NeFut Logo NeFut
Admin Login

[CS.AI] From Legal Text to AI‑Specific Risk Sources: A Systematic Analysis of the EU AI Act’s High‑Risk Requirements

Published at: 2026-09-15 22:00 Last updated: 2026-09-16 00:22
#AI #Machine Learning #Artificial Intelligence

The EU AI Act sets mandatory requirements for high‑risk AI systems with the explicit aim of ensuring trustworthy development and operation. At the same time, AI risk management relies on structured taxonomies to systematically identify and treat AI‑specific risk sources. Both the Act and established taxonomies target AI‑induced risks, yet no clear mapping exists between the risks implicitly covered by the Act’s high‑risk requirements and those defined in existing taxonomies, leaving practitioners without a structured basis for aligning regulatory obligations with risk‑management practice. This paper systematically classifies the requirements extracted from Section 2 of the EU AI Act (requirements for high‑risk AI systems). The analysis shows that only a minority of requirements directly address AI‑specific risk sources, while the majority impose organisational process and documentation obligations. From the risk‑related requirements a consolidated list of distinct AI‑specific risk sources is derived, called the EU AI Act Risk Source List. The list bridges the gap between legal obligations and AI risk‑management practice and provides a structured reference for explicit comparison between existing risk taxonomies and the risk sources implicitly addressed by the Act. This is the authors’ preprint; the paper was presented at the 4th International Conference on Frontiers of Artificial Intelligence, Ethics, and Multidisciplinary Applications, and the official proceedings link will be added after publication.

Review: The study offers a practical bridge between legal text and technical risk management, giving compliance teams a concrete set of AI‑specific risk sources to align with the EU AI Act.

Original Source: https://arxiv.org/abs/2609.13535

[h] Back to Home