SkarpSkarp

Chapter 5 of 25

The Compliance Design of High-Risk Systems

The recitals turn high-risk status into a lifecycle engineering and governance discipline. Risk management, data quality, logging, human oversight and resilience are treated as mutually supporting controls rather than isolated paperwork duties.

22 min readen

Recital (64): Compliance Is Cumulative, Not Optional

Why requirements apply

Recital (64) links high-risk requirements to risk mitigation and trustworthiness. Providers should account for intended purpose, context of use, state of the art, proportionality, and effectiveness.

Compliance accumulates

A product may fall under more than one Union harmonisation legal act. It can be made available or put into service only after compliance with all applicable legislation.

AI rules complement sectoral rules

Machinery or medical devices with AI can create risks that sectoral health-and-safety law does not address because those risks are specific to AI systems.

Integration is allowed, omission is not

Providers may combine AI testing, reporting, information, and documentation with existing sectoral processes. This flexibility must not undermine full compliance with every applicable requirement.

Recital (65): Risk Management Across the Lifecycle

The exact lifecycle principle

"The risk-management system should consist of a continuous, iterative process that is planned and run throughout the entire lifecycle of a high-risk AI system."

Review, update, document

The process should be regularly reviewed and updated for continuing effectiveness. Significant decisions and actions should be justified and documented.

Foreseeable misuse matters

Risk identification includes reasonably foreseeable misuse: predictable human uses that may sit outside the stated intended purpose or instructions for use.

Choose and explain measures

Providers should select the most appropriate measures in light of the state of the art, document and explain choices, and involve experts or external stakeholders when relevant.

Risk-Lifecycle Design Exercise

Scenario: AI-assisted emergency-department triage

A provider develops a high-risk AI system that prioritises incoming patients for clinical review. Its intended purpose is to help staff identify patients who may need rapid attention. During real use, staff begin treating its priority score as an automatic instruction rather than a support signal.

Work through the following prompts before revealing your answer:

  1. Lifecycle: At which stages should the provider run risk management: only before release, or before release and throughout deployment?
  2. Foreseeable misuse: Is staff over-reliance outside the intended purpose but still a use that may be reasonably expected from readily predictable human behaviour?
  3. Mitigation: What could be documented in the instructions for use about circumstances in which the score can create health, safety, or fundamental-rights risks?
  4. Evidence trail: Which decisions should be justified and documented when the provider selects mitigation measures?

Suggested analysis

Under Recital (65), risk management should run continuously and iteratively throughout the system lifecycle. Treating the score as an automatic instruction can plausibly be reasonably foreseeable misuse if it follows predictable human behaviour in this operational setting. The provider should identify and mitigate the risk, record its reasoning, and include relevant known or foreseeable risk circumstances in the instructions for use. The recital does not say that the provider must retrain the system for every foreseeable misuse; it says additional training is not required for that purpose, though providers are encouraged to consider it when necessary and appropriate.

Design insight: a compliance record should show the connection between the risk identified, the measure selected, the rationale for selecting it, and the information supplied to the deployer.

Recitals (66)-(70): Data Governance, Privacy, and Bias

Mutually supporting controls

Recital (66) connects risk management, data quality, documentation, logging, transparency, human oversight, robustness, accuracy, and cybersecurity as necessary risk-mitigation requirements.

The exact data-quality standard

"Data sets for training, validation and testing, including the labels, should be relevant, sufficiently representative, and to the best extent possible free of errors and complete in view of the intended purpose of the system."

Bias is dynamic

Data should have appropriate statistical properties for intended users or groups. Historical bias and deployment-created bias can be amplified, especially when outputs become inputs through feedback loops.

Privacy across the lifecycle

Recital (69) applies data minimisation and data protection by design and by default. Measures may include anonymisation, encryption, and bringing algorithms to data rather than copying data.

Exceptional special-category processing

For strictly necessary bias detection and correction, Recital (70) says providers should exceptionally "be able to process also special categories of personal data, as a matter of substantial public interest", subject to safeguards and conditions.

Quiz: Data Quality and Foreseeable Misuse

Choose the answer that most closely follows Recitals (65) and (67).

Which approach best reflects the source text for a provider whose high-risk AI outputs affect later training inputs?

  1. Use any historically available data if the model's overall accuracy is high.
  2. Consider whether feedback loops may perpetuate or amplify bias, and use data governance practices suited to the intended purpose and affected groups.
  3. Ignore foreseeable misuse because only uses expressly listed in the instructions for use matter.
  4. Avoid privacy-preserving techniques because data sets must be completely error-free.
Show Answer

Answer: B) Consider whether feedback loops may perpetuate or amplify bias, and use data governance practices suited to the intended purpose and affected groups.

Recital (67) specifically identifies feedback loops as a setting in which biases can affect future operations and amplify discrimination. It also requires purpose-relative relevance, representativeness, and data governance. Recital (65) requires attention to reasonably foreseeable misuse, not only expressly intended use. The source also says the completeness and error-freedom expectation should not affect privacy-preserving techniques.

Recitals (71)-(72): Traceability and Usable Transparency

What technical documentation should contain

Recital (71) identifies characteristics, capabilities, limitations, algorithms, data, training, testing, validation, and the risk-management system. Documentation should be clear, comprehensive, and kept up to date.

The automatic-log requirement

"high-risk AI systems should technically allow for the automatic recording of events, by means of logs, over the duration of the lifetime of the system."

Documentation and logs do different jobs

Documentation explains system design and compliance evidence. Logs record events over operational time, supporting traceability, monitoring, and post-market monitoring.

Instructions enable informed use

Instructions should explain capabilities, limitations, risks, deployer actions affecting performance, predetermined conformity-assessed changes, and human-oversight measures in an understandable language.

Recital (73): Human Oversight That Can Actually Intervene

Oversight is designed in

Recital (73) expects providers to identify appropriate human-oversight measures before placing the system on the market or putting it into service.

A capable human role

Where appropriate, oversight means operational constraints the system cannot override, responsiveness to the operator, and people with the competence, training, and authority to act.

Intervention and stopping

The system should, as appropriate, guide the overseer on whether, when, and how to intervene, avoid negative consequences, or stop the system when it fails to perform as intended.

Enhanced biometric safeguard

"no action or decision may be taken by the deployer on the basis of the identification resulting from the system unless this has been separately verified and confirmed by at least two natural persons."

Recitals (74)-(78): Accuracy, Robustness, and Cybersecurity

Declare performance expectations

Recital (74) says systems should perform consistently across their lifecycle at an appropriate accuracy, robustness, and cybersecurity level. Expected performance metrics should be declared in instructions for use.

Robustness includes safe interruption

Recital (75) covers errors, faults, inconsistencies, and unexpected situations. Measures may include fail-safe plans that safely interrupt operation during anomalies or outside predetermined boundaries.

The exact cybersecurity principle

"Cybersecurity plays a crucial role in ensuring that AI systems are resilient against attempts to alter their use, behaviour, performance or compromise their security properties"

AI-specific attacks

The recital identifies data poisoning, adversarial attacks, membership inference, and vulnerabilities in AI digital assets or underlying ICT infrastructure as relevant cybersecurity concerns.

Two regulatory pathways can interact

Recitals (77)-(78) describe how cybersecurity conformity under the horizontal products-with-digital-elements regime can demonstrate AI cybersecurity compliance, while preserving special assessment treatment for specified important and critical products.

Quiz: Logging, Oversight, and Resilience

Select the statement that accurately combines the requirements described in Recitals (71), (73), and (76).

Which statement is correct?

  1. Logs are optional narrative summaries prepared only after an incident, and biometric matches can directly determine deployer action.
  2. A provider should enable automatic event recording over the system lifetime; certain biometric-identification actions require separate verification and confirmation by at least two natural persons; cybersecurity measures should address AI-specific attacks such as data poisoning.
  3. Human oversight requires every decision made by every high-risk AI system to be confirmed by two natural persons.
  4. Cybersecurity concerns only the underlying network and never training data or trained models.
Show Answer

Answer: B) A provider should enable automatic event recording over the system lifetime; certain biometric-identification actions require separate verification and confirmation by at least two natural persons; cybersecurity measures should address AI-specific attacks such as data poisoning.

Recital (71) calls for technical capacity for automatic event recording by logs over the system lifetime. Recital (73) creates the two-natural-person safeguard for identification resulting from certain biometric identification systems, not every high-risk system. Recital (76) expressly includes data poisoning and attacks on trained models among AI-specific cybersecurity concerns.

Flashcards: The High-Risk Compliance Architecture

Flip each card, then explain how the term connects to another control in the lifecycle design.

Continuous, iterative risk management
A process planned and run throughout the entire lifecycle of a high-risk AI system, regularly reviewed and updated for continuing effectiveness.
Reasonably foreseeable misuse
Use outside the intended purpose or instructions that may nevertheless be reasonably expected from readily predictable human behaviour in the system's particular context.
Data quality standard
Training, validation, and testing data sets, including labels, should be relevant, sufficiently representative, and to the best extent possible free of errors and complete for the intended purpose.
Feedback loop
A situation in which AI outputs influence inputs for future operations, allowing bias to gradually increase, perpetuate, or amplify discrimination.
Technical documentation
Clear and comprehensive, up-to-date information on characteristics, capabilities, limitations, algorithms, data, training, testing, validation, and the risk-management system.
Automatic logs
High-risk AI systems should technically allow automatic recording of events by logs over the system's lifetime.
Human oversight
Provider-identified measures that enable natural persons with competence, training, and authority to oversee, intervene in, or stop the system where appropriate.
Enhanced biometric oversight
No deployer action or decision based on an identification result unless it has been separately verified and confirmed by at least two natural persons, subject to the stated proportionality exception.
Technical robustness
Resilience against harmful or undesirable behaviour caused by system or environmental limitations, including errors, faults, inconsistencies, and unexpected situations.
AI-specific cybersecurity risks
Risks including data poisoning, adversarial attacks, membership inference, and exploitation of vulnerabilities in AI digital assets or underlying ICT infrastructure.

Key Terms

logs
Automatically recorded events over the lifetime of the high-risk AI system, supporting traceability and monitoring.
deployer
The actor using the high-risk AI system and receiving information and instructions intended to support correct and informed use.
provider
The actor described in the recitals as establishing the risk-management system, selecting mitigation measures, maintaining documentation, and supplying instructions for use.
data poisoning
An AI-specific cyberattack example in which an attacker targets training data sets.
fail-safe plan
A technical solution enabling safe interruption of operation when anomalies occur or operation moves outside predetermined boundaries.
human oversight
Measures enabling natural persons to supervise use, make informed interventions, avoid negative consequences, or stop a system where appropriate.
intended purpose
The purpose used throughout the recitals to frame appropriate data, risk assessment, accuracy, robustness, and transparency.
adversarial attack
An AI-specific attack example targeting a trained model or its behaviour through crafted inputs.
technical documentation
The maintained compliance information needed to assess a system and facilitate post-market monitoring.
reasonably foreseeable misuse
A use not directly covered by intended purpose or instructions that can nevertheless be reasonably expected from readily predictable human behaviour in the particular context.
special categories of personal data
Sensitive personal-data categories that Recital (70) addresses in the exceptional, strictly necessary context of bias detection and correction, subject to safeguards and conditions.
data governance and management practices
Practices supporting high-quality training, validation, and testing data, including appropriate handling of personal-data collection purposes and bias risks.

Finished reading?

Test your understanding with a custom practice exam on this chapter.

Test yourself