Section 1 - Risk identification and evaluation
Organization identify and differentiate the risks of AI systems based on the risk classification pursuant EU-AI-Act. The first step is to find out if the AI Systems provide a forbidden practice while using and interaction with us humans. Second step is to identify if it´s a high-risk AI system pursuant Art. 6 EU-AI-Act. If no, then identify if its an AI system with or without a systemic risk pursuant Art. 50 EU-AI-Act. Based on this results derivate the regulatory requirements the AI-System has to follow and to fulfill. Additional to this we have to identify the possible user group of the AI-System and to find out specific risks we have to handle and to mitigate with this group, especially if its a vulnerable user group. In this context we have to check, the way of access to the AI-System. The other risks are from the use case, the purpose, physical product in which the AI-System will work, possible interactions with other AI systems and the area of operation, e.g. autonomous driving, health case. Finally we have to check, what will happen, when the AI-System doesn´t work, when data processings are interrupted or the automated decision making make mistakes - what would be the consequences for provider, deployer and user groups. Based on this results we can create a risk register including probability, risk score and extent of damage.
We are using technical tools to identify and evaluate risks.
My organization is a consulting company to guide through EU-AI-Act, ISO/IEC42001 and additional norms and standards from ISO/IEC, IEEE etc. For testing we refer to tools like "Orthrus" from AI & Partners.
At the moment only if a data breach pursuant GDPR is happened. Currently we are in the beginning with the understanding of EU-AI-Act and how we can implement it. For future it would be great opportunity to help other organizations with incident reporting and to offer programs how responsible can solve problems and mitigate risks of their AI-Systems.
Yes, we are in the Network of Governance Experts from AI & Partners, IEEE.org. A global risk register would be helpful in the future to share experiences of AI Systems and their risks and tools/workflows to mitigate the risks.
Using of this standards, e.g. IEEE 7000-2021, ISO/IEC42001, ISO/IEC5259-1, NIST 2.0 Cybersecurity Framework
Particular, I recommend to my clients to install an ethic-board or an expert of AI-Ethics/AI-Risks in other advisory boards or steering committees and to create a risk register to have an overwiew about the mitigation status.
Creating of policy for risk management in context with AI based on HLC of ISO/IEC42001 and additional Norm ISO/IEC23894:2023 AI Guidance on risk management, Implementing a protection level concept including a threshold to trigger an approval procedure, if the risk level is to high. Implementing real-time-monitoring features as part of post-marked monitoring, Implementing Iteration to review and mitigate the risks asap.


























