI systems, and Article 8, which ties compliance with all Section requirements to that system. Together, these provisions establish a structured, lifecycle obligation: providers must not merely identify risks but actively adopt measures to reduce them.

Article 9(1) requires that a risk management system be "established, implemented, documented and maintained in relation to high-risk AI systems." The system is not a one-time assessment but a continuous process. Article 9(2) sets out four sequential steps — risk identification, risk estimation and evaluation, evaluation of emerging risks from post-market monitoring, and critically, "the adoption of appropriate and targeted risk management measures designed to address the risks identified."

The scope of mitigable risk is bounded by Article 9(3):

"The risks referred to in this Article shall concern only those which may be reasonably mitigated or eliminated through the development or design of the high-risk AI system, or the provision of adequate technical information."
— AI Act Art. 9(3)

Recital 65 elaborates the rationale: the system must address risks "in light of their intended purpose and reasonably foreseeable misuse, including the possible risks arising from the interaction between the AI system and the environment within which it operates." Providers must select the most appropriate measures given the state of the art in AI, document their choices, and where relevant, involve external experts and stakeholders.

Key Developments

No binding case law yet directly applies Article 9's risk mitigation requirements — the AI Act's high-risk provisions are still transitioning into full applicability. However, regulatory guidance is already shaping practical expectations. The EDPB's 2025 Annual Report highlights that AI privacy risk management is a priority area, noting the publication of a dedicated LLM risk methodology:

"The AI Privacy Risks & Mitigations Large Language Models (LLMs) report puts forward a comprehensive risk management methodology and practical mitigation measures for common privacy risks in LLM systems."
— EDPB Annual Report 2025 §67

This report provides three concrete use cases — a customer-service chatbot, a student-progress monitoring system, and a travel assistant — demonstrating how risk mitigation frameworks should be operationalized in real deployments. Enforcement actions by national DPAs, including Italy's Garante, signal that regulators expect demonstrable mitigation measures even before full AI Act enforcement, particularly where data protection violations intersect with AI deployment.

Status of the Debate

This topic is an emerging debate. The legal text is clear in structure — Article 9 imposes concrete, sequential obligations — but the practical thresholds for what constitutes "appropriate and targeted" mitigation measures remain undefined by courts. No judicial interpretation of Article 9 has yet been rendered, and DPA enforcement has focused on data protection law rather than the AI Act's risk management provisions specifically. The doctrinal debate is driven by scholarship and regulatory guidance that anticipates how Article 9 will be applied once high-risk AI system obligations become fully enforceable. What would resolve the open questions is either an enforcement decision by a market surveillance authority under the AI Act, or preliminary rulings clarifying the standard of proof for "adequate" mitigation and the boundary between mitigable and non-mitigable risks under Article 9(3).

Practical Guidance

  • Implement a documented, iterative risk cycle: Article 9(2) requires four sequential steps — identification, estimation, post-market evaluation, and mitigation. Maintain living documentation of each cycle, including decisions to accept residual risk and the rationale behind chosen measures.

  • Address reasonably foreseeable misuse, not just intended use: Recital 65 explicitly extends the mitigation duty to uses "not directly covered by the intended purpose" but predictable from human behaviour. Map misuse scenarios and design countermeasures (e.g., access controls, output filtering, usage monitoring).

  • Select measures proportionate to the state of the art: Article 9 requires adopting the "most appropriate risk-management measures in light of the state of the art in AI." Benchmark mitigation choices against current technical standards and be prepared to justify why alternatives were rejected.

  • Integrate post-market monitoring into risk mitigation: Article 9(2)(c) ties risk evaluation to data gathered under the Article 72 post-market monitoring system. Feed real-world performance data back into the risk cycle and update mitigation measures when new risks surface.

  • Involve external experts and stakeholders: Recital 65 encourages this "when relevant." For high-risk systems affecting fundamental rights, document expert consultations as evidence of diligence in selecting mitigation strategies.

Everything on this topic ranked by relevance · links go to the exact provision / paragraph / section
Is the AI Act caging ChatGPT and other General Purpose Artificial Intelligence systems? > The growth of generative artificial intelligence systems has led EU lawmakers to focus on General Purpose AI in drafting the AI Act, which will set the framework governing… News Gaming Tech Law Mar 2023 Mitigation measures
why this is here
implementing relative mitigation measures

The document mentions mitigation measures as part of data governance, but does not detail risk mitigation strategies.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026