Article 9: Risk Management System
Article 9 requires providers of high-risk systems to run a continuous, iterative risk management process across the entire lifecycle of the system, identifying and mitigating known and reasonably foreseeable risks to health, safety, and fundamental rights. It is not a one-off pre-launch exercise.
- 02 Dec 2027 Applies to Annex III high-risk systems
- 02 Aug 2028 Applies to Annex I embedded high-risk systems
- Establish a documented risk management process covering the full lifecycle, from design to decommissioning.
- Identify known and reasonably foreseeable risks, including risks that emerge from reasonably foreseeable misuse.
- Evaluate and mitigate identified risks through design measures, mitigation measures, and information to deployers.
- Update the risk management file whenever the system, its use, or new evidence changes the risk picture.
- Keep the risk management system as part of the technical documentation package.
- Documented risk management system, kept current as part of technical documentation
Article 9 is frequently treated as a one-time risk assessment signed off before launch, when the text explicitly requires a continuous, iterative process maintained throughout the system's life.
What regulators published on Art. 9
- Loading from the public feed…
- Regulation (EU) 2024/1689 on EUR-Lex
- Look for Article 9
- Deadline changes and the acts behind them
Get told when Art. 9 moves.
Deadlines under this regulation have already shifted once in 2026. A signed webhook, a REST API and an MCP server carry the same record this page is built from, so your systems learn about the next change without anyone re-reading the text. Free during the beta.
Get free accessInformational content only. Not legal advice and not a substitute for qualified counsel. Dates reflect Regulation (EU) 2026/1744 as of 04 Aug 2026.