EUAIACTUS.COM

System-level risk review

AI risk assessment for EU AI Act and GDPR governance

A defensible AI risk assessment connects intended purpose, affected persons, EU AI Act classification, GDPR/data-protection questions, model and vendor dependencies, potential harms, controls and evidence across the system lifecycle.

A service provided by Lexara Advisory LLC · Reviewed by Constantin Razvan Gospodin.

Direct answer

What should an AI risk assessment include?

At minimum: the system and intended purpose, affected people, jurisdictions, actor roles, legal classification, data and model dependencies, foreseeable harms, existing controls, residual gaps, owners, review triggers and the evidence supporting each conclusion. A GDPR DPIA can overlap factually but is not the same legal assessment.

Assessment dimensions

Risk is broader than model accuracy.

Intended purpose & context

What the system is designed to do, who uses it, which decisions it supports and what happens when it is wrong or misused.

Fundamental-rights exposure

Potential effects on equality, privacy/data protection, access to services, employment, education, expression and other affected rights depending on the use case.

Transparency & explainability

Whether people know AI is involved, whether system limitations are communicated and whether Article 50 or other information obligations are triggered.

Human oversight

Whether people can understand, challenge, override or stop the system and whether oversight is meaningful rather than nominal.

Data & performance

Data provenance/quality, relevant bias and error modes, performance limitations, testing and monitoring in the actual operating context.

Vendor/model dependency

Documentation gaps, upstream model changes, contract limitations, incident interfaces, geographic processing and evidence available from third parties.

Article 9 distinction

Does every AI system require an Article 9 risk management system?

No. Article 9 of the EU AI Act requires a risk management system specifically for high-risk AI systems. That system must be established, implemented, documented and maintained as a continuous iterative lifecycle process. A broader organisational AI risk assessment can still be useful for non-high-risk systems, but it should not be described as an Article 9 obligation unless the legal high-risk conditions are met.

Legal classification

Risk assessment and EU AI Act classification are related but not identical.

A system can have meaningful operational or fundamental-rights risk without being classified as high-risk under Article 6. Conversely, a system that meets the statutory high-risk criteria must satisfy the legal requirements even if an internal risk score is low.

Legal test

Apply Articles 5, 6, 50, GPAI provisions and other applicable actor-specific rules.

Operational risk

Assess system-specific harm, likelihood, severity, controllability, affected populations and organisational exposure.

Outputs

What a defensible assessment should produce

  • System and intended-purpose description.
  • EU AI Act scope/role/classification record.
  • Risk scenarios and affected persons/groups.
  • Existing controls and evidence.
  • Residual-risk and material-gap analysis.
  • Actions, owners, deadlines and review triggers.
  • Vendor/model evidence requests where necessary.

Lifecycle

Risk assessment must change when the system changes.

Reassessment triggers can include model replacement, new intended purpose, new jurisdiction, material performance changes, new affected population, incident, vendor change or regulatory update.

Frequently asked

AI risk-assessment questions

What is an AI risk assessment?

It is a system-level review of intended purpose, affected persons, legal classification, data and model dependencies, potential harms, controls, evidence and lifecycle risks.

Is a GDPR DPIA the same as an EU AI Act risk assessment?

No. A DPIA and EU AI Act risk/classification work can reuse factual evidence, but they apply different legal tests and should record separate conclusions.

EU AI Act + GDPR governance →

Does every AI system require an Article 9 risk management system?

No. Article 9 applies to high-risk AI systems. Broader AI risk assessment can be a governance practice for other systems, but it is not automatically an Article 9 legal requirement.

Assess the system you actually operate.