Arts 8–9: the compliance frame and the risk management system
Lesson 1 of 6 in Inside the High-Risk Rulebook: Arts 8–15 Article by Article.
Once a system is classified high-risk, Chapter III Section 2 hands you seven substantive requirements — Arts 9 through 15 — and one framing article that tells you how to read them all. Art 8 says high-risk systems shall comply with the Section 2 requirements taking into account the intended purpose and the generally acknowledged state of the art. Two consequences hide in that sentence.
First, the requirements are contextual, not absolute. ‘Appropriate accuracy’ for a spam filter and for an emergency-triage system are different numbers; the intended purpose you declared during classification now calibrates every downstream duty. Second, the bar moves: state of the art in bias testing or adversarial robustness in 2027 will not be what it was in 2024, and compliance is measured against the moving bar. These are essential requirements in the New Legislative Framework sense — outcome descriptions whose technical content harmonised standards are meant to fill in. Primary responsibility for meeting all seven sits with the provider (Art 16(a)) — the value-chain module takes that thread up next.
Art 9 is the keystone: a risk management system that is established, implemented, documented and maintained — four verbs, each auditable. And it must be a continuous, iterative process planned and run throughout the entire lifecycle, not a risk-assessment workshop with a completion date.
Art 9: the risk management loop
- Plan the RMS across the lifecycle
Art 9(2): a continuous iterative process, requiring regular systematic review and updating — the loop below never terminates while the system is on the market.
- Identify & analyse foreseeable risks
Risks to health, safety and fundamental rights when the system is used in accordance with its intended purpose (Art 9(2)(a)).
- Estimate & evaluate risks — intended use AND foreseeable misuse
Art 9(2)(b): reasonably foreseeable misuse is in scope by statute. “Nobody should use it that way” is not a defence the text permits.
- Evaluate risks emerging from post-market data
Art 9(2)(c): data from the Art 72 post-market monitoring system feeds back into the risk analysis — the hook that makes the loop circular.
- Adopt targeted risk management measures
Art 9(2)(d) and 9(5), in strict order of preference: (1) eliminate or reduce risk through design and development; (2) mitigation and control measures for what cannot be eliminated; (3) information and training to deployers. Warning labels come last, not first.
- Judge residual risk acceptable?
Art 9(5): residual risks — per hazard and overall — must be judged acceptable. That judgment, and who signed it, is a documented artifact an auditor will ask for.
- Test against pre-defined metrics & thresholds
Art 9(6)–(8): testing to identify the most appropriate measures, against metrics and probabilistic thresholds defined in advance, throughout development and before market placement — including, where appropriate, real-world testing under Art 60.
- On the market — monitor and loop back
Post-market monitoring data re-enters at step 3. The RMS ends when the system leaves the market, not when it enters.
Key terms: risk management system, intended purpose, reasonably foreseeable misuse, residual risk, state of the art
Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.