Back to glossary

AI risk assessment

YZ risk değerlendirmesi

D5

AI risk assessment is the context-specific process of identifying, analyzing, prioritizing, and documenting potential AI-related harms and uncertainties for affected people and organizations.

Review status: 2027-02-24

Technical explanation

It informs proportionate choices about controls, monitoring, and responsibilities for a stated system and use context.

Conceptual boundaries

It is not a one-time checklist, a universal numerical score, or a complete risk-management program.

Provider-neutral example

Before piloting an AI triage tool, a team can document who may be affected, foreseeable misuse, error consequences, available evidence, and escalation controls.

Limitations

A documented assessment remains dependent on its stated context, evidence, assumptions, and later changes in the system or use.

Related concepts

Atomic claims and evidence

  1. 1.1NIST AI 100-1, Artificial Intelligence Risk Management Framework (AI RMF 1.0) — D5 governance and security slice
    Source
    NIST AI 100-1, Artificial Intelligence Risk Management Framework (AI RMF 1.0) — D5 governance and security slice
    Source role
    Authoritative source
    Exact locator
    Section 5 and Sections 5.2-5.4, printed pp. 20 and 24-32
    Supported claim
    NIST frames AI risk management around context, intended use, impacts, and the mapping, measuring, and managing of risks over the AI lifecycle.
    Last verification
    Review due
    Scope limitation
    This describes a framework approach; it does not prescribe one score or one fixed assessment sequence for every system.
    1.2OECD AI Principles
    Source
    OECD AI Principles
    Source role
    Authoritative source
    Exact locator
    Accountability
    Supported claim
    NIST frames AI risk management around context, intended use, impacts, and the mapping, measuring, and managing of risks over the AI lifecycle.
    Last verification
    Review due
    Scope limitation
    This describes a framework approach; it does not prescribe one score or one fixed assessment sequence for every system.
  2. 2.1Regulation (EU) 2024/1689 (Artificial Intelligence Act), consolidated text of 27 July 2026 — D5 instrument slice
    Source
    Regulation (EU) 2024/1689 (Artificial Intelligence Act), consolidated text of 27 July 2026 — D5 instrument slice
    Source role
    Authoritative source
    Exact locator
    Article 9(1)-(2), consolidated text of 27 July 2026
    Supported claim
    For high-risk AI systems within its scope, the EU AI Act requires an iterative risk-management system throughout the lifecycle.
    Last verification
    Review due
    Scope limitation
    This is an instrument-specific EU requirement for high-risk systems, not a universal requirement for every AI use.
    2.2OECD AI Principles
    Source
    OECD AI Principles
    Source role
    Authoritative source
    Exact locator
    Accountability
    Supported claim
    For high-risk AI systems within its scope, the EU AI Act requires an iterative risk-management system throughout the lifecycle.
    Last verification
    Review due
    Scope limitation
    This is an instrument-specific EU requirement for high-risk systems, not a universal requirement for every AI use.
    2.3European Commission AI Act Service Desk, Article 9: Risk management system
    Source
    European Commission AI Act Service Desk, Article 9: Risk management system
    Source role
    Supplementary source
    Exact locator
    Article 9(1)-(2), non-binding summary and 13 June 2024 official-version reference
    Supported claim
    For high-risk AI systems within its scope, the EU AI Act requires an iterative risk-management system throughout the lifecycle.
    Last verification
    Review due
    Scope limitation
    This is an instrument-specific EU requirement for high-risk systems, not a universal requirement for every AI use.