Risk Assessment
Requirement to assess and document the risks posed by AI systems, including potential harms, bias, and impacts on affected individuals.
What Counts
- Mandatory risk assessments before deployment
- Algorithmic impact assessments
- Documentation of potential harms and mitigations
- Ongoing risk monitoring
- Risk classification and categorization
What Does Not Count
- Generic technology risk assessments without AI-specific criteria
- Self-assessment without documentation requirements
- One-time assessments without ongoing monitoring
Related Terms
- Impact assessment
- Risk management
- Algorithmic audit
- Risk classification
Implementing Regulations
| Regulation | Jurisdiction | Status | Provisions |
|---|---|---|---|
| Privacy Act 1988 — Automated Decision-Making Reforms | Australia | enacted | 1 |
| Brazil AI Bill (PL 2338/2023) | Brazil | proposed | 1 |
| California CCPA ADMT Regulations | California | enacted | 1 |
| Provisions on the Management of Algorithmic Recommendations | China | enforcing | 1 |
| Interim Measures for Generative AI Services | China | enforcing | 1 |
| Framework Convention on AI, Human Rights, Democracy and Rule of Law (CETS 225) | Council of Europe | enacted | 1 |
| Colorado Privacy Act Rules (4 CCR 904-3) | Colorado | enforcing | 1 |
| EU AI Act | European Union | phased enforcement | 1 |
| Digital Operational Resilience Act (DORA) | European Union | enforcing | 2 |
| AI Promotion Act | Japan | enforcing | 1 |
| AI Basic Act | South Korea | enforcing | 1 |
| New York RAISE Act | New York | enacted | 1 |
| Artificial Intelligence Basic Act | Taiwan | proposed | 1 |
| UK Online Safety Act 2023 | United Kingdom | phased enforcement | 1 |
| Law on Artificial Intelligence | Vietnam | enforcing | 1 |