AI risk assessment
YZ risk değerlendirmesi
D5
AI risk assessment is the context-specific process of identifying, analyzing, prioritizing, and documenting potential AI-related harms and uncertainties for affected people and organizations.
Review status: 2027-02-24
Technical explanation
It informs proportionate choices about controls, monitoring, and responsibilities for a stated system and use context.
Conceptual boundaries
It is not a one-time checklist, a universal numerical score, or a complete risk-management program.
Provider-neutral example
Before piloting an AI triage tool, a team can document who may be affected, foreseeable misuse, error consequences, available evidence, and escalation controls.
Limitations
A documented assessment remains dependent on its stated context, evidence, assumptions, and later changes in the system or use.
Related concepts
Atomic claims and evidence
1.1NIST AI 100-1, Artificial Intelligence Risk Management Framework (AI RMF 1.0) — D5 governance and security slice
- Source
- NIST AI 100-1, Artificial Intelligence Risk Management Framework (AI RMF 1.0) — D5 governance and security slice
- Source role
- Authoritative source
- Exact locator
- Section 5 and Sections 5.2-5.4, printed pp. 20 and 24-32
- Supported claim
- NIST frames AI risk management around context, intended use, impacts, and the mapping, measuring, and managing of risks over the AI lifecycle.
- Last verification
- Review due
- Scope limitation
- This describes a framework approach; it does not prescribe one score or one fixed assessment sequence for every system.
1.2OECD AI Principles
- Source
- OECD AI Principles
- Source role
- Authoritative source
- Exact locator
- Accountability
- Supported claim
- NIST frames AI risk management around context, intended use, impacts, and the mapping, measuring, and managing of risks over the AI lifecycle.
- Last verification
- Review due
- Scope limitation
- This describes a framework approach; it does not prescribe one score or one fixed assessment sequence for every system.
2.1Regulation (EU) 2024/1689 (Artificial Intelligence Act), consolidated text of 27 July 2026 — D5 instrument slice
- Source
- Regulation (EU) 2024/1689 (Artificial Intelligence Act), consolidated text of 27 July 2026 — D5 instrument slice
- Source role
- Authoritative source
- Exact locator
- Article 9(1)-(2), consolidated text of 27 July 2026
- Supported claim
- For high-risk AI systems within its scope, the EU AI Act requires an iterative risk-management system throughout the lifecycle.
- Last verification
- Review due
- Scope limitation
- This is an instrument-specific EU requirement for high-risk systems, not a universal requirement for every AI use.
2.2OECD AI Principles
- Source
- OECD AI Principles
- Source role
- Authoritative source
- Exact locator
- Accountability
- Supported claim
- For high-risk AI systems within its scope, the EU AI Act requires an iterative risk-management system throughout the lifecycle.
- Last verification
- Review due
- Scope limitation
- This is an instrument-specific EU requirement for high-risk systems, not a universal requirement for every AI use.
2.3European Commission AI Act Service Desk, Article 9: Risk management system
- Source
- European Commission AI Act Service Desk, Article 9: Risk management system
- Source role
- Supplementary source
- Exact locator
- Article 9(1)-(2), non-binding summary and 13 June 2024 official-version reference
- Supported claim
- For high-risk AI systems within its scope, the EU AI Act requires an iterative risk-management system throughout the lifecycle.
- Last verification
- Review due
- Scope limitation
- This is an instrument-specific EU requirement for high-risk systems, not a universal requirement for every AI use.