AI risk management: AI obligations

Practical requirements extracted from policy instruments, with the source article, the actors they bind, evidence examples and original framework mappings. Legal requirements are marked; everything else is voluntary guidance.

5 results

Legal requirement risk management United States

Apply minimum risk-management practices to high-impact AI

OMB M-25-21 · Section 4

For AI whose output serves as a principal basis for decisions with significant effects on rights, safety or access to services, agencies must complete pre-deployment testing, an AI impact assessment, ongoing monitoring, operator training, human oversight and a mechanism for affected people to seek remedy, or stop using the AI.

Source-linked
Legal requirement risk management Colorado (United States)

Deployers must implement a risk management policy and programme

Colorado AI Act · C.R.S. 6-1-1703(2)

Deployers of high-risk AI must implement a risk-management policy and programme governing deployment, specifying principles, processes and personnel used to identify, document and mitigate known or reasonably foreseeable risks of algorithmic discrimination, and reasonable in light of recognised frameworks such as the NIST AI RMF or ISO/IEC 42001.

Source-linked Applies from 30 Jun 2026
Legal requirement risk management European Union

Establish a risk management system for high-risk AI

EU AI Act · Article 9

Providers of high-risk AI systems must establish, implement, document and maintain a continuous, iterative risk-management system across the system's lifecycle: identifying known and reasonably foreseeable risks to health, safety and fundamental rights, estimating and evaluating risks including from reasonably foreseeable misuse, evaluating post-market data, and adopting targeted risk-management measures, with testing before placing on the market.

Source-linked Applies from 2 Aug 2026
Search