Applies 2 Dec 2027

EU AI Act Article 9: Risk management system

Article 9 of the EU AI Act requires a documented, lifecycle-long risk management system for high-risk AI systems, not a one-time assessment. The system must identify foreseeable risks to health, safety, and fundamental rights. It must evaluate them under intended use and reasonably foreseeable misuse, adopt targeted mitigation measures, and produce testing evidence sufficient to defend the residual-risk judgement.

Who
Providers of high-risk AI systems (Annex III): hiring, credit scoring, biometrics, essential services.
From when
2 Dec 2027 (Annex III), 2 Aug 2028 (Annex I)
Art. 113(c)(i), as amended
Maximum fine
€15M or 3%
Art. 99(4), point (a), through the provider obligations in Art. 16

Quoted from EUR-Lex

What Article 9 says

9(1)

1. A risk management system shall be established, implemented, documented and maintained in relation to high-risk AI systems.

9(2)

2. The risk management system shall be understood as a continuous iterative process planned and run throughout the entire lifecycle of a high-risk AI system, requiring regular systematic review and updating. It shall comprise the following steps:

9(2)(a)

(a) the identification and analysis of the known and the reasonably foreseeable risks that the high-risk AI system can pose to health, safety or fundamental rights when the high-risk AI system is used in accordance with its intended purpose;

9(2)(b)

(b) the estimation and evaluation of the risks that may emerge when the high-risk AI system is used in accordance with its intended purpose, and under conditions of reasonably foreseeable misuse;

9(2)(d)

(d) the adoption of appropriate and targeted risk management measures designed to address the risks identified pursuant to point (a).

9(6)

6. High-risk AI systems shall be tested for the purpose of identifying the most appropriate and targeted risk management measures. Testing shall ensure that high-risk AI systems perform consistently for their intended purpose and that they are in compliance with the requirements set out in this Section.

Selected paragraphs, quoted exactly. Read the whole article in Regulation (EU) 2024/1689 on EUR-Lex. Checked 4 Oct 2026.

Regulation (EU) 2026/1744 · in force 27 Jul 2026

What changed

Change in lawArticle 113, third paragraph, point (c)
It shall apply from 2 August 2026.
Removed: (c) Article 6(1) and the corresponding obligations in this Regulation shall apply from 2 August 2027.Added: (c) Chapter III, Sections 1, 2, and 3, with the exception of Article 6(5), shall apply from:Added: (i) 2 December 2027 as regards AI systems classified as high-risk pursuant to Article 6(2) and Annex III; andAdded: (ii) 2 August 2028 as regards AI systems classified as high-risk pursuant to Article 6(1) and Annex I;

The context line is the second paragraph of Article 113, which set the date for Annex III systems before the change. Removed and context lines quote Regulation (EU) 2024/1689 as adopted; added lines quote the amending Regulation.

Source: Regulation (EU) 2026/1744, Article 1, point (40), verified 4 Oct 2026

In plain words

What you must produce

A risk management system, documented and kept up to date for the whole lifecycle of the system.

  • 9(2)(a)Identification and analysis of the known and reasonably foreseeable risks
  • 9(2)(b)Estimation and evaluation of risks under intended use and reasonably foreseeable misuse
  • 9(2)(d)The risk management measures adopted for the risks identified
  • 9(6)Testing that shows the system performs consistently for its intended purpose

A summary to help you plan. The quoted text above is the law.

Coverage: Covered

RiskForge

RiskForge produces an audit-trailed Risk Management File suitable for inclusion in your Annex IV technical documentation pack in roughly 30 minutes. Eight risk dimensions, 37 guided questions, SHA-256 hash-chained tamper-evident audit log, NIST AI RMF and ISO/IEC 42001 cross-mapping. RiskForge is a screening + documentation artefact, not a substitute for notified-body conformity assessment.

Install

bashpip install riskforge

Writes: Risk Management File (JSON / PDF)

Risk Management File, first page, sample output

From the fact register

Questions about Article 9

When does Article 9 apply?
It applies from 2 Dec 2027 for high-risk systems listed in Annex III (Art. 113(c)(i), as amended), and from 2 Aug 2028 for high-risk systems covered by Annex I (Art. 113(c)(ii), as amended). Before Regulation (EU) 2026/1744, the dates were 2 Aug 2026 and 2 Aug 2027.
What is the maximum fine for breaching Article 9?
Up to €15 million or 3% of total worldwide annual turnover for the preceding financial year, whichever is higher (Art. 99(4), point (a), through the provider obligations in Art. 16). For SMEs, including start-ups, the fine is capped at whichever of the two is lower (Art. 99(6)). Since 27 Jul 2026, the same lower cap applies to small mid-cap enterprises (Art. 99(6a)).
Did the Digital Omnibus change Article 9?
Its text is unchanged. Regulation (EU) 2026/1744 moved the date it applies from, through Article 113. The section "What changed" quotes the old and new text.
Is there an AiExponent tool for Article 9?
Yes. RiskForge is released and open source. It writes a Risk Management File (JSON / PDF).

Content verified 4 Oct 2026 · Not legal advice.