AI risk library
Fourteen risks, each mapped to the article that addresses it. Not a generic taxonomy, these are the risks the Regulation actually names or implies, which makes them the ones an assessor will look for evidence against.
| Risk | Where the Regulation addresses it | Why it matters more than it looks |
|---|---|---|
| Discrimination & unfair outcomes Outputs that systematically disadvantage a group, whether or not intended | Art. 10 bias examination · Art. 9 fundamental rights risks · Art. 27 FRIA | An infringement of Union law protecting fundamental rights is a reportable serious incident under Art. 3(49) — no physical harm needed More → |
| Automation bias Reviewers deferring to output they were meant to check | Art. 14(4): named expressly in the Regulation | Measured by override rate. A rate near zero is a finding, not a comfort More → |
| Model drift Live performance departing from the declared figure | Art. 15 consistent performance · Art. 72 post-market monitoring | Drift is a route to non-conformity, not just an ops issue — you declared the number More → |
| Feedback loops The system's own outputs shaping its future training data | Art. 15, must be eliminated or reduced as far as possible, with mitigation | Catches ranking, recommendation, fraud scoring and triage, anything whose decisions become tomorrow's data More → |
| Data poisoning Manipulation of the training data set | Art. 15, named AI-specific vulnerability | One of five attack classes named in the Regulation; most ISMS control sets cover none of them More → |
| Model evasion Inputs crafted to make the model err | Art. 15, named AI-specific vulnerability | Adversarial examples. Not tested by a standard penetration test unless you ask More → |
| Confidentiality attacks Extracting training data or model parameters | Art. 15, named AI-specific vulnerability | Membership inference, model inversion, extraction. Sits outside the classic CIA frame More → |
| Scope creep in intended purpose The system used for something it was not registered for | Art. 3(12) · Art. 25 · Art. 43(4) substantial modification | Can convert a deployer into a provider without anyone deciding to More → |
| Shadow AI Systems in use that nobody has catalogued | Gates Art. 6(4), Art. 49, Art. 72: you cannot classify what you cannot list | Found through expense data, OAuth grant logs and an amnesty survey, not a policy reminder More → |
| Third-party and model supply chain Components changing without a version bump | Arts. 23–25 · Annex IV heading 2 | A model behind an API can be updated with behaviour you never tested More → |
| Synthetic content misuse Generative output used to deceive, or to produce prohibited material | Art. 50(2) marking · Art. 5 NCII/CSAM from 2 Dec 2026 · Art. 5(1a) liability limb | The Art. 5(1a) test turns on whether output is reproducible without significant technical modification More → |
| Oversight without authority A reviewer who cannot in practice overrule the system | Art. 14(4) · Art. 26(2) competence, training and authority | Throughput targets and manager escalation quietly remove the authority the Article requires More → |
| Log gaps Neither party retaining what the Regulation requires | Art. 19 provider · Art. 26(6) deployer, each for logs “under their control” | In SaaS the provider holds everything and the deployer holds nothing, and still owes retention More → |
| Documentation decay A technical file frozen at conformity assessment | Art. 11: must be kept up to date · Art. 18 ten-year retention | Non-compliant by the second release. Ten years also outlasts most log policies and most tenures More → |
How to use this
Article 9 requires identification and analysis of known and reasonably foreseeable risks to health, safety and fundamental rights, and risks emerging under reasonably foreseeable misuse. A register that contains none of the rows above for a system it plainly applies to is incomplete on its face.
Expert analysis. This is our catalogue, not a standard. Use it to test a register for gaps, not as the register itself. Article 9 →
Article 9 risk management → · AI inventory → · Maturity self-assessment →
Where this usually goes next
Three situations account for most people reading this page. Each has a different answer.
A deal is blocked on an AI questionnaire
Legal will not sign until you can evidence how AI is governed. HumanAudit’s AI Trust Package is a fixed $3,500 over five business days: a public trust page, a pre-filled SIG Lite / CAIQ / SSPA Section K questionnaire bank, and your AI inventory and classification.
You need ISO/IEC 42001 documentation
23 clause-mapped AIMS documents with all 38 Annex A controls pre-populated, editable and yours to keep, from $199. Or score your gaps first: 18 questions, free, no signup to begin.
You are not sure what reaches you
Twenty minutes with the founder. No prep, no deck, straight to the person accountable for the work. If none of this applies to you, you get told that on the call.
This reference is published by HumanAudit Inc. Not a law firm, not an accredited certification body, not a registered auditor. We build documentation, your counsel interprets it, and an accredited body of your choosing certifies you. How this is funded →