Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.
How does ShipReady Metrics track AI risk?
Updated
The AI risk register lists AI-specific risks an Article 9 or ISO 42001 assessment would consider, and shows whether the governance obligations that mitigate each are met across the registered high-risk inventory. Where nothing is covered it reads not verified. Not legal advice.
ShipReady Metrics AI risk tracking, last verified 10 September 2026 against Articles 9, 15, 43, 51, 55, 72 and 113 of Regulation (EU) 2024/1689 (OJ L 2024/1689, 12.7.2024) for the duties being mapped. ISO/IEC 42001:2023 is a management-system standard, not the regulation. NIST AI RMF 1.0 is guidance, not law. This page is not legal advice, not a filing, and does not start a clock. It does not determine that the Act applies to YOU, that YOU are a provider or a deployer, that YOUR system is high-risk, or that YOUR model has systemic risk. A register entry is not an Article 9 risk-management system.
This is a register over your own inventory, not an Article 9 system
Audience: a risk owner, CISO, or compliance lead who wants to know what the AI risk register does before relying on it. This page is not legal advice. It does not start a clock. Nothing here is a determination that the Act applies, that YOU are a provider or a deployer, that YOUR system is high-risk, or that YOUR model has systemic risk.
The path is: signed-in app → Compliance → AI governance. The AI risk register lives beside the AI inventory there. It is not the cyber risk register, which lives under Security and covers a different population of risks. Article 9 of Regulation (EU) 2024/1689 requires a risk management system established, implemented, documented and maintained as a continuous iterative process throughout the entire lifecycle of a high-risk AI system, requiring regular systematic review and updating — only if that article applies. A register is one artefact inside such a system; it is not the system. Last verified 10 September 2026. Not legal advice.
- Four kinds of text appear here, and they are labelled: legal requirements of 2024/1689 (only if they apply); Commission and AI Office materials, which are guidance, not the regulation; ISO/IEC 42001:2023 and NIST AI RMF 1.0, a standard and guidance respectively, not law; and ShipReadyMetrics capability, which describes shipped behaviour and never a legal determination.
- Article 9 and Article 55 are different tracks. Article 9 is the high-risk risk-management system, and it applies only if Article 6 puts a system in that category. Article 55 is the systemic-risk general-purpose-model track in Chapter V, applied from 2 August 2025 by Article 113(b), except Article 101. Mapping a register row to both does not merge them.
- The AI-risk-management-requirements guide on this site is the vendor-neutral Articles 9 and 55 page. The how-shipreadymetrics-supports-ai-governance guide on this site is the wider product map. A dedicated model-evaluation-requirements guide and a dedicated AI-cybersecurity-requirements guide are not on this site yet. Naming them is not a link.
How the register decides what to say
The register does not ask you to score every risk from scratch. It carries a library of AI-specific risks, each tied to the EU AI Act reference it relates to, and then reads your own inventory to decide what it can honestly say about each one. Last verified 10 September 2026. Not legal advice.
| Element | Behaviour as shipped | What it is not | Kind of text |
|---|---|---|---|
| The risk library | AI-specific risks an Article 9 or ISO/IEC 42001:2023 assessment would have to consider, each labelled with the EU AI Act reference it relates to. | Not an exhaustive list of your risks, and not a determination that any of them are present in your systems. | ShipReadyMetrics capability, informed by Article 9 of 2024/1689 (legal requirement, only if it applies) and ISO/IEC 42001:2023 (a standard). |
| Status per risk: mitigated, open gap, or not verified | A risk reads mitigated when the governance obligations that would address it are met across the registered high-risk systems; open gap when they are not; not verified when there is no coverage to assess. | Not a legal finding that a risk has been managed, and never a fabricated mitigation. Not verified means nothing was assessed, not that nothing is wrong. | ShipReadyMetrics capability. |
| The subject set | Systems the organisation declared high-risk. A system declared at a lower tier is not a subject, so it can neither inflate coverage nor dilute a gap. | Not a classification under Article 6. If the declared population is wrong, the register's arithmetic is honest about the wrong population — which is why the under-declaration flag on the inventory matters. | ShipReadyMetrics capability, informed by Article 6 of 2024/1689 (legal requirement, only if it applies). |
| Priority action | Where several open risks share a single missing obligation, the register names that obligation and how many risks completing it would close. | Not advice about what to do first in your organisation, and not a claim that closing it discharges anything. | ShipReadyMetrics capability. |
| Empty-inventory behaviour | With no registered high-risk systems, every obligation reads not verified and no gap reminder is raised. | Not a pass. Nothing to assess is reported as nothing to assess, in both directions: a fabricated gap is as dishonest as a fabricated pass. | ShipReadyMetrics capability. |
| Conformity-review cadence and substantial modification | A recorded review date reads as current, due, or overdue; a modification recorded after the last review reads as a re-assessment being due; no date at all reads as not tracked. | Not an Article 43 conformity assessment and not a fabricated overdue. | ShipReadyMetrics capability, informed by Article 43 of 2024/1689 (legal requirement, only if it applies). |
Example risk entry
One worked row, so that the shape is concrete. It is an illustration of the register's behaviour, not a finding about any organisation and not a determination that this risk is present in YOUR systems. Last verified 10 September 2026. Not legal advice.
| Part of the entry | Example content | Kind of text |
|---|---|---|
| Risk title | Human overseers cannot intervene quickly enough when a high-risk system produces an anomalous output. | ShipReadyMetrics capability — a library row, not a finding. |
| EU AI Act reference shown on the row | Article 14 human oversight, inside the Article 9 risk-management process. | Articles 9 and 14 of 2024/1689. Legal requirements, only if they apply. |
| What the register reads to set a status | Whether the human-oversight artefact is recorded across the systems the organisation declared high-risk. | ShipReadyMetrics capability. Reading a boolean is not reading an oversight design. |
| Status when two of five declared high-risk systems carry that artefact | Open gap, with the count shown rather than a score. | ShipReadyMetrics capability. Not a legal finding that Article 14 is breached. |
| Status when no system is declared high-risk | Not verified — nothing is in scope to assess. | ShipReadyMetrics capability. Never a fabricated pass. |
| What closing the gap means | That the organisation recorded the missing artefact. Someone still has to have designed oversight that works, and a named human still owns that judgement. | ShipReadyMetrics capability. Not a conformity determination and not legal advice. |
Article 9 and Article 55 — mapped, not discharged
The register is aligned to these duties so that the work has a shape a compliance owner recognises. Alignment is not discharge, and a mapped row does not make a legal requirement true. Last verified 10 September 2026. Not legal advice.
| Duty | What the cited text is | What the register does | Kind of text |
|---|---|---|---|
| Article 9 of 2024/1689 — the high-risk risk-management system | A risk management system shall be established, implemented, documented and maintained in relation to high-risk AI systems, as a continuous iterative process planned and run throughout the entire lifecycle, requiring regular systematic review and updating. Article 9(6) and 9(8) speak to testing against preliminarily defined metrics and probabilistic thresholds. | Holds a risk library and coverage status over declared high-risk systems, and records review dates. It does not run the process, does not do the testing, and does not maintain the system for you. | Article 9 of 2024/1689. Legal requirement, only if it applies. The AI-risk-management-requirements guide on this site is that page. |
| Article 55 of 2024/1689 — systemic-risk GPAI | Providers of general-purpose AI models with systemic risk owe additional duties, including evaluation, systemic-risk assessment and mitigation, cybersecurity protection, and serious-incident reporting to the AI Office without undue delay under Article 55(1)(c). Chapter V applies from 2 August 2025 under Article 113(b), except Article 101. | Records the organisation's own GPAI and systemic-risk flags and whether Article 53 documentation and Article 55 safeguards are asserted. It does not evaluate a model, does not designate systemic risk, and does not file with the AI Office. | Article 55 of 2024/1689. Legal requirement, only if it applies. A dedicated model-evaluation-requirements guide is not on this site yet. Naming it is not a link. |
| Article 15 of 2024/1689 — accuracy, robustness and cybersecurity | High-risk AI systems shall be designed and developed to achieve an appropriate level of accuracy, robustness and cybersecurity, and to perform consistently in those respects throughout their lifecycle. | Surfaces whether the related artefacts are recorded. It does not measure accuracy, does not test robustness, and does not certify cybersecurity. | Article 15 of 2024/1689. Legal requirement, only if it applies. A dedicated AI-cybersecurity-requirements guide is not on this site yet. Naming it is not a link. |
| ISO/IEC 42001:2023 risk and impact practice | The standard asks an organisation to assess risks and impacts of AI systems and to treat them as part of a management system. | Gives that practice somewhere to live, dated and owned. It does not certify anything. | ISO/IEC 42001:2023. Best practice / standard, not a legal substitute for the Act. |
| NIST AI RMF 1.0 Measure and Manage functions | NIST AI 100-1, January 2023. Voluntary US agency guidance on measuring and managing AI risk. | Nothing directly. It is named here as context, because it is often cited alongside Article 9 as if it were law. | Guidance, not law. Not Regulation (EU) 2024/1689 and not ISO/IEC 42001:2023. |
Honest limits
These are properties of the register as shipped. Last verified 10 September 2026. Not legal advice.
- It grades coverage, not quality. Whether an oversight design actually works, or a risk assessment was any good, is a human judgement it does not make.
- It reads declarations. If the inventory's declared tiers are wrong, the register is honestly arithmetic over the wrong subject set.
- It does not score residual risk on a numeric scale, because a number computed from booleans would look more precise than the facts underneath it.
- It does not evaluate models, run red-team exercises, or test accuracy. Those are separate activities with their own evidence.
- It does not designate a model as having systemic risk under Article 51, and does not file anything with the AI Office under Article 55(1)(c).
- It is not the cyber risk register. That one lives under Security and covers a different population.
- It is not an Article 9 risk-management system, and completing every row is not compliance with Article 9.
What to do now
As of last verification on 10 September 2026, Article 9 sits on the Article 113 residual application of 2 August 2026, with Article 113(c) keeping Article 6(1) and the corresponding obligations on 2 August 2027, and Chapter V — including Article 55 — has applied since 2 August 2025 under Article 113(b), except Article 101. The list below is operational preparation, not a determination that any of it binds YOU.
- Settle the inventory's declared tiers before reading the register's percentages of anything. The subject set is what the whole surface rests on.
- Treat not verified as a task, not as a clean result. It means nothing was assessed.
- Use the priority action as a scheduling hint, not as advice. It names the obligation that would close the most open rows; it does not know your constraints.
- Keep the Article 9 work and the Article 55 work in separate documents. They have different subjects, different parties, and different dates.
- The AI-risk-management-requirements guide on this site is the vendor-neutral Articles 9 and 55 page. The how-shipreadymetrics-produces-ai-governance-evidence guide on this site is the evidence page. A dedicated model-evaluation-requirements and AI-cybersecurity-requirements guide is not on this site yet. Naming them is not a link.
Checklist
This is a question list, not a determination that Article 9 or Article 55 binds YOU. Walk the legal questions with counsel.
- Does the Act apply to YOU at all? Articles 2 and 3. This page does not run that test.
- Are the declared high-risk systems in your inventory the right ones? Everything the register says is scoped to them.
- Does a mitigated status mean the risk is managed in law? No. It means the obligations that relate to it are recorded as met across the declared subjects.
- Does not verified mean there is no risk? No. It means nothing was in scope to assess.
- Is the register an Article 9 risk-management system? No. Article 9 requires a continuous, documented, maintained process across the lifecycle; a register is one artefact inside that.
- Does the register evaluate models or designate systemic risk? No. It records the organisation's own flags and does not file with the AI Office.
- Is the AI risk register the same as the cyber risk register? No. The cyber risk register lives under Security.
- Document the assessment, including which library risks you judged inapplicable and why. This page does not keep YOUR file.
Where this shows up in ShipReady Metrics
The bundled framework key eu_ai_act is customer-visible. Its version label is Regulation (EU) 2024/1689 high-risk obligations (starter subset). The control-set is a starter subset, illustrative, to be tailored by a compliance owner; not legal advice; not a conformity determination; not CE marking. Readiness is not compliance and not an EU-database registration.
If you already have a session: signed-in app → Compliance → AI governance holds the AI inventory and the AI risk register, including the per-risk status and the priority action. Marking in-scope is not applicability. A named human still owns the assessment.
This product does not file with the AI Office, does not register in the EU database, does not issue certifications, does not affix CE marks, and is not a notified body. The obligation map lists frameworks the organisation has marked in-scope. The cyber risk register lives under Security and is a different register from the AI risk register.
This page does not document a public demo URL. There is no public EU AI Act demo path. This product does not start a clock.
Primary sources (last verified 10 September 2026)
Every regulatory or guidance claim on this page is taken from one of these. Product claims describe shipped behaviour. If a later revision of a source changes the rule, the date above is how you can see we have not re-checked yet.
Regulation (EU) 2024/1689 of 13 June 2024 (Artificial Intelligence Act), Articles 6, 9, 14, 15, 43, 51, 53, 55, 72 and 113, is a legal requirement only if it applies. Entry into force 1 August 2024. Article 113(a) 2 February 2025; Article 113(b) 2 August 2025 except Article 101; general application 2 August 2026; Article 113(c) Article 6(1) from 2 August 2027. ISO/IEC 42001:2023 is a management-system standard, not the regulation. NIST AI RMF 1.0 (NIST AI 100-1, January 2023) is guidance, not law. Commission AI Act pages and AI Office materials are Commission materials — guidance, not the regulation. These are not a complete world list. Not legal advice.
The EU AI Act overview on this site is the pillar page. The AI-risk-management-requirements guide on this site is the Articles 9 and 55 page. The GPAI-systemic-risk guide on this site is the Article 51–55 page. The how-shipreadymetrics-supports-ai-governance guide on this site is the product map. The how-shipreadymetrics-builds-ai-inventory guide on this site is the inventory page. A dedicated model-evaluation-requirements and AI-cybersecurity-requirements guide is not on this site yet. Naming them is not a link.
Frequently asked questions
Is this legal advice?
No. It is a dated description of how the AI risk register behaves, set beside Articles 9 and 55 of Regulation (EU) 2024/1689 and ISO/IEC 42001:2023, which is a standard, not the regulation. Whether those articles apply to YOU, and whether any risk is adequately managed, are legal questions for counsel on your facts. This page does not start a clock.
Is the AI risk register an Article 9 risk-management system?
No. Article 9 of Regulation (EU) 2024/1689 requires a risk management system established, implemented, documented and maintained as a continuous iterative process throughout the entire lifecycle of a high-risk AI system, with regular systematic review and updating. A register is one artefact inside such a process. Completing every row is not compliance with Article 9, and this product does not run the process for you.
Does a mitigated status mean the risk is legally managed?
No. A row reads mitigated when the governance obligations that relate to it are recorded as met across the systems the organisation declared high-risk. That is arithmetic over declarations. It is not a conformity determination, not a legal finding, and not a judgement about whether the underlying design actually works. A named human still owns that judgement.
Does the register cover Article 55 systemic-risk duties?
No. It records the organisation's own general-purpose-model and systemic-risk flags and whether Article 53 documentation and Article 55 safeguards are asserted. It does not evaluate a model, does not designate systemic risk under Article 51, and does not report serious incidents to the AI Office under Article 55(1)(c). Chapter V has applied since 2 August 2025 under Article 113(b), except Article 101 — a different date from the high-risk track.
Is this the same as the cyber risk register?
No. The AI risk register lives with the AI-governance surface under Compliance and is scoped to AI-specific risks across the declared high-risk AI inventory. The cyber risk register lives under Security and covers a different population of risks with different owners. Keeping them separate is deliberate: merging them would make both harder to read and neither easier to defend.
Published by ShipReady Metrics, an evidence-based technology and compliance intelligence platform. This guide is educational and vendor-neutral.