Glossary · EU AI Act: high-risk AI
AI risk planning
Also known as: AI risk management, risk management system (AI Act)
German: KI-Risikomanagement
In AI governance, AI risk planning is the structured identification, evaluation, control, monitoring and documentation of risks arising from AI use. Under the EU AI Act, it takes the form of the risk management system that providers of high-risk AI systems must establish, document and maintain as a continuous, iterative process across the system’s lifecycle.
- AI regulation
- EU
In one sentence
AI risk planning identifies, evaluates, controls and monitors AI risks; for high-risk AI it is the risk management system of Art. 9 AI Act.
Example
The provider of an AI-based picking robot plans for risks such as misclassified objects, unexpected arm paths near workers and degraded vision in dust, defines tests and monitoring for each, and updates the plan from field data.
How it applies
- Steps under Article 9: Identify and analyze known and reasonably foreseeable risks to health, safety and fundamental rights; estimate and evaluate risks under the intended purpose and reasonably foreseeable misuse; evaluate further risks from post-market monitoring; and adopt targeted measures so that residual risk is judged acceptable. Testing against predefined metrics is part of the process.
- Scope: It applies to high-risk AI systems and must consider the effects on persons under 18 and other vulnerable groups. Providers already running risk management under other EU law may combine the two.
- Machine safety: For AI in machinery, AI risk planning complements the machine risk assessment under ISO 12100. Keep one hazard list and link AI-specific risks to it instead of running two unconnected analyses.
- Technical documentation: The risk management system is documented in the technical documentation (AI Act); residual risks that users must know go into the instructions for use.
Compared with the USA, Canada and China
In the USA, the NIST AI RMF offers a voluntary structure for the same work, and California's SB 53 requires large frontier developers to publish how they assess and mitigate catastrophic risks. Colorado's replacement law dropped the risk management programs of its original AI Act. Canada's federal institutions assess risk through the Algorithmic Impact Assessment. China requires a security assessment before influential generative AI services launch, reviewed by the regulator rather than run as a provider's own continuous process.
Read more on AI TechDoc Press
The in-depth analysis behind this entry, in the AI TechDoc Press newsletter. Subscribe for free