Home / The Act / Chapter III / Article 9

Article 9 — Risk management system

APPLIES DEC 2, 2027 WAS 2026-08-02 AMENDED BY OMNIBUS
Chapter III · High-risk tier
Source: EUR-Lex · CELEX 32024R1689
Verified 2026-07-16
PLAIN-LANGUAGE SUMMARY — ORIGINAL INTERPRETATION, NOT THE OFFICIAL TEXT

Providers of high-risk AI systems must run a documented risk management process across the whole lifecycle. It identifies foreseeable risks to health, safety and fundamental rights, evaluates them under intended use and foreseeable misuse, draws on post-market monitoring, and applies mitigations until residual risk is judged acceptable. Testing supports this, and extra care is owed where minors or other vulnerable groups may be affected. Providers already bound by comparable risk rules in Union law may combine the two processes.

AMENDED BY THE DIGITAL OMNIBUS ON AI

This provision's application date moved under the Omnibus. It now applies from 2027-12-02 (originally 2026-08-02). Source: Omnibus final text (OJ pending) · verified 2026-07-16

OFFICIAL TEXT Read verbatim on EUR-Lex ↗
The authoritative wording lives on EUR-Lex, quoted there in all 24 languages. We deep-link to the paragraph level rather than reproducing the full text. The consolidated post-Omnibus version will be linked the day its CELEX publishes.
AT A GLANCE
Chapter: III — High-risk AI systems
Applies: Dec 2, 2027
Tier: High-risk tier
RELATED
Related obligations →Risk categories →Standards →
PENALTY EXPOSURE
€15M or 3%
of worldwide turnover — see Art. 99 penalties framework.
← PREVIOUS · ART. 8 Compliance with the requirements NEXT · ART. 10 → Data and data governance
ELSEWHERE IN CHAPTER III — High-risk AI systems
Art. 6 Classification rules for high-risk AI systems Art. 7 Amendments to Annex III Art. 8 Compliance with the requirements Art. 10 Data and data governance Art. 11 Technical documentation Art. 12 Record-keeping Art. 13 Transparency and provision of information to d Art. 14 Human oversight