← All guides

High-risk duties

The seven requirements for high-risk systems (Articles 9–15)

Risk management, data governance, documentation, logging, transparency, human oversight, and accuracy — the seven essential requirements a high-risk system must satisfy, in plain terms.

Updated 3 July 2026 · Reference material, not legal advice


If your system is high-risk, its provider must design and build it to satisfy seven essential requirements set out in Articles 9 to 15. Each is a genuine engineering and documentation obligation, not a box to tick.

1. Risk-management system (Article 9)

A continuous, iterative process across the whole lifecycle: identify and analyse known and foreseeable risks, estimate risks in intended use and reasonably foreseeable misuse, weigh post-market data, and adopt targeted measures. Residual risk must be judged acceptable. Systems are tested against pre-defined metrics before market placement, with particular attention to minors and vulnerable groups.

2. Data and data governance (Article 10)

Training, validation and testing data must be relevant, sufficiently representative and — to the extent possible — free of errors and complete. Providers examine datasets for bias and take measures to detect and mitigate it. Special-category data may be processed to correct bias only under strict, documented conditions.

3. Technical documentation (Article 11)

Drawn up before market placement and kept current, following Annex IV, to demonstrate conformity to authorities. (See the dedicated guide on technical documentation.)

4. Record-keeping / logging (Article 12)

The system automatically logs events over its lifetime, for traceability, post-market monitoring and the detection of risks or substantial modifications. Biometric identification systems have specific minimum log fields.

5. Transparency and instructions for use (Article 13)

The system is transparent enough for a deployer to interpret and use its output correctly, and comes with clear instructions covering its purpose, performance, known limitations, oversight measures and maintenance.

6. Human oversight (Article 14)

The system is designed so that people can effectively oversee it — understanding its capabilities and limits, staying alert to automation bias, correctly interpreting output, and being able to disregard, override or stop it. Biometric identification requires verification by at least two competent people.

7. Accuracy, robustness and cybersecurity (Article 15)

An appropriate and consistent level of accuracy (declared in the instructions), resilience to errors through redundancy and fail-safes, control of feedback loops in systems that keep learning, and resilience to attacks such as data or model poisoning and adversarial examples.

What this means in practice

These seven requirements become a concrete programme of work with owners, evidence and sign-offs. Euridium maps each to its article, its “compliant-if” test and the evidence expected, so nothing is left implicit.

See where your own AI systems stand.

Run a guided assessment and get the obligations that apply to your role.

Open the platform

This guide is a plain-language summary for orientation. The authoritative text is Regulation (EU) 2024/1689 as published in the Official Journal of the European Union (12 July 2024). It does not constitute legal advice.