Skip to content

Regulation Tracker / EU AI Act / Chapter III · Section 2

Article 9
Risk management system

Chapter III — Classification rules for high-risk AI systems, Section 2 — Compliance with the requirements. 10 distinct duties, powers or definitions are coded from this article, applying from 2027-12-02. 10 reach legal practice directly.

Amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI), in force 2026-07-27 — about 122 words changed. The text below is the consolidated version of 27 July 2026; the 2024 text and the amending regulation are on EUR-Lex. 10 of the duties below now apply later than Article 113 originally provided; each shows both dates.

official text: EUR-Lex (consolidated 27 Jul 2026) · text © European Union (Decision 2011/833/EU) · coding CC BY 4.0 · data: obligations.json · Hugging Face · GitHub

The text

1. A risk management system shall be established, implemented, documented and maintained in relation to high-risk AI systems.

2. The risk management system shall be understood as a continuous iterative process planned and run throughout the entire lifecycle of a high-risk AI system, requiring regular systematic review and updating. It shall comprise the following steps:

  1. (a)the identification and analysis of the known and the reasonably foreseeable risks that the high-risk AI system can pose to health, safety or fundamental rights when the high-risk AI system is used in accordance with its intended purpose;
  2. (b)the estimation and evaluation of the risks that may emerge when the high-risk AI system is used in accordance with its intended purpose, and under conditions of reasonably foreseeable misuse;
  3. (c)the evaluation of other risks possibly arising, based on the analysis of data gathered from the post-market monitoring system referred to in Article 72;
  4. (d)the adoption of appropriate and targeted risk management measures designed to address the risks identified pursuant to point (a).

3. The risks referred to in this Article shall concern only those which may be reasonably mitigated or eliminated through the development or design of the high-risk AI system, or the provision of adequate technical information.

4. The risk management measures referred to in paragraph 2, point (d), shall give due consideration to the effects and possible interaction resulting from the combined application of the requirements set out in this Section, with a view to minimising risks more effectively while achieving an appropriate balance in implementing the measures to fulfil those requirements.

5. The risk management measures referred to in paragraph 2, point (d), shall be such that the relevant residual risk associated with each hazard, as well as the overall residual risk of the high-risk AI systems is judged to be acceptable.

6. High-risk AI systems shall be tested for the purpose of identifying the most appropriate and targeted risk management measures. Testing shall ensure that high-risk AI systems perform consistently for their intended purpose and that they are in compliance with the requirements set out in this Section.

7. Testing procedures may include testing in real-world conditions in accordance with Article 60.

8. The testing of high-risk AI systems shall be performed, as appropriate, at any time throughout the development process, and, in any event, prior to their being placed on the market or put into service. Testing shall be carried out against prior defined metrics and probabilistic thresholds that are appropriate to the intended purpose of the high-risk AI system.

9. When implementing the risk management system as provided for in paragraphs 1 to 7, providers shall give consideration to whether in view of its intended purpose the high-risk AI system is likely to have an adverse impact on persons under the age of 18 and, as appropriate, other vulnerable groups.

10. For providers of high-risk AI systems that are subject to requirements regarding internal risk management processes under other relevant provisions of Union law, the aspects provided in paragraphs 1 to 9 may be part of, or combined with, the risk management procedures established pursuant to that law.

What it requires, coded

SafeLegalAI's reading of each duty in this article: who, what, from when, under which fine tier, and whether it reaches a firm, chambers, court or legal-AI vendor. Descriptive, not advice; the quoted words are the Regulation's.

  1. Art. 9(1)Risk managementHigh-risklegal practice

    Providers must establish, implement, document and maintain a risk management system for high-risk AI systems.

    "A risk management system shall be established, implemented, documented and maintained in relation to high-risk AI systems."
    Who
    Provider
    From
    (Art. 113(c)(i) as amended by Reg. (EU) 2026/1744)As enacted in 2024: (Art. 113 second subparagraph); deferred by Regulation (EU) 2026/1744 (Digital Omnibus on AI).For Art. 6(1)/Annex I high-risk systems, Art. 113(c)(ii) as amended applies the corresponding obligation from 2028-08-02; Art. 111(2) gives public-authority high-risk systems until 2030-08-02.
    Fine tier
    Art. 99(4)
    Legal practice
    Reaches legal practice directly — Core obligation for legal-AI vendors whose systems are high-risk, including judicial or ADR systems under Annex III point 8.
    See
    Art. 6 · Annex III point 8
  2. Art. 9(2)Risk managementHigh-risklegal practice

    The risk management system must be a continuous lifecycle process with systematic review and updating, covering risk identification, estimation, post-market risk evaluation and targeted mitigation measures.

    "The risk management system shall be understood as a continuous iterative process planned and run throughout the entire lifecycle of a high-risk AI system, requiring regular systematic review and updating. It shall comprise the following steps:"
    Who
    Provider
    From
    (Art. 113(c)(i) as amended by Reg. (EU) 2026/1744)As enacted in 2024: (Art. 113 second subparagraph); deferred by Regulation (EU) 2026/1744 (Digital Omnibus on AI).For Art. 6(1)/Annex I high-risk systems, Art. 113(c)(ii) as amended applies the corresponding obligation from 2028-08-02; Art. 111(2) gives public-authority high-risk systems until 2030-08-02.
    Fine tier
    Art. 99(4)
    Legal practice
    Reaches legal practice directly — Core obligation for legal-AI vendors whose systems are high-risk, including judicial or ADR systems under Annex III point 8.
    See
    Art. 6 · Annex III point 8 · Art. 72
  3. Art. 9(3)Risk managementHigh-risklegal practice

    Article 9 risk management concerns only risks that may reasonably be mitigated or eliminated through system development, design or adequate technical information.

    "The risks referred to in this Article shall concern only those which may be reasonably mitigated or eliminated through the development or design of the high-risk AI system, or the provision of adequate technical information."
    Who
    Provider
    From
    (Art. 113(c)(i) as amended by Reg. (EU) 2026/1744)As enacted in 2024: (Art. 113 second subparagraph); deferred by Regulation (EU) 2026/1744 (Digital Omnibus on AI).For Art. 6(1)/Annex I high-risk systems, Art. 113(c)(ii) as amended applies the corresponding obligation from 2028-08-02; Art. 111(2) gives public-authority high-risk systems until 2030-08-02.
    Fine tier
    Art. 99(4)
    Legal practice
    Reaches legal practice directly — Core obligation for legal-AI vendors whose systems are high-risk, including judicial or ADR systems under Annex III point 8.
    See
    Art. 6 · Annex III point 8
  4. Art. 9(4)Risk managementHigh-risklegal practice

    Risk management measures must consider the effects and interactions of all Section 2 requirements to minimise risks while balancing implementation of those requirements.

    "The risk management measures referred to in paragraph 2, point (d), shall give due consideration to the effects and possible interaction resulting from the combined application of the requirements set out in this Section, with a view to minimising risks more effectively while achieving an appropriate balance in implementing the measures to fulfil those requirements."
    Who
    Provider
    From
    (Art. 113(c)(i) as amended by Reg. (EU) 2026/1744)As enacted in 2024: (Art. 113 second subparagraph); deferred by Regulation (EU) 2026/1744 (Digital Omnibus on AI).For Art. 6(1)/Annex I high-risk systems, Art. 113(c)(ii) as amended applies the corresponding obligation from 2028-08-02; Art. 111(2) gives public-authority high-risk systems until 2030-08-02.
    Fine tier
    Art. 99(4)
    Legal practice
    Reaches legal practice directly — Core obligation for legal-AI vendors whose systems are high-risk, including judicial or ADR systems under Annex III point 8.
    See
    Art. 6 · Annex III point 8
  5. Art. 9(5)Risk managementHigh-risklegal practice

    Risk management measures must make each residual hazard risk and the overall residual risk of high-risk AI systems acceptable.

    "The risk management measures referred to in paragraph 2, point (d), shall be such that the relevant residual risk associated with each hazard, as well as the overall residual risk of the high-risk AI systems is judged to be acceptable."
    Who
    Provider
    From
    (Art. 113(c)(i) as amended by Reg. (EU) 2026/1744)As enacted in 2024: (Art. 113 second subparagraph); deferred by Regulation (EU) 2026/1744 (Digital Omnibus on AI).For Art. 6(1)/Annex I high-risk systems, Art. 113(c)(ii) as amended applies the corresponding obligation from 2028-08-02; Art. 111(2) gives public-authority high-risk systems until 2030-08-02.
    Fine tier
    Art. 99(4)
    Legal practice
    Reaches legal practice directly — Core obligation for legal-AI vendors whose systems are high-risk, including judicial or ADR systems under Annex III point 8.
    See
    Art. 6 · Annex III point 8
  6. Art. 9(6)Risk managementHigh-risklegal practice

    High-risk AI systems must be tested to identify targeted risk management measures and ensure consistent intended-purpose performance and compliance with Section 2 requirements.

    "High-risk AI systems shall be tested for the purpose of identifying the most appropriate and targeted risk management measures. Testing shall ensure that high-risk AI systems perform consistently for their intended purpose and that they are in compliance with the requirements set out in this Section."
    Who
    Provider
    From
    (Art. 113(c)(i) as amended by Reg. (EU) 2026/1744)As enacted in 2024: (Art. 113 second subparagraph); deferred by Regulation (EU) 2026/1744 (Digital Omnibus on AI).For Art. 6(1)/Annex I high-risk systems, Art. 113(c)(ii) as amended applies the corresponding obligation from 2028-08-02; Art. 111(2) gives public-authority high-risk systems until 2030-08-02.
    Fine tier
    Art. 99(4)
    Legal practice
    Reaches legal practice directly — Core obligation for legal-AI vendors whose systems are high-risk, including judicial or ADR systems under Annex III point 8.
    See
    Art. 6 · Annex III point 8
  7. Art. 9(7)Derogation or exemptionHigh-risklegal practice

    Testing procedures for high-risk AI systems may include testing in real-world conditions in accordance with Article 60.

    "Testing procedures may include testing in real-world conditions in accordance with Article 60."
    Who
    Provider
    From
    (Art. 113(c)(i) as amended by Reg. (EU) 2026/1744)As enacted in 2024: (Art. 113 second subparagraph); deferred by Regulation (EU) 2026/1744 (Digital Omnibus on AI).For Art. 6(1)/Annex I high-risk systems, Art. 113(c)(ii) as amended applies the corresponding obligation from 2028-08-02; Art. 111(2) gives public-authority high-risk systems until 2030-08-02.
    Legal practice
    Reaches legal practice directly — Core obligation for legal-AI vendors whose systems are high-risk, including judicial or ADR systems under Annex III point 8.
    See
    Art. 6 · Annex III point 8 · Art. 60
  8. Art. 9(8)Risk managementHigh-risklegal practice

    Testing of high-risk AI systems must occur as appropriate during development and always before market placement or service, against predefined metrics and probabilistic thresholds.

    "The testing of high-risk AI systems shall be performed, as appropriate, at any time throughout the development process, and, in any event, prior to their being placed on the market or put into service. Testing shall be carried out against prior defined metrics and probabilistic thresholds that are appropriate to the intended purpose of the high-risk AI system."
    Who
    Provider
    From
    (Art. 113(c)(i) as amended by Reg. (EU) 2026/1744)As enacted in 2024: (Art. 113 second subparagraph); deferred by Regulation (EU) 2026/1744 (Digital Omnibus on AI).For Art. 6(1)/Annex I high-risk systems, Art. 113(c)(ii) as amended applies the corresponding obligation from 2028-08-02; Art. 111(2) gives public-authority high-risk systems until 2030-08-02.
    Fine tier
    Art. 99(4)
    Legal practice
    Reaches legal practice directly — Core obligation for legal-AI vendors whose systems are high-risk, including judicial or ADR systems under Annex III point 8.
    See
    Art. 6 · Annex III point 8
  9. Art. 9(9)Risk managementHigh-risklegal practice

    Providers implementing risk management must consider whether the intended purpose is likely to adversely affect persons under 18 and, as appropriate, other vulnerable groups.

    "When implementing the risk management system as provided for in paragraphs 1 to 7, providers shall give consideration to whether in view of its intended purpose the high-risk AI system is likely to have an adverse impact on persons under the age of 18 and, as appropriate, other vulnerable groups."
    Who
    Provider
    From
    (Art. 113(c)(i) as amended by Reg. (EU) 2026/1744)As enacted in 2024: (Art. 113 second subparagraph); deferred by Regulation (EU) 2026/1744 (Digital Omnibus on AI).For Art. 6(1)/Annex I high-risk systems, Art. 113(c)(ii) as amended applies the corresponding obligation from 2028-08-02; Art. 111(2) gives public-authority high-risk systems until 2030-08-02.
    Fine tier
    Art. 99(4)
    Legal practice
    Reaches legal practice directly — Core obligation for legal-AI vendors whose systems are high-risk, including judicial or ADR systems under Annex III point 8.
    See
    Art. 6 · Annex III point 8
  10. Art. 9(10)Risk managementHigh-risklegal practice

    Providers subject to internal risk-management requirements under other Union law may include or combine Article 9 aspects with those existing procedures.

    "For providers of high-risk AI systems that are subject to requirements regarding internal risk management processes under other relevant provisions of Union law, the aspects provided in paragraphs 1 to 9 may be part of, or combined with, the risk management procedures established pursuant to that law."
    Who
    Provider
    From
    (Art. 113(c)(i) as amended by Reg. (EU) 2026/1744)As enacted in 2024: (Art. 113 second subparagraph); deferred by Regulation (EU) 2026/1744 (Digital Omnibus on AI).For Art. 6(1)/Annex I high-risk systems, Art. 113(c)(ii) as amended applies the corresponding obligation from 2028-08-02; Art. 111(2) gives public-authority high-risk systems until 2030-08-02.
    Fine tier
    Art. 99(4)
    Legal practice
    Reaches legal practice directly — Core obligation for legal-AI vendors whose systems are high-risk, including judicial or ADR systems under Annex III point 8.
    See
    Art. 6 · Annex III point 8

Cite

Regulation (EU) 2024/1689, Article 9 (Risk management system), as amended by Regulation (EU) 2026/1744, consolidated text of 27 July 2026, https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_9 — text © European Union; only the Official Journal is authentic. Coding: SafeLegalAI (published by Cognesio LLP), "EU AI Act, structured", safelegalai.com/regulation/eu-ai-act/article-9, accessed 2026-09-08, CC BY 4.0.