New Study Maps EU AI Act's High-Risk Requirements to AI Risk Taxonomies
Summarized by AI from reporting by ArXiv cs.AI, published under our editorial policy.
A study from the University of Amsterdam and the University of Oxford maps the EU AI Act's high-risk requirements to established AI risk taxonomies, revealing overlaps in transparency and data quality but gaps in technical risks like adversarial attacks and model bias.

Key takeaways
- The EU AI Act and established AI risk taxonomies share common ground in areas like transparency and data quality.
- The study identifies gaps in the EU AI Act's coverage of technical risks such as adversarial attacks and model bias.
- The research provides a detailed mapping between legal requirements and technical risk management practices.
Researchers from the University of Amsterdam and the University of Oxford released a study analyzing the alignment between the EU AI Act's high-risk requirements and established AI risk taxonomies. The study, published on arXiv, aims to bridge the gap between legal text and technical risk management practices in AI.
How the EU AI Act and Risk Taxonomies Compare
The EU AI Act introduces mandatory requirements for high-risk AI systems to ensure trustworthy AI development and operation. At the same time, AI risk management practices rely on structured risk taxonomies to identify and treat AI-specific risk sources. The study investigates whether the risks implicitly addressed by the Act align with those covered by existing risk taxonomies.
Overlaps and Gaps in Risk Coverage
The study identifies both overlaps and gaps between the EU AI Act's high-risk requirements and established risk taxonomies. For instance, the Act emphasizes transparency, accountability, and data quality, which are also key areas in most risk taxonomies. However, the study notes that some technical risk sources, such as adversarial attacks and model bias, are not explicitly covered by the Act's requirements. Conversely, the Act includes broader societal risks that are not always addressed in technical taxonomies.
Implications for Developers and Policymakers
This research is crucial for AI developers and policymakers. By understanding the alignment and gaps between legal requirements and technical risk management, developers can ensure their AI systems comply with the EU AI Act while effectively managing technical risks. For policymakers, the study provides insights into how the Act can be refined to better address the technical aspects of AI risk management.
Accessing the Full Study
If you are an AI developer or policymaker, you can start by reviewing the study on arXiv. The paper provides a detailed mapping of the EU AI Act's high-risk requirements to existing risk taxonomies, which can help you identify areas for improvement in your risk management practices. You can access the study at https://arxiv.org/abs/2609.13535.
Frequently asked
- Is the EU AI Act sufficient for managing all AI risks?
- The study suggests that while the Act covers many areas, it does not explicitly address all technical risks, such as adversarial attacks and model bias.
- How can AI developers use this study?
- The study provides a mapping of the EU AI Act's requirements to risk taxonomies, helping developers ensure compliance and effective risk management.