Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.

What AI risk management does the EU AI Act require?

Updated

Article 9 of Regulation (EU) 2024/1689 is a high-risk AI risk-management system, only if Article 6 applies. Article 55 is a separate GPAI systemic-risk track. ISO 42001 and NIST AI RMF do not discharge Article 9. Not legal advice. It does not determine that YOU have to run an RMS.

AI risk management requirements, last verified 9 September 2026 against Articles 6, 8, 9, 16, 51, 55 and 113 of Regulation (EU) 2024/1689 (OJ L 2024/1689, 12.7.2024). Article 9 is not Article 55. ISO/IEC 42001:2023 is a management-system standard, not the regulation. ISO/IEC 23894:2023 is guidance on AI risk management, not a legal substitute. NIST AI RMF 1.0 is guidance, not law. Commission AI Act pages and AI Office materials are Commission materials — guidance, not the regulation. Regulation (EU) 2026/1744 is an amending regulation. This page is not legal advice, not a filing, not a determination that YOU have to run an Article 9 risk-management system, and does not start a clock.

This is Article 9 and Article 55, not YOUR risk-management system

Audience: a risk owner, CISO, or product owner walking Regulation (EU) 2024/1689 on AI risk management. This page is not legal advice. It does not start a clock. Reading it does not start a clock. Mapping a row is not a determination that the Act applies, that YOUR system is high-risk, that Article 9 binds YOU, or that YOU have to run an Article 9 risk-management system. This page does not file with the AI Office.

The AI Act is Regulation (EU) 2024/1689 of 13 June 2024, OJ L 2024/1689, 12.7.2024. ELI: http://data.europa.eu/eli/reg/2024/1689/oj. Article 9 is the risk-management system for high-risk AI systems. Article 55 is a different track: extra duties for providers of general-purpose AI models with systemic risk. They are not the same article. ISO/IEC 42001:2023 is a standard. ISO/IEC 23894:2023 is guidance. NIST AI RMF 1.0 is guidance. They are not the Act. The EU AI Act overview on this site is the pillar page. The AI-governance-requirements guide on this site is the Articles 4, 14, 26 and ISO 42001 page. The GPAI-systemic-risk guide on this site is the Article 51–55 page. Last verified 9 September 2026. Not legal advice.

  • Statute versus standard versus guidance: Articles 6, 8, 9, 16, 51, 55 and 113 of 2024/1689 are legal requirements only if they apply. ISO/IEC 42001:2023 is a management-system standard, not a legal substitute for the Act. ISO/IEC 23894:2023 is guidance on AI risk management, not a legal substitute. NIST AI RMF 1.0 is guidance, not law. Commission AI Act pages and AI Office materials are Commission materials — guidance, not the regulation. This page quotes which kind of text it is relying on.
  • The requirements-in-force-2026 guide on this site is the Article 113 dates page. The GPAI-requirements guide on this site is the Article 53 baseline page. The GPAI-systemic-risk guide on this site is the Article 51–55 page. The provider-vs-deployer guide on this site is the Articles 3, 16, 25 and 26 page. The AI-governance-requirements guide on this site is the Articles 4, 14, 26 and ISO 42001 page. A dedicated model-evaluation-requirements, AI-ownership-accountability, and how-shipreadymetrics-tracks-ai-risk guide is not on this site yet. Naming them is not a link.
  • This page does not invent a 2 August 2026 start date for Annex I high-risk RMS duties. Article 9 sits in Chapter III Section 2. Article 113(c) of 2024/1689 keeps Article 6(1) and the corresponding obligations — Annex I product-embedded high-risk — on 2 August 2027, not 2 August 2026. Article 55 sits in Chapter V. Article 113(b) applies Chapter V from 2 August 2025, with the exception of Article 101. Those dates are not one number. This page does not invent a 2 August 2026 date for Annex I.

Article 9 is not Article 55

Do not conflate them. Article 9 is a high-risk AI-system risk-management system. Article 55 is a GPAI-model systemic-risk assessment track. A high-risk AI system under Article 6 is not automatically a general-purpose AI model with systemic risk under Article 51. A systemic-risk GPAI model is not automatically a high-risk AI system under Article 6. Mapping a row is not a finding that either article binds YOU. Last verified 9 September 2026. Not legal advice.

Article 9 versus Article 55 (not YOUR file; not a determination that either binds YOU; not legal advice)
TrackWhat the cited text isKind of textLast verified
Article 9 — high-risk RMSA risk management system shall be established, implemented, documented and maintained in relation to high-risk AI systems. Legal requirement if Article 6 high-risk applies. This page does not find that YOUR system is high-risk and does not determine that Article 9 binds YOU.Article 9 of 2024/1689. Legal requirement, only if it applies. Distinct from Article 55.9 September 2026
Article 55 — GPAI systemic-risk assessmentIn addition to Articles 53 and 54, providers of general-purpose AI models with systemic risk shall, among other points, assess and mitigate possible systemic risks at Union level. Legal requirement if Article 51 systemic-risk applies. In force 2 August 2025 via Article 113(b). This page does not designate YOUR model.Article 55 of 2024/1689. Legal requirement, only if it applies. Distinct from Article 9.9 September 2026
Article 6 — high-risk classification, not Article 55Article 6 classifies high-risk AI systems (Annex I product-embedded under Article 6(1); Annex III use-cases under Article 6(2)). That classification is the gate for Article 9. It is not the Article 51 systemic-risk gate.Article 6 of 2024/1689. Legal requirement, only if it applies. This page does not classify YOUR system.9 September 2026
Article 51 — GPAI systemic-risk classification, not Article 9Article 51 classifies general-purpose AI models with systemic risk. That classification is the gate for Article 55. It is not the Article 6 high-risk gate and is not Article 9.Article 51 of 2024/1689. Legal requirement, only if it applies. The GPAI-systemic-risk guide on this site is the Article 51–55 page.9 September 2026

What original Article 9 actually says

Last verified 9 September 2026 against Article 9 of Regulation (EU) 2024/1689 on EUR-Lex (OJ L 2024/1689, 12.7.2024). These are legal requirements of the original regulation, only if they apply. This page does not apply them to YOU. Not legal advice.

Article 9 as the original regulation states it (not YOUR RMS; not a determination that Article 9 binds YOU; not legal advice)
PointWhat the cited text saysKind of textLast verified
Article 9(1)Authentic Article 9(1): A risk management system shall be established, implemented, documented and maintained in relation to high-risk AI systems.Article 9(1) of 2024/1689. Legal requirement, only if it applies. This page does not establish YOUR RMS.9 September 2026
Article 9(2) chapeauAuthentic Article 9(2): The risk management system shall be understood as a continuous iterative process planned and run throughout the entire lifecycle of a high-risk AI system, requiring regular systematic review and updating.Article 9(2) of 2024/1689. Legal requirement, only if it applies. This page does not run YOUR lifecycle.9 September 2026
Article 9(2)(a)the identification and analysis of the known and the reasonably foreseeable risks that the high-risk AI system can pose to health, safety or fundamental rights when the high-risk AI system is used in accordance with its intended purpose;Article 9(2)(a) of 2024/1689. Legal requirement, only if it applies. This page does not identify YOUR risks.9 September 2026
Article 9(2)(b)the estimation and evaluation of the risks that may emerge when the high-risk AI system is used in accordance with its intended purpose, and under conditions of reasonably foreseeable misuse;Article 9(2)(b) of 2024/1689. Legal requirement, only if it applies.9 September 2026
Article 9(2)(c)the evaluation of other risks possibly arising, based on the analysis of data gathered from the post-market monitoring system referred to in Article 72;Article 9(2)(c) of 2024/1689. Legal requirement, only if it applies. This page does not run YOUR Article 72 monitoring.9 September 2026
Article 9(2)(d)the adoption of appropriate and targeted risk management measures designed to address the risks identified pursuant to point (a).Article 9(2)(d) of 2024/1689. Legal requirement, only if it applies. This page does not pick YOUR measures.9 September 2026
Article 9(3)The risks referred to in this Article shall concern only those which may be reasonably mitigated or eliminated through the development or design of the high-risk AI system, or the provision of adequate technical information.Article 9(3) of 2024/1689. Legal requirement, only if it applies.9 September 2026
Article 9(4)The risk management measures referred to in paragraph 2, point (d), shall give due consideration to the effects and possible interaction resulting from the combined application of the requirements set out in this Section, with a view to minimising risks more effectively while achieving an appropriate balance in implementing the measures to fulfil those requirements.Article 9(4) of 2024/1689. Legal requirement, only if it applies. 'This Section' is Chapter III Section 2.9 September 2026
Article 9(5)The risk management measures referred to in paragraph 2, point (d), shall be such that the relevant residual risk associated with each hazard, as well as the overall residual risk of the high-risk AI systems is judged to be acceptable. In identifying the most appropriate risk management measures, the following shall be ensured: (a) elimination or reduction of risks identified and evaluated pursuant to paragraph 2 in as far as technically feasible through adequate design and development; (b) where appropriate, implementation of adequate mitigation and control measures addressing risks that cannot be eliminated; (c) provision of information required pursuant to Article 13 and, where appropriate, training to deployers.Article 9(5) of 2024/1689. Legal requirement, only if it applies. This page does not judge YOUR residual risk acceptable.9 September 2026
Article 9(6) and 9(8)High-risk AI systems shall be tested for the purpose of identifying the most appropriate and targeted risk management measures. Testing shall be performed, as appropriate, at any time throughout the development process, and, in any event, prior to their being placed on the market or put into service. Testing shall be carried out against prior defined metrics and probabilistic thresholds that are appropriate to the intended purpose of the high-risk AI system.Articles 9(6) and 9(8) of 2024/1689. Legal requirement, only if it applies. This page does not run YOUR tests. A dedicated model-evaluation-requirements guide is not on this site yet. Naming it is not a link.9 September 2026
Article 9(7)Testing procedures may include testing in real-world conditions in accordance with Article 60.Article 9(7) of 2024/1689. Legal requirement, only if it applies. This page does not authorise YOUR real-world test.9 September 2026
Article 9(9)When implementing the risk management system as provided for in paragraphs 1 to 7, providers shall give consideration to whether in view of its intended purpose the high-risk AI system is likely to have an adverse impact on persons under the age of 18 and, as appropriate, other vulnerable groups.Article 9(9) of 2024/1689. Legal requirement, only if it applies. This page does not assess YOUR impact on persons under 18.9 September 2026
Article 9(10)For providers of high-risk AI systems that are subject to requirements regarding internal risk management processes under other relevant provisions of Union law, the aspects provided in paragraphs 1 to 9 may be part of, or combined with, the risk management procedures established pursuant to that law.Article 9(10) of 2024/1689. Legal requirement, only if it applies. Combining procedures is not a determination that Article 9 is discharged by ISO 42001 or NIST AI RMF.9 September 2026
Article 8 and Article 16(a) — Section 2 gateArticle 8: High-risk AI systems shall comply with the requirements laid down in this Section, taking into account their intended purpose and the generally acknowledged state of the art on AI and AI-related technologies. Article 16(a): Providers of high-risk AI systems shall ensure that their high-risk AI systems are compliant with the requirements set out in Section 2. Section 2 includes Article 9.Articles 8 and 16(a) of 2024/1689. Legal requirement, only if it applies. This page does not find that YOU are a provider.9 September 2026

Article 113: high-risk RMS dates are not the GPAI dates

Last verified 9 September 2026 against Article 113 of Regulation (EU) 2024/1689 on EUR-Lex (OJ L 2024/1689, 12.7.2024). Article 9 sits in Chapter III Section 2 (requirements for high-risk AI systems). The original Article 113 second paragraph applies the rest of the Regulation from 2 August 2026. Article 113(c) keeps Article 6(1) and the corresponding obligations — Annex I product-embedded high-risk — on 2 August 2027, not 2 August 2026. High-risk RMS duties did not start on 2 August 2026 for Annex I. This page does not invent a 2 August 2026 date for Annex I. Those dates are not one number.

Article 55 sits in Chapter V. Article 113(b): Chapter III Section 4, Chapter V, Chapter VII and Chapter XII and Article 78 shall apply from 2 August 2025, with the exception of Article 101. GPAI systemic-risk assessment duties therefore apply from 2 August 2025 under Article 113(b), except Article 101. They did not start on 2 August 2026. This page does not invent a 2 August 2026 start date for GPAI.

Regulation (EU) 2026/1744 is an amending regulation. Counsel reads the authentic operative article of any amendment. This page does not apply 2026/1744 to YOU. It does not rewrite Article 113(b) for Chapter V in the original regulation, and it does not move original Article 113(c) Annex I off 2 August 2027. Not legal advice.

What original Article 55 actually says — the other track

Last verified 9 September 2026 against Article 55 of Regulation (EU) 2024/1689 on EUR-Lex (OJ L 2024/1689, 12.7.2024). Article 55 is not Article 9. The GPAI-systemic-risk guide on this site is the Article 51–55 page. Mapping a row is not a designation that YOUR model has systemic risk. Not legal advice.

Article 55 as the original regulation states it (not YOUR assessment; not a designation; not Article 9; not legal advice)
PointWhat the cited text saysKind of textLast verified
Article 55(1) chapeauAuthentic Article 55(1): In addition to the obligations listed in Articles 53 and 54, providers of general-purpose AI models with systemic risk shall:Article 55(1) of 2024/1689. Legal requirement, only if Article 51 systemic-risk applies. Distinct from Article 9.9 September 2026
Article 55(1)(a)perform model evaluation in accordance with standardised protocols and tools reflecting the state of the art, including conducting and documenting adversarial testing of the model with a view to identifying and mitigating systemic risks;Article 55(1)(a) of 2024/1689. Legal requirement, only if it applies. This page does not evaluate YOUR model. A dedicated model-evaluation-requirements guide is not on this site yet. Naming it is not a link.9 September 2026
Article 55(1)(b)assess and mitigate possible systemic risks at Union level, including their sources, that may stem from the development, the placing on the market, or the use of general-purpose AI models with systemic risk;Article 55(1)(b) of 2024/1689. Legal requirement, only if it applies. This is the GPAI systemic-risk assessment track. It is not the Article 9 high-risk RMS.9 September 2026
Article 55(1)(c)keep track of, document, and report, without undue delay, to the AI Office and, as appropriate, to national competent authorities, relevant information about serious incidents and possible corrective measures to address them;Article 55(1)(c) of 2024/1689. Legal requirement, only if it applies. This page does not file that report and does not start a clock.9 September 2026
Article 55(1)(d)ensure an adequate level of cybersecurity protection for the general-purpose AI model with systemic risk and the physical infrastructure of the model.Article 55(1)(d) of 2024/1689. Legal requirement, only if it applies. A dedicated AI-cybersecurity-requirements guide is not on this site yet. Naming it is not a link.9 September 2026
Article 55(2)Providers of general-purpose AI models with systemic risk may rely on codes of practice within the meaning of Article 56 to demonstrate compliance with the obligations set out in paragraph 1 of this Article, until a harmonised standard is published. Compliance with European harmonised standards grants providers the presumption of conformity to the extent that those standards cover those obligations. Providers who do not adhere to an approved code of practice or do not comply with a European harmonised standard shall demonstrate alternative adequate means of compliance for assessment by the Commission.Article 55(2) of 2024/1689. Legal requirement of the option, only if it applies. A code of practice is voluntary and does not replace Article 55. ISO 42001 and NIST AI RMF are not that code and do not discharge Article 9.9 September 2026

Risk-lifecycle example — not YOUR file

The table below is an example of how Article 9(2) describes an iterative lifecycle. It is not YOUR risk-management system. Walking the rows is not a determination that Article 9 binds YOU. Last verified 9 September 2026. Not legal advice.

Example lifecycle mapped to Article 9(2) (not YOUR RMS; not a filing; not legal advice)
Example stepWhat Article 9 saysKind of textWhat this page does not do
IdentifyArticle 9(2)(a): identification and analysis of known and reasonably foreseeable risks to health, safety or fundamental rights in intended purpose.Article 9(2)(a) of 2024/1689. Legal requirement, only if it applies.Does not identify YOUR risks. Does not classify YOUR system as high-risk.
Estimate under intended use and reasonably foreseeable misuseArticle 9(2)(b): estimation and evaluation of risks in intended purpose and under reasonably foreseeable misuse.Article 9(2)(b) of 2024/1689. Legal requirement, only if it applies.Does not estimate YOUR residual risk.
Feed post-market data back inArticle 9(2)(c): evaluation of other risks from the Article 72 post-market monitoring system. Article 9(2) chapeau requires regular systematic review and updating.Articles 9(2) and 72 of 2024/1689. Legal requirement, only if it applies.Does not run YOUR Article 72 monitoring.
Treat, then judge residual riskArticle 9(2)(d) and Article 9(5): adopt targeted measures; residual risk per hazard and overall residual risk judged acceptable; eliminate or reduce as far as technically feasible; mitigate what cannot be eliminated; inform deployers under Article 13.Articles 9(2)(d), 9(5) and 13 of 2024/1689. Legal requirement, only if it applies.Does not judge YOUR residual risk acceptable.
Test before placing on the marketArticles 9(6) and 9(8): test throughout development and, in any event, prior to placing on the market or putting into service, against prior defined metrics and probabilistic thresholds.Articles 9(6) and 9(8) of 2024/1689. Legal requirement, only if it applies.Does not run YOUR tests. A dedicated model-evaluation-requirements guide is not on this site yet. Naming it is not a link.

ISO/IEC 42001 and ISO/IEC 23894 do not discharge Article 9

ISO/IEC 42001:2023 is the international standard for an AI management system. It is a standard, not Regulation (EU) 2024/1689. ISO/IEC 23894:2023 is guidance on AI risk management, intended to be used with ISO 31000:2018. It is guidance, not a certifiable substitute for Article 9. Running an ISO 42001 programme, citing ISO 23894, or holding an ISO 42001 certificate is not a determination that Article 9 is met. Last verified 9 September 2026. Not legal advice.

The ISO 42001 framework guide on this site is the education page under frameworks. An ISO 42001 versus EU AI Act comparison is not on this site yet. Naming it is not a link.

ISO/IEC 42001:2023 and ISO/IEC 23894:2023 as standard and guidance (not the Act; not a legal substitute; not legal advice)
TextWhat it isKind of textLast verified
ISO/IEC 42001:2023Specifies requirements for establishing, implementing, maintaining and continually improving an AI management system. It is certifiable by an accredited certification body. That is a standard's certification cycle, not an AI Act conformity assessment and not an Article 9 RMS determination.ISO/IEC 42001:2023. Best practice / standard, not a legal substitute for the Act. Does not discharge Article 9.9 September 2026
ISO/IEC 23894:2023Information technology — Artificial intelligence — Guidance on risk management. Guidance on how organisations that develop, produce, deploy or use AI can manage AI-related risk. Intended to be used with ISO 31000:2018. It is guidance, not a certifiable management-system standard, and not Regulation (EU) 2024/1689.ISO/IEC 23894:2023. Guidance, not a legal substitute for Article 9. Does not discharge Article 9.9 September 2026
Article 9 of 2024/1689 — distinct legal RMSA risk management system shall be established, implemented, documented and maintained in relation to high-risk AI systems. An ISO 42001 certificate does not discharge Article 9. Citing ISO 23894 does not discharge Article 9.Article 9 of 2024/1689. Legal requirement, only if it applies.9 September 2026

NIST AI RMF is guidance, not law

NIST AI 100-1, Artificial Intelligence Risk Management Framework (AI RMF 1.0), January 2023, is US National Institute of Standards and Technology guidance. It is voluntary. It organises work under Govern, Map, Measure, and Manage. It is not Regulation (EU) 2024/1689. It is not ISO/IEC 42001:2023. Mapping a Govern, Map, Measure, or Manage function is not a finding that Article 9 is met. NIST AI RMF does not discharge Article 9. Last verified 9 September 2026. Not legal advice.

Legal requirement versus standard versus ShipReady recommendation

The table below labels each text. Do not treat a standard as the article, do not treat guidance as the article, and do not treat a product surface as a determination. Last verified 9 September 2026. Not legal advice.

Statute versus standard versus guidance versus product (not a ranking; not legal advice; last verified 9 September 2026)
TextWhat it isWhat this page does not do
Regulation (EU) 2024/1689 Article 9Legal requirement — high-risk AI risk-management system, only if Article 6 high-risk applies. Article 9 sits in Chapter III Section 2. Annex I corresponding obligations on 2 August 2027 under Article 113(c).Does not determine that Article 9 binds YOU. Does not invent a 2 August 2026 date for Annex I. Does not run YOUR RMS.
Regulation (EU) 2024/1689 Article 55Legal requirement — extra duties for GPAI models with systemic risk, only if Article 51 applies. In force 2 August 2025 under Article 113(b), except Article 101. Distinct from Article 9.Does not designate YOUR model. Does not conflate Article 55 with Article 9. Does not invent a 2 August 2026 start date for GPAI.
Regulation (EU) 2026/1744 — Digital Omnibus on AIAn amending regulation. Counsel reads the authentic operative article of any amendment.Does not treat an amending-regulation recital as moving original Article 113(c) Annex I off 2 August 2027, or as rewriting Article 113(b) for Chapter V.
ISO/IEC 42001:2023Best practice / standard. An AI management system standard. Not a legal substitute for the Act.Does not treat an ISO 42001 certificate as discharging Article 9 or Article 55.
ISO/IEC 23894:2023Guidance on AI risk management, used with ISO 31000:2018. Not a certifiable substitute for Article 9.Does not treat an ISO 23894 citation as discharging Article 9.
NIST AI RMF 1.0 (NIST AI 100-1, January 2023)Guidance, not law. Voluntary US agency framework (Govern, Map, Measure, Manage).Does not treat a Govern/Map/Measure/Manage function as discharging Article 9.
European Commission AI Act page and AI Office materialsCommission materials. Guidance, not the regulation.Does not treat a Commission page as rewriting Article 9, Article 55, or Article 113.
This product's AI risk registerShipReady recommendation: a register the organisation recorded on the AI-governance surface. Not a legal determination.Does not discharge Article 9. Does not run Article 9 for you. A named human still owns the assessment.

What to do now

As of last verification on 9 September 2026, Article 55 GPAI systemic-risk duties have applied since 2 August 2025 under Article 113(b), except Article 101. High-risk Chapter III Section 2 duties, including Article 9, sit on the original 2 August 2026 residual, except Article 6(1) corresponding obligations on 2 August 2027 under Article 113(c). High-risk RMS duties did not start on 2 August 2026 for Annex I. The list below is operational preparation. It is not a determination that YOU have to run an Article 9 risk-management system. Walk it with counsel.

  • Ask counsel whether Article 6 high-risk applies to YOUR system. This page does not run that test. Marking eu_ai_act in an obligation map is not that determination and is not an RMS determination.
  • If counsel finds a high-risk AI system, walk Article 9 as written. Do not treat ISO/IEC 42001:2023, ISO/IEC 23894:2023, or NIST AI RMF 1.0 as discharging Article 9. This product does not run Article 9 for you.
  • If counsel finds a GPAI model with systemic risk under Article 51, walk Article 55. That is a different track from Article 9. Do not date those duties from 2 August 2026. Article 113(b) is 2 August 2025. The GPAI-systemic-risk guide on this site is the Article 51–55 page.
  • The EU AI Act overview on this site is the pillar page. The requirements-in-force-2026 guide on this site is the Article 113 dates page. The AI-governance-requirements guide on this site is the Articles 4, 14, 26 and ISO 42001 page. A dedicated model-evaluation-requirements, AI-ownership-accountability, and how-shipreadymetrics-tracks-ai-risk guide is not on this site yet. Naming them is not a link.

Checklist

This is a question list, not a determination that YOU have to run an Article 9 RMS, and not a filing. Walk it with counsel. The EU AI Act overview on this site is the pillar page.

  • Does the Act apply to YOU at all? Articles 2 and 3. This page does not run that test.
  • Does Article 6 high-risk apply? Article 9 is a legal requirement only if it does. This page does not classify YOUR system.
  • If high-risk, which Article 9 points, if any? This page does not pick YOUR points and does not run YOUR RMS.
  • Does Article 51 systemic-risk apply? Article 55 is a different track. This page does not designate YOUR model.
  • Does ISO/IEC 42001:2023 or NIST AI RMF 1.0 discharge Article 9? No. They are a standard and guidance, not a legal substitute.
  • Did high-risk RMS duties start 2 August 2026 for Annex I? No. Article 113(c) is 2 August 2027, not 2026.
  • Document the assessment, including a not-in-scope and not-an-RMS-required decision. This page does not keep YOUR file.

Where this shows up in ShipReady Metrics

The bundled framework key eu_ai_act is customer-visible. Its version label is Regulation (EU) 2024/1689 high-risk obligations (starter subset). It is not in INTERNAL_TESTER_ONLY_FRAMEWORKS. The control-set is a starter subset, illustrative, to be tailored by a compliance owner; not legal advice; not a conformity determination; not CE marking. Readiness is not compliance and not an EU-database registration.

If you already have a session: signed-in app → Compliance → AI governance holds the AI inventory and AI-governance posture. The AI risk register lives with that AI-governance surface. That register does not determine that YOU have to run an Article 9 risk-management system, does not discharge Article 9 or Article 55, and does not file with the AI Office or a market-surveillance authority. Marking in-scope is not an RMS determination and not auto-filing. A named human still owns the assessment.

This product does not run an Article 9 risk-management system for you, does not judge residual risk acceptable, does not run Article 55 model evaluation or Union-level systemic-risk assessment, does not file with the AI Office, and does not issue certifications. The obligation map lists frameworks the organisation has marked in-scope, including eu_ai_act if that mark is set. Marking eu_ai_act in-scope is not a determination that you have to run an RMS.

This page does not document a public demo URL. There is no public EU AI Act demo path. This product does not start a clock.

Primary sources (last verified 9 September 2026)

Every regulatory or guidance claim on this page is taken from one of these. If a later revision of a source changes the rule, the date above is how you can see we have not re-checked yet.

Regulation (EU) 2024/1689 of 13 June 2024 (Artificial Intelligence Act), Articles 6, 8, 9, 16, 51, 55 and 113, is a legal requirement only if it applies. Entry into force 1 August 2024. Article 113(a) 2 February 2025; Article 113(b) 2 August 2025; general application 2 August 2026; Article 113(c) Article 6(1) from 2 August 2027. Regulation (EU) 2026/1744 is an amending regulation. ISO/IEC 42001:2023 is a management-system standard, not the regulation. ISO/IEC 23894:2023 is guidance on AI risk management, not the regulation. NIST AI RMF 1.0 (NIST AI 100-1, January 2023) is guidance, not law. The European Commission's AI Act page is Commission material, not the regulation. These are not a complete world list. Not legal advice.

The EU AI Act overview on this site is the pillar page. The requirements-in-force-2026 guide on this site is the Article 113 dates page. The GPAI-requirements guide on this site is the Article 53 baseline page. The GPAI-systemic-risk guide on this site is the Article 51–55 page. The provider-vs-deployer guide on this site is the Articles 3, 16, 25 and 26 page. The AI-governance-requirements guide on this site is the Articles 4, 14, 26 and ISO 42001 page. The EU AI Act framework guide on this site is the education page under frameworks. The ISO 42001 framework guide on this site is live. A dedicated model-evaluation-requirements, AI-ownership-accountability, and how-shipreadymetrics-tracks-ai-risk guide is not on this site yet. Naming them is not a link.

Frequently asked questions

Is this legal advice?

No. It is a dated map of AI risk-management duties distilled from Regulation (EU) 2024/1689 Articles 9 and 55, with ISO/IEC 42001:2023 labelled as a standard, ISO/IEC 23894:2023 labelled as guidance, and NIST AI RMF labelled as guidance, not the regulation. Whether those articles apply to YOU, and whether YOU have to run an Article 9 risk-management system, is a legal question for counsel on your facts. This page does not start a clock and does not file with the AI Office.

Does this page determine that Art. 9 binds us?

No. This page does not determine that Article 9 binds YOU. Mapping a row is not a finding that the Act applies, that YOUR system is high-risk under Article 6, or that YOU have to run an Article 9 risk-management system. Counsel applies Article 9 to YOUR facts. Last verified 9 September 2026.

Does ISO 42001 or NIST AI RMF discharge Art. 9?

No. ISO/IEC 42001:2023 is a voluntary management-system standard. ISO/IEC 23894:2023 is guidance. NIST AI RMF 1.0 is voluntary US agency guidance. The AI Act is Regulation (EU) 2024/1689. Running an ISO 42001 programme, citing ISO 23894, or mapping a NIST Govern/Map/Measure/Manage function is not a determination that Article 9 is met. An ISO 42001 certificate is not CE marking and not an Article 9 RMS. Last verified 9 September 2026.

Did high-risk RMS duties start 2 August 2026 for Annex I?

No. Article 113(c) of Regulation (EU) 2024/1689 applies Article 6(1) and the corresponding obligations from 2 August 2027. That is the Annex I product-embedded high-risk date. It is not 2 August 2026. This page does not invent a 2 August 2026 date for Annex I. Last verified 9 September 2026.

Is Article 55 the same as Article 9?

No. Article 9 is a risk-management system for high-risk AI systems, only if Article 6 high-risk applies. Article 55 is extra duties for providers of general-purpose AI models with systemic risk, only if Article 51 applies, in force 2 August 2025 via Article 113(b). Do not conflate them. This page does not designate YOUR model and does not determine that Article 9 binds YOU.

Does marking eu_ai_act in-scope mean we run an RMS?

No. Marking the bundled framework key eu_ai_act in-scope on the obligation map is not a determination that you have to run an Article 9 risk-management system, is not a finding that Article 9 or Article 55 applies, and is not auto-filing. Counsel applies those articles to YOUR facts. A named human still owns the assessment.

Does ShipReady run Article 9 for you?

No. Signed-in app → Compliance → AI governance holds the AI inventory and the AI risk register the organisation recorded. That surface does not run an Article 9 risk-management system, does not judge residual risk acceptable, and does not discharge Article 9 or Article 55. This product does not file with the AI Office. A named human still owns the assessment.

Published by ShipReady Metrics, an evidence-based technology and compliance intelligence platform. This guide is educational and vendor-neutral.