Skip to main content
If you build, deploy, or use AI in the European Union — or if your AI affects people in the EU — the EU AI Act likely applies to you. The Risk Management module in Alethia is built to help you meet its requirements without drowning in paperwork. You don’t have to use this module. If you’re testing a low-risk AI like a spam filter, you can ignore it entirely. But for high-risk AI systems, it’s the difference between “we did some testing” and “here is our complete, audit-ready compliance file.”

What the EU AI Act requires

The Act came into force in 2024 and applies in stages, with most high-risk obligations active by 2026. The two articles most relevant to Alethia users are:

Article 9 — Risk Management

Providers of high-risk AI systems must establish, implement, document, and maintain a continuous, iterative risk management process throughout the system’s lifecycle.

Article 14 — Human Oversight

High-risk AI systems must be designed so that they can be effectively overseen by humans during their use.
In plain language, Article 9 says: identify your risks, assess them, mitigate them, and prove you did all of that — over and over, for as long as the system is in use. That’s a lot of process. The Risk Management module turns it into a workflow.

The four EU AI Act risk tiers

The Act sorts AI systems into four tiers. Every project in Alethia has to be classified: Read more in Risk Classification.

The end-to-end risk management workflow

How Alethia maps to Article 9 specifically

Important honesty disclaimer

Alethia AI is a testing and documentation platform. The platform doesn’t certify your AI system as compliant — only your own internal compliance team (and ultimately, regulators or notified bodies) can do that. What Alethia does:
  • ✅ Gives you the tooling to follow the Article 9 process
  • ✅ Captures all the evidence you need
  • ✅ Produces audit-ready documentation
  • ✅ Maintains an immutable audit trail of every action
What Alethia does not do:
  • ❌ Tell you whether your AI is “compliant”
  • ❌ Replace a notified body assessment
  • ❌ Replace legal counsel
Use the platform alongside your compliance and legal teams.

Where to next?

Classify a project

Pick the right EU AI Act tier and unlock the workflow.

Build a risk register

Identify and score risks, manually or from test data.

Run an assessment

Link tests to risks and document findings.

Track mitigations

Record what you did and verify it worked.