Does Hiroshima AI Process – Principles & Code of Conduct require Risk Assessment?

G7 • voluntary

Yes — 2 provisions

Requirements at a glance

This regulation imposes 8 specific requirements for Risk Assessment across 2 provisions:

Risk Management Lifecycle (Action 1) #

Obligation:
Risk Assessment
enforcing
Effective:
Oct 30, 2023
Risk tier:
all
Scope:
providers
high-impactcross-domain
The first and foundational action of the Code — requires risk identification and mitigation throughout the entire AI development and deployment lifecycle. Referenced by the US Executive Order on AI and EU AI Act implementation guidance as a convergent international baseline.

Requirements

RequirementDetails
Lifecycle risk identificationIdentify, evaluate, and mitigate risks prior to and throughout development and deployment
Pre-deployment assessmentConduct risk assessments before release of significant new versions
Proportionate controlsApply measures commensurate to the risk level identified
Ongoing monitoringContinuously assess risks as systems evolve and contexts of use change

Penalties

ViolationFine
Non-complianceVoluntary — no binding enforcement mechanism

Security Controls (Action 6) #

Obligation:
Risk Assessment
enforcing
Effective:
Oct 30, 2023
Risk tier:
all
Scope:
providers
cross-domain
Action 6 specifically addresses physical security, cybersecurity, and insider threat controls — including protection of model weights, algorithms, servers, and datasets. This cybersecurity-of-AI-systems obligation has no direct 1:1 match in the current obligation ontology; mapped to risk-assessment as the closest fit. Consider adding a dedicated security obligation.

Requirements

RequirementDetails
Physical securityInvest in physical security controls across the AI lifecycle
Cybersecurity controlsImplement cybersecurity controls including protection of model weights and algorithms
Insider threat safeguardsEstablish controls against insider threats targeting AI systems
Infrastructure securitySecure servers, datasets, and computational infrastructure

Penalties

ViolationFine
Non-complianceVoluntary — no binding enforcement mechanism
View full regulation View obligation Obligation matrix