REAL

Risk Management and Accountability under the EU AI Act: From High-Risk AI Systems to Agentic AI

Mezei, Kitti (2026) Risk Management and Accountability under the EU AI Act: From High-Risk AI Systems to Agentic AI. MTA LAW WORKING PAPERS (14). ISSN 2064-4515

[img]
Preview
Text
Mezei_Kitti_2026_szeptember.pdf - Published Version

Download (861kB) | Preview

Abstract

In the risk-based regulatory design of the AI Act, the intensity of legal intervention is determined by the level and nature of risk: the applicable obligations and legal consequences are calibrated to the system’s risk category, ranging from lighter requirements through ex ante compliance obligations to outright prohibition. This approach leaves the identification, assessment and mitigation of concrete risks largely to the regulated actors, while seeking to make that assessment reviewable through documentation and regulatory oversight. A central question is therefore whether the self-assessments conducted by providers of AI systems are substantively reviewable. Because the risks associated with the same technology depend on its intended purpose, deployment context, and the safeguards in place, the regulatory framework cannot rely on ex ante classification alone. For high-risk AI systems, this approach is reflected in a set of interrelated requirements concerning risk management, data governance, transparency and human oversight. Although formally distinct, these obligations are functionally part of the same lifecycle-based process, running from the identification and mitigation of risks through the transmission of information and human oversight to ex post review. This model is built in part on a co-regulatory logic: provider-side risk management, standardisation, conformity assessment and regulatory supervision operate as interrelated elements. Such arrangements may provide flexibility and draw on private expertise, but they also raise a central accountability problem: regulatory responsibility is distributed across public and private actors, while the legitimacy of the framework depends on whether the exercise of regulatory judgment remains transparent, reviewable and subject to external scrutiny. The challenge is therefore to preserve the advantages of private participation in regulatory implementation without weakening the level of accountability expected of public regulation. In the context of AI systems, this requires not only identifying the actor formally responsible for compliance, but also ensuring that the relevant risk management decisions and assumptions can subsequently be reconstructed and assessed. This study examines the AI Act’s risk-based approach primarily through the requirements applicable to high-risk AI systems, since it is for these systems that the AI Act lays down lifecycle-wide requirements linking risk management to the ongoing reviewability of compliance.

Item Type: Article
Subjects: K Law / jog > K Law (General) / jogtudomány általában
Depositing User: Dr. Kitti Mezei
Date Deposited: 26 Sep 2026 10:17
Last Modified: 26 Sep 2026 10:17
URI: https://real.mtak.hu/id/eprint/247776

Actions (login required)

View Item View Item