Paper deep dive
Overview of Risk Assessment and Management for Intelligent Systems under the AI Act and Beyond
Javier Irigoyen, Roberto Daza, Aythami Morales, Julian Fierrez, Ruben Tolosana, Ruben Vera-Rodriguez, Francisco Jurado, Alvaro Ortigosa
Intelligence
Status: succeeded | Model: Gemma-4-26B-A4B | Prompt: intel-v1 | Confidence: 95%
Last extracted: 7/5/2026, 12:40:35 PM
Summary
This paper provides a comprehensive overview of AI risk assessment and management methodologies within the context of emerging regulatory frameworks like the EU AI Act. It categorizes AI-related risks into technical and non-technical dimensions (e.g., bias, privacy, robustness) and reviews global regulatory landscapes, including the EU's risk-based approach, the US's sector-specific and federal mandates, Canada's Algorithmic Impact Assessment, and China's generative AI regulations. The paper also discusses international standards (ISO/IEC) and voluntary frameworks (NIST AI RMF, Singapore Model Framework) to highlight the transition from theoretical ethical principles to practical, operationalized risk management.
Entities (7)
Relation Signals (4)
EU AI Act â categorizesaiinto â Unacceptable, High, Limited, and Minimal Risk
confidence 100% ¡ The Act adopts a risk-based approach, classifying AI applications into four categories: 1) Unacceptable Risk... 2) High Risk... 3) Limited Risk... 4) Minimal or No Risk.
AI HLEG â developed â Ethics Guidelines for Trustworthy AI
confidence 100% ¡ Its Ethics Guidelines for Trustworthy AI [1], published in April 2019, set foundational principles for responsible AI deployment in Europe.
AI Risk â includes â Bias, Privacy, and Robustness
confidence 95% ¡ The spectrum of AI-related risks identified in the literature, from technical failures to ethical and social impacts... such as biased outcomes, privacy violations, lack of transparency.
NIST AI RMF â providesguidancefor â AI Risk Management
confidence 90% ¡ The NIST AI Risk Management Framework (AI RMF 1.0, NIST.AI.100-1) provides guidance to identify, measure, and prioritize AI risks.
Cypher Suggestions (0)
No Cypher suggestions yet.
Abstract
Abstract:The society and emerging risk-based regulatory frameworks for AI underscore the need for rigorous risk assessment to ensure safe and reliable AI systems. In response to this imperative, this paper presents an overview of AI risk assessment (identification and analysis) and management methodologies. It begins by reviewing the worldwide regulatory landscape that drives the need for systematic AI risk assessment. Then we characterize the spectrum of AI-related risks identified in the literature, from technical failures to ethical and social impacts. Subsequently, it reviews key risk assessment methodologies proposed for AI systems, focusing on general frameworks. The paper highlights best practices and illuminates methodological gaps, highlighting areas for further research on AI risk assessment.
Tags
Links
- Source: https://arxiv.org/abs/2607.02197v1
- Canonical: https://arxiv.org/abs/2607.02197v1
Trouble viewing inline? Open PDF directly â
Full Text
34,739 characters extracted from source content.
Expand or collapse full text
Overview of Risk Assessment and Management for Intelligent Systems under the AI Act and Beyond Javier Irigoyen â , Roberto Daza ââ , Aythami Morales â⥠, Julian Fierrez â , Ruben Tolosana â , Ruben Vera-Rodriguez â , Francisco Jurado â , and Alvaro Ortigosa â â BiometricsAI, Universidad Aut Ě onoma de Madrid (UAM), Spain â GHIA, Universidad Aut Ě onoma de Madrid (UAM), Spain ⥠Universidad de Las Palmas de Gran Canaria (ULPGC), Spain Corresponding author: javier.irigoyen@uam.es AbstractâThe society and emerging risk-based regulatory frameworks for AI underscore the need for rigorous risk assess- ment to ensure safe and reliable AI systems. In response to this imperative, this paper presents an overview of AI risk assessment (identification and analysis) and management methodologies. It begins by reviewing the worldwide regulatory landscape that drives the need for systematic AI risk assessment. Then we characterize the spectrum of AI-related risks identified in the literature, from technical failures to ethical and social impacts. Subsequently, it reviews key risk assessment methodologies pro- posed for AI systems, focusing on general frameworks. The paper highlights best practices and illuminates methodological gaps, highlighting areas for further research on AI risk assessment. Index TermsâAI Act, AI Risks, Responsible AI, Safe AI. I. INTRODUCTION The proliferation and integration of Artificial Intelligence (AI) technologies in multiple sectors has led to significant innovations and improvements in efficiency, decision-making, and automation. Despite these advantages, the widespread use of AI also introduces considerable risks, such as biased outcomes, privacy violations, lack of transparency, and cyber- security vulnerabilities. As AI systems become increasingly autonomous, these risks pose significant legal, ethical, and operational challenges for organizations and society at large. Consequently, there is a growing emphasis from regulatory bodies, policymakers, and academia on systematically assess- ing and managing AI-associated risks, exemplified by the recent entry into force of the European Unionâs Artificial Intelligence Act (AI Act). The AI Act represents a landmark regulatory approach that aims to create a standardized framework to identify and mitigate risks posed by AI systems. Its risk-based approach categorizes AI applications according to potential harm, man- dating stringent assessment requirements for high-risk AI applications. Although such regulations provide a foundational structure for risk governance, there remains a need for practical methodologies to implement these regulatory requirements effectively within organizations. This research was supported by C Ě atedra ENIA UAM-VERIDAS enIAResponsable(NextGenerationEUPRTRTSI-100927-2023-2), M2RAI (PID2024-160053OB-I00, MICIU/FEDER), TRUST-ID (PID2025- 173396OB-I00, MICIU/AEI and the EU) and PowerAI+ (SI4/PJI/2024-00062, Comunidad de Madrid and UAM). Javier Irigoyen is supported by an FPI fellowship from MINECO/FEDER. Recent academic literature has offered information on methodologies and frameworks for AI risk assessment, in- cluding contributions on interpretability, fairness, robustness, and sustainability. Despite these advances, current approaches often remain theoretical or domain-specific, lacking compre- hensive empirical validation in diverse organizational contexts. Furthermore, existing research frequently addresses individual risk dimensions in isolation or lacks integration into a coher- ent, universally applicable framework. Our paper addresses these critical gaps by systematically reviewing existing AI risk assessment approaches, synthe- sizing insights from the literature, regulatory requirements, and practical implementations within organizations. Through our comprehensive review, our aim is to provide clarity on best practices and shortcomings of current methodologies, ultimately contributing to the development of robust, empiri- cally validated guidelines for effective AI risk assessment and compliance under the new regulatory landscape. I. INTRODUCTION TO ETHICAL GUIDELINES AND TRUSTWORTHY AI IN THE EUROPEAN CONTEXT The European Commissionâs work on Artificial Intelligence (AI) governance has been guided by the High-Level Ex- pert Group on Artificial Intelligence (AI HLEG). Its Ethics Guidelines for Trustworthy AI [1], published in April 2019, set foundational principles for responsible AI deployment in Europe and introduced Trustworthy AI as a governance ideal built on three interconnected principles. A. General Principles of Trustworthy AI The principles of Trustworthy AI [2], [3] can be summarized in three main pillars: 1) Lawful: AI systems must comply with the legal frame- works, regulations, and obligations applicable in the European Union. 2) Ethical: Beyond legal compliance, AI must respect fundamental ethical principles and societal values, prior- itizing human dignity, individual autonomy, and fairness so that technology serves rather than undermines society. 3) Robust: AI must be technically resilient, maintaining accuracy, reliability, security, and consistency while ac- arXiv:2607.02197v1 [cs.CY] 2 Jul 2026 counting for its broader social context to minimize risks and unintended harm. Together, these principles define the baseline that an AI sys- tem must meet to be considered trustworthy in the European perspective outlined by the AI HLEG. B. Operationalization of Principles into Specific Requirements The AI HLEG translated these broad principles into seven practical requirements that systems should satisfy throughout their life cycle: 1) Human Agency and Oversight: AI systems should empower users, support informed decision-making, and protect fundamental rights. Oversight mecha- nismsâranging from âhuman-in-the-loopâ to âhuman- in-commandâ approachesâmust ensure that AI aug- ments rather than overrides human judgment. 2) Technical Robustness and Safety: AI must be secure, resilient, accurate, reliable, and reproducible, with safety mechanisms and follow-up plans to limit harm from unexpected failures or errors. 3) Privacy and Data Governance: AI systems must re- spect privacy and follow robust data governance prac- tices, safeguarding data quality, integrity, and accessibil- ity while complying with data protection rules such as the GDPR. 4) Transparency: Clear information on AI capabilities, limitations, logic, and decisions must be provided. Stakeholders should know when they interact with AI and understand AI-generated outcomes through trace- ability and explainability. 5) Diversity, Non-discrimination, and Fairness: AI sys- tems must avoid biases that could marginalize or unfairly disadvantage individuals or vulnerable groups. Fairness, inclusivity, and accessibility should guide development and deployment. 6) Societal and Environmental Well-being: The broader impacts of AI on society and the environment must be carefully managed. AI technologies should foster sus- tainability, mitigate environmental harm, and consider the long-term welfare of future generations. 7) Accountability: Clear and enforceable mechanisms must be established to attribute responsibility for AI systemsâ actions and outcomes. Auditability, traceability, and effective redress procedures ensure accountability, particularly for critical or high-risk applications. These requirements translate lawful, ethical, and robust AI into practical guidance for industry, policymakers, and regulators. Later EU policy, especially the proposed Artificial Intelligence Act (AI Act), builds on them by formalizing a legally enforceable framework for managing AI risks. I. TOWARDS RISK-BASED AI SYSTEMS Building on the ethical framework provided by the AI HLEG, the European Commission proposed the Artificial Intelligence Act (AI Act) to regulate AI systems systemat- ically. The Act adopts a risk-based approach, classifying AI applications into four categories: 1) Unacceptable Risk: Applications incompatible with EU values, such as social scoring or manipulative systems influencing vulnerable individuals, are prohibited. 2) High Risk: Systems whose malfunction could affect safety, fundamental rights, or well-beingâsuch as med- ical diagnostics, biometric identification, or critical in- frastructure managementâare subject to stringent obli- gations. 3) Limited Risk: Systems that require transparency obli- gations but do not pose severe threats, such as chatbots or deepfakes, must inform users that they are interacting with AI. 4) Minimal or No Risk: Applications such as spam filters or video game AI, which present negligible risk, face minimal or no obligations. For High Risk AI systems, the AI Act defines obligations closely aligned with Trustworthy AI requirements, including: ⢠Data and data governance. ⢠Risk management system. ⢠Technical documentation and record keeping. ⢠Transparency and provision of information to users. ⢠Human oversight. ⢠Accuracy, robustness, and cybersecurity. ⢠Quality management system. The risk management system obligation can be detailed into the following requirements: 1) Risk management system: ⢠Characterization of the AI system. ⢠Continuous operation throughout the life cycle. 2) Risk management process: ⢠Identification of risks affecting the AI system. ⢠Estimation and evaluation of risks caused by rea- sonably foreseeable misuse. ⢠Evaluation of other possible risks. 3) Risk management measures to eliminate or reduce risks: ⢠Adequate design and development. ⢠Mitigation and control measures. ⢠Provision of information to users. ⢠User training. 4) Conditions required to operate the AI system: ⢠User capacities (e.g., technical knowledge, experi- ence, education, training). ⢠Configuration of the intended operating environ- ment. 5) Testing of the AI system: ⢠System performance. ⢠System compliance with prior requirements. Certain clauses within these requirements, notably risk iden- tification, estimation and evaluation of risks from reasonably Limited Unacceptable Requirements ROBUSTNESS REGULATION ETHICS Human autonomy Fairness Explicability TRUSTWORTHY AI Risk-based classification RiskManagement System Health, Safety, Human rights Riskidentification RISK ASSESSMENT Riskmitigation Human oversight Robustness Transparency Privacy Fairness Soc. & Env. well-being Accountability Preventionofharm Minimal High Fig. 1. Overview of AI risk assessment as a module in the context of a general responsible AI framework. foreseeable misuse, and evaluation of other possible risks, directly involve risk assessment (see Fig. 1). Such assessments are challenging because AI risks are abstract and multidi- mensional, and depend on implementation scale, technology, application context, and even the definition of risk itself. This creates a critical question: how can these multifaceted AI risks be assessed in practice? A. International Regulatory Summary Several jurisdictions have established frameworks that ad- dress AI risk assessment, including binding obligations for organizations deploying high-risk systems. The following ex- amples show different approaches to defining, evaluating, and managing AI-associated risks. European Union â Artificial Intelligence Act: The AI Act [4] creates a four-level risk taxonomy and legally obliges providers of high-risk systemsâsuch as Annex I uses in biometric identification, critical infrastructure, hiring, or creditâto conduct extensive risk management. Article 9 re- quires a documented risk-management system to identify and mitigate risks throughout the AI life cycle. Before deployment or market access in the EU, these systems must pass a conformity assessment covering data quality, transparency, human oversight, robustness, and risk mitigation. Other EU rules also support AI risk assessment in specific contexts; for example, the GDPR requires Data Protection Impact As- sessments (DPIAs) [5] for high-risk personal data processing, including AI-driven profiling or automated decisions. United States â OMB Memorandum M-24-10: While Congress still debates a horizontal AI law, OMB Memorandum M-24-10 [6] requires federal agencies to treat AI risks system- atically. Systems deemed rights-impacting (e.g. employment or benefits decisions) or safety-impacting (e.g. autonomous vehicles or diagnostics) must undergo pre-deployment risk assessment aligned with the NIST AI RMF. Agencies must map context and stakeholders, measure likelihood and impact, select controls such as bias testing, human oversight and red- team security probes, and continuously monitor performance. A Chief AI Officer coordinates inventories and annual public summaries, while OMB audits compliance. Beyond federal agencies, U.S. mandates remain sector-specific; for instance, the FDA treats some AI-based medical software as a medical device [7], subjecting them to pre-market risk analysis and post-market surveillance. Canada â Directive on Automated Decisions-Making: Since 2019, every federal project that automates a decision about people must complete the Online Algorithmic Impact Assessment (AIA) [8] before any code ships. Its 51 risk questions and 34 mitigation questions cover design intent, data sources, algorithmic logic, privacy, bias, transparency, and human fall-backs. The tool scores systems from Level I to IV: Level I triggers basic documentation, while Level IV (e.g., immigration or parole decisions) demands external peer review, source-code transparency, plain-language explanations, live human override, and yearly re-certification. Published results create public pressure, and the Treasury Board can suspend projects that ignore the AIA. China â Interim Measures on Generative AI Services: In 2023, regulators introduced rules for commercial generative AI. The Interim Measures for the Administration of Generative AI Services [9] impose security evaluation obligations on providers. Article 17 requires services with public opinion or social mobilization capacity to conduct a security evaluation and complete algorithm submission procedures. 1) Non-binding official guidelines: In addition to binding regulations, several countries have developed influential vol- untary frameworks that guide responsible AI adoption and risk assessment. Singapore â Model AI Governance Framework (vol- untary): The framework [10] urges companies to adopt a risk-based approach: identify AI features with the greatest stakeholder impact, then select proportionate controls such as explainability, robustness testing, auditability, dataset gover- nance, and human-in-the-loop mechanisms. United Kingdom â AI Regulation White Paper (consulta- tive): The white paper [11] sets five overarching principles and asks existing regulators to conduct context-specific risk assess- ments rather than imposing a single statute. A central function will share risk templates, coordinate horizon scanning, and support regulatory sandboxes for proportionate, innovation- friendly oversight. India â NITI Aayog âResponsible AI for Allâ (volun- tary): The roadmap [12] frames seven constitutional principles and calls for calibrated, risk-proportionate assessment, from system-level issues such as bias, explainability, and privacy to wider societal impacts. United States (industry) â NIST AI RMF 1.0 (vol- untary): NISTâs framework offers sector-agnostic guidance: organizations Govern AI risk, Map context & stakeholders, Measure likelihood/impact with metrics, and Manage through controls and monitoring, complemented by a Playbook and sector profiles (e.g., for generative AI). International Standards â ISO/IEC 42001 & 23894 (certifiable): ISO 42001 allows organizations to certify an AI management system covering policy, roles, objectives, and continuous improvement, while ISO 23894 provides tech- niques to identify, analyze, evaluate, and treat AI-specific risks, aligning with ISO 31000 and NIST AI RMF. 2) AI Risk Management Standards: International standard- ization efforts support the practical implementation of AI risk assessment required by regulations. Particularly relevant are ISO and IEC standards, especially within ISO/IEC JTC 1/SC 42. For the AI Act RMS, these include ISO/IEC AWI 5338, TR 5469, 23894-2, 24027, 24029-1, CD 24668, 38507, and 42001 [13]. These standards address different aspects of AI risk management and support compliance and best practices. The National Institute of Standards and Technology (NIST) has developed complementary frameworks for AI risk manage- ment, emphasizing flexibility, transparency, and accountability. These frameworks add practical approaches and methodolo- gies for regulators and AI developers. The NIST AI Risk Management Framework (AI RMF 1.0, NIST.AI.100-1) provides guidance to identify, measure, and prioritize AI risks throughout the AI system life cycle. It quantifies risks by assessing likelihood and impact, using qualitative and, where possible, quantitative metrics to capture AI complexity and uncertainty. Its four functionsâGOVERN (oversight and accountability), MAP (contextualizing risks), MEASURE (applying metrics), and MANAGE (implementing treatment strategies)âstructure risk analysis and management. The Generative AI Profile (NIST.AI.600-1) extends the AI RMF by addressing risks unique to or exacerbated by Generative AI (GAI), such as confabulation, harmful content generation, privacy concerns, cybersecurity vulnerabilities, and intellectual property issues. It introduces measures such as Content Provenance, Pre-deployment Testing, and Incident Disclosure to improve transparency, responsiveness, empirical testing, and continuous monitoring of generative AI risks. IV. RISK ASSESSMENT: IDENTIFICATION AND ANALYSIS A. Risk Identification AI risk assessment involves two stages: risk identification, which pinpoints specific hazards or sources of harm, and risk analysis, which evaluates their likelihood and severity [14]. Effective identification requires a structured framework for mapping potential risks, but since AI systems are complex and âriskâ is an abstract concept, researchers have proposed varied taxonomies, each capturing different technical and ethical challenges. This matters more than ever as AI spreads into high-stakes sectors like healthcare, finance, transportation, and security. A key step toward good governance is understanding these different risk types, which is why many researchers have developed frameworks, methodologies, and classifications to help identify, prioritize, and mitigate AI-related risks. A critical commonality among these frameworks is the categorization of AI risks into technical and non-technical dimensions. Bagehorn et al. [15], for instance, develop the âAI Risk Atlasâ segmenting risks into input, inference, output, and non-technical categories, each further analyzed through dimensions such as accuracy, fairness, privacy, robustness, and explainability. Slattery et al. [16] complement this perspec- tive by synthesizing existing classifications into an accessible âAI Risk Repository,â which offers a dual taxonomy: one that categorizes risks causallyâby entity, intentionality, and timingâand another by domain, including misinformation, discrimination, privacy, and system security. Identifying risks specific to particular social-scale contexts also emerges as a common theme in the literature. Critch and Russell [17] highlight the social-scale risks originating from intentional misuse, unintended interactions, and system misalignments, using fault tree analysis to systematically explore accountability and intervention strategies. Similarly, Uuk et al. [18] emphasize the systemic nature of the risks arising from general-purpose AI, pinpointing broad societal threats such as democratic erosion, economic disruptions, and environmental harm. Both studies advocate for structured and comprehensive policy responses to manage these widespread impacts effectively. The complexity and rapid evolution of AI technologies require adaptive and context-sensitive regulatory frameworks, as evidenced by Al-Maamari et al. [19]. Their comparative analysis across regions including the EU, US, UK, and China TABLE I TAXONOMIES OF AI RISKS Ref.TaxonomyRisk category Slattery et al. [16] Causal (high-level) Entity Intentionality Timing Domain (mid-level) Discrimination and toxicity Privacy and security Misinformation Malicious actors and misuse Human-computer interaction Socioeconomic and environmental AI safety, failures and limitations Uuk et al. [18]Systemic Control Democracy Discrimination Economy Environment Fundamental rights Governance Harms to non-humans Information Irreversible change Power Security Warfare Steimers et al. [14] Ethical Fairness Privacy Degree of automation Reliability and robustness Complexity of the task and usage environment Degree of transparency and explainability Security System hardware Technological maturity OECD [22]Trustworthy AI Sustainability Human rights, privacy and fairness Transparency and explainability Robustness, security and safety Accountability underscores how different governance modelsâranging from centralized directives to sector-specific approachesâaddress the delicate balance between innovation and oversight. Each model has strengths and limitations; for example, the struc- tured transparency and conformity assessments of the EU contrast with the decentralized approach of the US, which promotes innovation but risks fragmented enforcement. Addressing practical implementation and ongoing man- agement of these frameworks, Habbal et al. [20] introduce the AI Trust, Risk, and Security Management (AI TRiSM) framework, stressing the importance of adaptive strategies such as ModelOps to deal with continuously emerging threats and challenges such as adversarial attacks, biases, and ethical concerns. Steimers and Schneider [14] further reinforce the need for AI-specific risk management strategies, highlighting the unique risks of AI systems, including unpredictability and opacity, that traditional software risk management does not adequately address. Then, Hendrycks et al. [21] offer a perspective on catas- trophic risks, categorizing them as malicious use, AI race conditions, organizational risks, and rogue AI scenarios. They propose concrete methods to mitigate these threats, such as enhanced biosecurity, strict model access controls, organiza- tional risk culture improvements, and international regulatory coordination, reflecting the multifaceted approach needed to protect against severe outcomes. B. Risk Analysis Different studies have proposed various approaches to mea- sure and manage risks derived from the use of AI, highlighting a diverse range of frameworks and conceptualizations. This diversity underscores the complexity and richness of the land- scape, showcasing non-exclusive, complementary approaches to AI risk assessment. The fundamental need for clear governance and structured frameworks to manage AI risks is addressed comprehensively by Falco et al. [23], who propose an independent audit system known as IAAIS. They emphasize prospective assessments, audit trails, and adherence to jurisdictional requirements, en- suring operational transparency and fostering public trust. Sim- ilarly, Koshiyama et al. [24] underscore the systemic necessity of rigorous auditing, highlighting how comprehensive lifecycle assessments can mitigate legal, ethical, and operational risks through specialized auditing processes. Moving from governance to implementation, Fell Ě ander et al. [25] introduce DRESS-eAI, a novel data-driven method- ology. Their approach integrates multidisciplinary perspec- tivesâincluding technical, legal, and social insightsâto ad- dress ethical risks practically and sustainably. This aligns closely with Nagbøl et al. [26], whose AIRA tool specifically prioritizes structured stakeholder communication and broad performance metrics, such as fairness, interpretability, and privacy, promoting effective organizational risk management. Further developing these ideas, Giudici et al. [27] present the Key AI Risk Indicators (KAIRI) framework, directly tying regulatory compliance from the European AI Act to quan- tifiable principles like Sustainability, Accuracy, Fairness and Explainability, particularly in financial contexts. Meanwhile, Zhang et al. [28] broaden this approach by categorizing risks at the data and model levels, highlighting the critical importance of managing biases, uncertainties, and potential adversarial vulnerabilities in high-risk AI applications. Such domain-oriented operationalizations are also emerging in ed- ucation, where Irigoyen et al. [29], [30] frame pedagogical risk evaluation through an extended dataset for explainable assessment, and in humanâAI interaction, where Daza et al. [31] assess social-engineering risks through adaptive role- based evaluation. Based on regulatory frameworks, Novelli et al. [32] ad- vocate for proportional and scenario-based risk assessment models inspired by climate change risk frameworks. Their methodology examines complex interactions among risk deter- minants, enhancing the precision and adaptability of regulatory responses, particularly relevant for general-purpose AI systems such as large language models (LLMs). To bridge theory with practical application, Koessler et al. [33] review established risk assessment methods from safety- critical industries, recommending their adaptation for AI- specific catastrophic risks. Techniques like scenario analysis, causal mapping, and Delphi methods are promoted for iter- ative pre-deployment and pre-training assessments, ensuring comprehensive life cycle coverage. Complementing this, Xia et al. [34] provide an extensive mapping of current frame- works, highlighting strengths, limitations, and recommending enhancements towards concreteness and interconnectedness in future AI risk assessments. Collectively, these contributions form a holistic and dynamic understanding of AI risk assessment, advocating robust in- terdisciplinary frameworks, precise regulatory alignment, and structured stakeholder engagement to navigate the complex risk landscape effectively. V. FUTURE WORK In our future work, we will study risks in multimodal LLMs (including VLMs [35]) and representations based on images of agents (including avatars [36]). Analyzing biases [37], [38] and synthetic manipulations [39] while maintaining privacy [40] are also key topics for risk evaluation on our agenda. Finally, we will apply these risk assessment and management principles to concrete domains such as document intelligence [41], e-learning [30], [42], gaming [31], and e-health [43]. REFERENCES [1] M. Cannarsa, âEthics guidelines for trustworthy AI,â The Cambridge Handbook of Lawyering in the Digital Age, p. 283â297, 2021. [2] A. Pe Ě na et al., âHuman-centric multimodal machine learning: Recent advances and testbed on AI-based recruitment,â SN Computer Science, vol. 4, no. 5, p. 434, June 2023. [3] N. D Ě Äąaz-Rodr Ě Äąguez, J. Del Ser, M. Coeckelbergh, M. L. de Prado, E. Herrera-Viedma, and F. Herrera, âConnecting the dots in trustworthy artificial intelligence: From AI principles, ethics, and key requirements to responsible AI systems and regulation,â Information Fusion, vol. 99, p. 101896, 2023. [4] European Parliament and Council of the European Union, âRegulation (EU) 2024/1689 of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act),â Official Journal of the European Union, L 2024/1689, Jul. 2024. [Online]. Available: https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng [5] European Parliament and Council of the European Union, âGeneral Data Protection Regulation (GDPR),â Regulation (EU) 2016/679, Official Journal of the European Union, L 119, Apr. 2016, [Online]. Available: EUR-Lex. [6] Office of Management and Budget, âAdvancing Governance, Innovation, and Risk Management for Agency Use of Artificial Intelligence,â Memorandum M-24-10, Executive Office of the President, Mar. 2024, [Online]. Available: White House PDF. [7] U.S. Food and Drug Administration, âArtificial Intelligence in Software as a Medical Device,â Mar. 2025, [Online]. Available: FDA AI SaMD page. [8] Government of Canada, âAlgorithmic Impact Assessment Tool,â 2025. [Online].Available:https://w.canada.ca/en/government/system/ digital-government/digital-government-innovations/responsible-use-ai/ algorithmic-impact-assessment.html [9] CAC et al., âInterim Measures for the Administration of Generative Artificial Intelligence Services,â Jul. 2023, order No. 15. [Online]. Avail- able: https://w.cac.gov.cn/2023-07/13/c 1690898327029107.htm [10] PDPC Singapore and IMDA, âModel Artificial Intelligence Governance Framework,âPDPCSingaporeandIMDA,Tech.Rep.,Jan. 2020. [Online]. Available: https://w.pdpc.gov.sg/-/media/files/pdpc/ pdf-files/resource-for-organisation/ai/sgmodelaigovframework2.pdf [11] DSIT,âAPro-InnovationApproachtoAIRegulation,â HMGovernment,Tech.Rep.CP815,Mar.2023. [Online].Available:https://w.gov.uk/government/publications/ ai-regulation-a-pro-innovation-approach/white-paper [12] NITI Aayog, âResponsible AI #AIForAll: Approach Document for India, Part 1 â Principles for Responsible AI,â NITI Aayog, Tech. Rep., Feb. 2021. [Online]. Available: https://w.niti.gov.in/sites/default/ files/2021-02/Responsible-AI-22022021.pdf [13] S. Nativi and D. Nigris, âAI watch: AI standardisation landscape,â European Commission, 2021. [14] A. Steimers and M. Schneider, âSources of risk of AI systems,â Intl. Journal of Environmental Research and Public Health, 2022. [15] F. Bagehorn, K. Brimijoin, E. M. Daly, J. He, M. Hind, L. Garces- Erice, C. Giblin, I. Giurgiu, J. Martino, R. Nair et al., âAI risk atlas: Taxonomy and tooling for navigating AI risks and resources,â arXiv preprint arXiv:2503.05780, 2025. [16] P. Slattery, A. K. Saeri, E. A. Grundy, J. Graham et al., âThe AI risk repository: A comprehensive meta-review, database, and taxonomy of risks from artificial intelligence,â arXiv:2408.12622, 2024. [17] A. Critch and S. Russell, âTASRA: a taxonomy and analysis of societal- scale risks from AI,â arXiv preprint arXiv:2306.06924, 2023. [18] R. Uuk, C. I. Gutierrez et al., âA taxonomy of systemic risks from general-purpose AI,â arXiv:2412.07780, 2024. [19] A. Al-Maamari, âBetween innovation and oversight: A cross-regional study of AI risk management frameworks in the EU, US, UK, and China,â arXiv preprint arXiv:2503.05773, 2025. [20] A. Habbal, M. K. Ali, and M. A. Abuzaraida, âArtificial intelligence trust, risk and security management (AI trism): Frameworks, applica- tions, challenges and future research directions,â Expert Systems with Applications, vol. 240, p. 122442, 2024. [21] D. Hendrycks, M. Mazeika, and T. Woodside, âAn overview of catas- trophic AI risks,â arXiv preprint arXiv:2306.12001, 2023. [22] âOECDlegalinstrument0449.â[Online].Available:https: //legalinstruments.oecd.org/en/instruments/OECD-LEGAL-0449 [23] G. Falco et al., âGoverning AI safety through independent audits,â Nature Machine Intelligence, vol. 3, no. 7, p. 566â571, 2021. [24] A. Koshiyama et al., âAlgorithm auditing: Managing the legal, ethical, and technological risks of artificial intelligence, machine learning, and associated algorithms,â Computer, vol. 55, no. 4, p. 40â50, 2022. [25] A. Fell Ě ander, J. Rebane et al., âAchieving a data-driven risk assessment methodology for ethical AI,â Digital Society, vol. 1, no. 2, p. 13, 2022. [26] P. R. Nagbøl, O. M Ě uller, and O. Krancher, âDesigning a risk assessment tool for artificial intelligence systems,â in Intl. Conf. on Design Science Research in Information Systems and Technology, 2021, p. 328â339. [27] P. Giudici, M. Centurelli et al., âArtificial intelligence risk measure- ment,â Expert Systems with Applications, vol. 235, p. 121220, 2024. [28] X. Zhang, F. T. Chan, C. Yan, and I. Bose, âTowards risk-aware artificial intelligence and machine learning systems: An overview,â Decision Support Systems, vol. 159, p. 113800, 2022. [29] J. Irigoyen, R. Daza et al., âEduEVAL-DB: A Role-Based Dataset for Pedagogical Risk Evaluation in Educational Explanations,â in Int. Conf. on Learning Analytics & Knowledge Workshops (GenAI-LA), 2026. [30] J. Irigoyen, R. Daza, F. Jurado, J. Fierrez, R. Tolosana, A. Ortigosa et al., âAIriskEval-edu: New Dataset for Risk Assessment in AI-mediated K- 12 Educational Explanations,â in IEEE ICCST, 2026. [31] R. Daza et al., âEvaluating Social Engineering Risks in AI-based Interaction using Biometrics and a Gaming Setup,â in ICCST, 2026. [32] C. Novelli, F. Casolari, A. Rotolo, M. Taddeo, and L. Floridi, âAI risk assessment: A scenario-based, proportional methodology for the AI Act,â Digital Society, vol. 3, no. 1, p. 13, 2024. [33] L. Koessler and J. Schuett, âRisk assessment at AGI companies: A review of popular risk assessment techniques from other safety-critical industries,â arXiv preprint arXiv:2307.08823, 2023. [34] B. Xia et al., âTowards concrete and connected AI risk assessment (C2AIRA): A systematic mapping study,â in Intl. Conf. on AI Engi- neering (CAIN), 2023, p. 104â116. [35] D. DeAlcala et al., âIs my vision-language data in your AI? membership inference test (MINT) Demo 2,â in IEEE COMPSAC, 2026. [36] L. Pedrouzo et al., âLeveraging avatar fingerprinting: A photorealistic talking-head public database and benchmark,â arXiv:2603.26934, 2026. [37] J. Tello, M. de la Cruz, T. Ribeiro et al., âSymbolic AI (LFIT) for XAI to handle biases,â in European Conf. on Artificial Intelligence Workshops (ECAIw), ser. CEUR-WS, vol. 3523, October 2023. [38] A. Pe Ě na et al., âAddressing bias in LLMs: Strategies and application to fair AI-based recruitment,â in AAAI/ACM AIES, 2025. [39] P. Korshunov et al., âDeepID challenge of detecting synthetic manipu- lations in ID documents,â in IEEE ICCV Workshops, 2025. [40] G. Mancera et al., âPBa-LLM: Privacy-and bias-aware NLP using named-entity recognition (NER),â in IAPR ICDAR. Springer, 2025. [41] J. Mu Ě noz-Haro, R. Tolosana et al., âPrivacy-aware detection of fake identity documents: methodology, benchmark, and improved algorithms (FakeIDet2),â Information Fusion, vol. 128, p. 103969, 2026. [42] Ě A. Becerra, J. Irigoyen, R. Daza, R. Cobos, A. Morales, J. Fierrez, and M. Cukurova, âBiometrics and behavior analysis for detecting distrac- tions in e-learning,â in 2024 International Symposium on Computers in Education (SIIE). IEEE, 2024, p. 1â6. [43] S. Romero-Tapiador, R. Tolosana, A. Morales et al., âPersonalized weight loss management through wearable devices and artificial intelli- gence,â Computers in Biology and Medicine, vol. 209, p. 111676, 2026.