**Article 9**

**Establishment and Lifecycle of the Risk Management System**  
Horizon Analytics Group has developed and instituted a comprehensive risk management system in accordance with Article 9(1) and (2) applicable to the Election Sentiment Transformer (EST), classifying it as a high-risk AI system due to its potential impact on fundamental rights related to free and fair democratic processes. The risk management system is embedded throughout the entire lifecycle of EST, encompassing design, development, deployment, maintenance, and decommissioning phases. This iterative process is reviewed biannually and updated based on new findings from post-market monitoring activities and system performance data, ensuring continual capture and mitigation of emerging risks. Documented procedures stipulate regular internal audits and cross-functional risk assessment workshops incorporating risk identification, evaluation, and mitigation measure validation.

**Risk Identification and Analysis**  
The risk management framework initiates with a robust identification and analysis of known and reasonably foreseeable risks under EST’s intended purpose—that is, the generation and dissemination of targeted messaging affecting electoral sentiment through social media data streams. A multidisciplinary expert panel conducted an impact analysis using scenario modeling to enumerate risks including misinformation amplification, manipulation of vulnerable voter groups (particularly minors and socioeconomically marginalized populations), adverse effects on political pluralism, and potential biases perpetuated by training data skew. This analysis leveraged datasets of over 750 million public social media posts from prior electoral cycles and incorporated synthetic stress tests simulating adversarial input and coordinated misinformation campaigns. Weighing both systemic risks (e.g., societal polarization) and individual risks (e.g., undue influence on specific voters) guided the comprehensive risk catalog.

**Risk Estimation and Evaluation under Intended and Misuse Conditions**  
Following identification, risks were quantitatively estimated using probabilistic modeling to assess likelihoods and impacts under nominal operation and plausible misuse scenarios, such as deployment in contexts with insufficient demographically representative data or attempts to target disinformation via coordinated user manipulation. The EST underwent Monte Carlo simulations applying perturbation of input data distributions to evaluate model stability and robustness, showing an expected mean error rate in sentiment prediction of 4.3% under normal conditions and up to 9.1% under specified misuse conditions. The evaluation rigorously considered the interaction of algorithmic bias with external manipulative behaviors, and the model demonstrated resilience in limiting risk escalation through embedded mitigation layers. Metrics from real-world pilot tests involving 15 million anonymized user interactions reinforced these quantitative estimations.

**Post-Market Risk Evaluation Based on Monitoring Data**  
The risk management system incorporates continuous feedback from the post-market monitoring system per Article 72. Horizon Analytics Group operates an automated data collection subsystem that aggregates anonymized performance logs, user engagement statistics, and external audit findings. Monthly trend analyses are conducted to detect deviations from baseline risk thresholds, including shifts in algorithmic fairness indicators and emergent error patterns. For instance, an uptick in false positive identification of sentiment polarization was detected and promptly traced to changes in social media platform metadata standards, triggering an adjustment of model input preprocessing layers to restore performance margins. These activities form part of a dynamic risk reassessment protocol ensuring adaptive mitigation measures.

**Design and Development Measures for Risk Mitigation**  
Risk reduction is primarily achieved through an ensemble of technical and procedural controls implemented during EST's design and development stages. Architecturally, the transformer model incorporates attention mechanisms calibrated to reduce overfitting on demographic correlates that could propagate bias. The training dataset, comprising 2.8 billion labelled text snippets from diverse geographic and linguistic contexts, underwent rigorous cleaning, augmentation, and fairness auditing to pre-emptively address representational imbalances. The development lifecycle included adversarial testing with synthetic and real-world manipulation attempts to evaluate defense robustness, resulting in the incorporation of dynamic input validation filters and anomaly detection modules. Model explainability features were embedded to facilitate transparency and accountability, enabling both provider and deployer to interpret decision pathways. These measures eliminate or reduce identified risks to the extent technically feasible.

**Mitigation and Control Measures for Residual Risks**  
For risks that cannot be entirely eliminated by technical design—such as nuanced impacts on voter perception stemming from the nature of persuasive messaging—operational safeguards are in place. Detailed and context-specific technical documentation provides instructions on appropriate use contexts to deployers, emphasizing the necessity of complementary human oversight and ethical guidelines adherence. User interface provisions include warnings against targeting minors or vulnerable groups under age 18, informed by demographic risk profiling and vulnerability assessments. Training materials for deployers cover identification of misuse patterns and escalation procedures. Furthermore, an internal compliance committee regularly reviews risk residuals, assessing their acceptability with respect to societal and regulatory standards before model updates are finalized.

**Testing Framework and Performance Assurance**  
Extensive testing protocols, aligned with Articles 9(6) and 9(8), underpin risk management effectiveness. EST underwent progressive testing phases from component-level functional tests through integrated system validation, including deployment in controlled real-world social media environments simulating electoral cycles. Performance metrics such as sentiment prediction accuracy, false positive/negative rates, fairness indices (e.g., demographic parity and equal opportunity difference), and robustness scores were established upfront with probabilistic thresholds (e.g., minimum 92% accuracy, maximum 5% false positive rate in sentiment classification). Recurrent testing cycles have consistently met or exceeded these thresholds. Real-world pilot testing involved collaboration with electoral commissions, ensuring compliance with ethical standards and verifying the system’s consistent operation under realistic temporal and data volume constraints. Adversarial stress tests further confirmed stability under abnormal input conditions or data shifts.

**Consideration of Vulnerable Groups and Minors**  
Special attention was devoted to assessing and mitigating adverse effects on persons under 18 and other vulnerable populations, in compliance with Article 9(9). Demographic analyses identified segments with high social media usage but limited digital literacy, such as adolescents aged 16-17, and groups with potential cognitive susceptibility to persuasive messaging. The system’s content generation module incorporates filters to exclude messaging designed to influence these groups, and deployment guidelines explicitly recommend restrictions or opt-outs for minors’ inclusion in data inputs. Post-market monitoring includes tracking of engagement metrics disaggregated by age where permissible, triggering risk reassessment if disproportionate influence is observed. These measures ensure that protection of vulnerable groups is embedded within both technical design and operational policies.

**Integration with Broader Risk Management Obligations**  
Recognizing the AI system’s intersection with regulatory frameworks governing data protection, media integrity, and electoral transparency, Horizon Analytics Group coordinates its risk management procedures with obligations arising under applicable Union laws concerning data privacy and electoral conduct. This integrated approach ensures that Article 9’s stipulations coexist with and complement other internal risk management requirements, enabling coherent compliance oversight without redundancy or conflict, in line with Article 9(10). The risk management records and audit logs are designed for seamless integration with these broader compliance artifacts.