Article 9 — Risk management system
APPLIES DEC 2, 2027 WAS 2026-08-02 AMENDED BY OMNIBUS
Chapter III · High-risk tier
Source: EUR-Lex · CELEX 32024R1689
Verified 2026-07-16
Source: EUR-Lex · CELEX 32024R1689
Verified 2026-07-16
PLAIN-LANGUAGE SUMMARY — ORIGINAL INTERPRETATION, NOT THE OFFICIAL TEXT
Providers of high-risk AI systems must run a documented risk management process across the whole lifecycle. It identifies foreseeable risks to health, safety and fundamental rights, evaluates them under intended use and foreseeable misuse, draws on post-market monitoring, and applies mitigations until residual risk is judged acceptable. Testing supports this, and extra care is owed where minors or other vulnerable groups may be affected. Providers already bound by comparable risk rules in Union law may combine the two processes.
AMENDED BY THE DIGITAL OMNIBUS ON AI
This provision's application date moved under the Omnibus. It now applies from 2027-12-02 (originally 2026-08-02). Source: Omnibus final text (OJ pending) · verified 2026-07-16
AT A GLANCE
Chapter: III — High-risk AI systems
Applies: Dec 2, 2027
Tier: High-risk tier
PENALTY EXPOSURE
€15M or 3%
of worldwide turnover — see Art. 99 penalties framework.
ELSEWHERE IN CHAPTER III — High-risk AI systems