**Article 9**

**Establishment and Scope of the Risk Management System**  
Aegis Mobility Technologies has established and documented a comprehensive risk management system for the Guardian Signal Controller, consistent with the continuous and iterative lifecycle framework mandated for high-risk AI systems. This system is designed to monitor and evaluate risks associated with the AI-driven detection and classification of traffic participants, primarily at urban intersections. The identified scope focuses on risks to health, safety, and fundamental rights arising from misclassification errors, particularly the known risk of misidentifying cyclists under low-light conditions, a scenario substantiated through extensive testing involving 23,000 annotated video clips collected from diverse urban intersections over a 12-month period. Although enhanced feature extraction techniques (e.g., infrared imaging or advanced temporal filtering) and adaptive thresholding approaches were considered for mitigating cyclist misclassification, the provider determined these interventions to be currently unimplemented, based on a balanced assessment of technical complexity, latency requirements for real-time signal control, and integration constraints within existing municipal infrastructure.

**Risk Identification, Analysis, and Estimation**  
The system incorporates an initial risk identification process grounded in domain-specific hazard analysis. This process recognizes that failure modes such as cyclist misclassification during low-light scenarios—accounting for approximately 7% of deployment conditions—may lead to suboptimal traffic signal adjustments and elevated risk of collisions or delayed green-phase allocation. Performance benchmarking against a labeled dataset showed that the CNN-Random Forest ensemble achieved a cyclist detection recall of 87% under daylight conditions, which declined to approximately 72% during dusk and night-time. Data gathered during simulated misuse conditions, including occlusion scenarios and sensor noise exceeding normal operating parameters, further informed risk estimation. Despite these residual risks, the system’s design scope confines modifications primarily to alerting downstream municipal operators post-event rather than pursuing in-situ algorithmic intervention.

**Continuous Monitoring and Post-Market Data Integration**  
Post-market monitoring is executed through secure telemetry streams transmitting anonymized event logs and detection confidence scores. These data, collected under Article 72 provisions, facilitate systematic review of false positives and false negatives, particularly cyclist-related misdetections during low-visibility intervals. Analytical pipelines incorporate temporal trend analyses that have revealed an incremental 3-4% variance in detection accuracy correlated with seasonal lighting changes. These insights are periodically reviewed during scheduled risk management meetings and inform updates to alert protocols or operator guidance but do not precipitate integration of additional adaptive thresholding or enhanced feature extraction modules at present.

**Risk Management Measures and Rationale**  
In alignment with risk mitigation prioritization, the Guardian Signal Controller implements targeted risk management measures focused on operator alerting mechanisms and procedural controls rather than front-end AI system redesign for cyclist detection. Specifically, the system generates event-based alerts when classifier confidence falls below predefined thresholds, prompting municipal operators to verify and, if necessary, manually override signal timing decisions. This strategy relies on the assumption that human-in-the-loop intervention mitigates safety risks associated with residual algorithmic errors. The decision to eschew algorithmic enhancement such as low-light feature augmentation was supported by an internal cost-benefit analysis that weighed the latency penalty and deployment complexity against marginal gains in detection recall. Concomitantly, the provider's documentation supplies deployers with technical guidance on recognizing conditions prone to decreased classifier reliability, with recommended operator training addressing these operational contingencies.

**Testing Protocols and Validation Measures**  
Extensive testing of the Guardian Signal Controller has been conducted under real-world and controlled conditions, encompassing over 400 hours of field tests in varied weather and lighting environments. Performance metrics include precision, recall, and F1-score evaluations specific to pedestrian, vehicle, and cyclist classes. Testing against prior defined metrics—such as a minimum 75% cyclist recall under all lighting conditions before deployment—demonstrated marginal fulfillment, with particular shortfalls in twilight and urban night-time conditions documented. Testing was repeated iteratively throughout system development, with incremental model retraining conducted using datasets including 15 million sensor readings alongside video annotations. However, due to the provider’s strategic decision to rely on post-detection alerting for residual risk management, no adaptive thresholding or feature extraction techniques beyond conventional RGB image processing were integrated prior to market release.  

**Consideration of Vulnerable Groups and Intended Use Context**  
Given that cyclists and pedestrians include individuals potentially under 18 years of age and other vulnerable road users, the risk management approach incorporates this sensitivity in both data analysis and operator guidance documentation. The system’s operator alerts explicitly emphasize caution when traffic conditions suggest the presence of vulnerable users under reduced visibility scenarios. While the AI component itself does not modify classification thresholds based on user age or vulnerability status, the procedural controls expect municipal operators to factor such considerations into signal timing decisions and intervention protocols. Training materials provided to deployers address the need for heightened awareness of vulnerable groups, prescribing specific operational instructions during low-visibility periods where cyclist detection confidence is known to decline.

**Integration with Other Compliance Frameworks**  
Aegis Mobility Technologies aligns the Guardian Signal Controller’s risk management processes with broader internal quality and safety management systems under relevant Union standards. This integration ensures that risk-related data collected pursuant to Article 9 are incorporated into unified workflows and documentation, facilitating coordinated oversight without duplicative processes. The system’s risk management lifecycle integrates seamlessly with security and data integrity controls, ensuring that identified risks linked to misclassification are thoroughly tracked, reviewed, and communicated to responsible deployment entities.