Plain-language summary
Providers of high-risk AI systems must establish, implement, document, and maintain a continuous risk management system throughout the AI system's lifecycle. This system requires regular reviews and updates to identify, analyze, and evaluate risks to health, safety, or fundamental rights, including those affecting vulnerable groups. Providers must estimate and assess these risks, implement measures to mitigate them, and ensure remaining risks are acceptable. The system must also include testing to validate risk management measures and confirm the AI system operates as intended.