Just because you don't assess it,
it doesn't mean it's not there.
Risk Assessment: A definition
The EU AI Act does not provide a definition for the term "risk assessment", which it uses in a non-coherent manner. Therefore, the author has developed the following definition in her (unpublished) Master's thesis:
"Risk Assessment means a systematic, iterative, and documented overall process for identifying hazards associated with an AI system, for analyzing and estimating the resulting risks by determining the probability of harm occurring and the severity of that harm, and for subsequently evaluating the risks to enable informed decisions on risk mitigation and the acceptability of residual risks."
Recommendations
This briefing will be further developed. For individual advice on implementation and support, please contact the author directly.
Author
Claudia Otto
As a lawyer and researcher, Claudia specializes in AI safety, security, and risk assessment under the EU AI Act, the subject of her Master's thesis in Security and Disaster Management (MBA).
Need guidance on risk and compliance?

Cite this briefing
Otto, AI Risk Literacy, Risk Assessment: A definition, September 2025
