EU AI Act Art. 9: risk management system

Risk management system across the high-risk lifecycle

From clause to evidenceThe chain from EU AI Act Art. 9 to its evidence record, in 6 steps; the text alternative lists them and the facts under the figure state each in full.ClauseEU AI ActArt. 9Duty holderProviderApplies from2027-12-02DeferredArtefactRisk registeras codeLayersLayer 01Layer 03Evidence recordRisk registerentry+8 moreSame topic in 24 frameworks (83 clauses): ISO 42001, NIST AI RMF, TC260 Framework 3.0, ISO 23894, CSA AICM, Korea AIAct, UK ATRS and 17 moreAs of 2026-09-24 · illustrative, not a claim of conformity From clause to evidenceThe chain from EU AI Act Art. 9 to its evidence record, in 6 steps; the text alternative lists them and the facts under the figure state each in full.ClauseEU AI Act · Art. 9Duty holderProviderApplies from2027-12-02 · DeferredArtefactRisk register as codeLayersLayer 01Layer 03Evidence recordRisk register entry · +8 moreSame topic in 24 frameworks (83 clauses):ISO 42001, NIST AI RMF, TC260 Framework 3.0,ISO 23894, CSA AICM and 19 moreAs of 2026-09-24illustrative, not a claim of conformity
From clause to evidence Build the artefact, then file every output it produces as a record that names AIGE-OBL-EUAIA-ART9. Drawn from chapter 08.
Text alternative
Id
AIGE-OBL-EUAIA-ART9
Instrument
EU AI Act (post-Omnibus) law
Compared side by side
ISO 42001 vs EU AI Act · NIST AI RMF vs EU AI Act
Clause
Art. 9
Duty holder
Provider
Authority
National MSA
Applies from
Deferred · Annex III
Later dates
  • Applies to Annex I embedded (product safety-component) systems
  • Deadline for legacy high-risk systems intended for use by public authorities (Art. 111(2))
System class
High-risk (Annex III) · High-risk (Annex I)

The artefact that evidences it

Risk register as code; threat models; linkage to FRIA and eval results.

Patterns that build it

The same topic in other frameworks

From the topic crosswalk: the clauses filed under the same topics as this one. Mappings are illustrative, not a claim of conformity.

Risk management

Impact assessment

Robustness, security and evaluations

Open controls that evidence it

Draft controls in the open control profiles that map to this row: each states a requirement and the evidence it must leave behind.

Source

Chapter 08, section EU AI Act, post-Omnibus, checked against its sources on the review date above.

Machine-readable

Cite this obligation

García Aibar, J. (2026). EU AI Act Art. 9: risk management system (AIGE-OBL-EUAIA-ART9). In AI Governance Engineering: The Thesis & Body of Knowledge (v0.5.0). https://doi.org/10.5281/zenodo.22956197. https://aigovernanceengineer.com/obligations/aige-obl-euaia-art9. CC BY 4.0

BibTeX

@misc{aige2026obligation,
  author       = {Jorge García Aibar},
  title        = {{EU AI Act Art. 9: risk management system (AIGE-OBL-EUAIA-ART9)}},
  howpublished = {In AI Governance Engineering: The Thesis \& Body of Knowledge},
  year         = {2026},
  version      = {0.5.0},
  doi          = {10.5281/zenodo.22956197},
  url          = {https://aigovernanceengineer.com/obligations/aige-obl-euaia-art9},
  note         = {Version 0.5.0}
}