Executive Summary

The EU AI Act (Articles 9-15) establishes risk management, data governance, documentation, human oversight, and security requirements for AI systems. AIR Blackbox provides controls that map directly to these articles and align with ISO 42001 (AI Management System) and NIST AI RMF (AI Risk Management Framework) standards.

This document shows how each EU AI Act article relates to specific ISO 42001 controls and NIST AI RMF categories. It serves as a bridge between regulatory requirements and technical implementation.

Summary Mapping Table

EU AI Act Article ISO 42001 Controls NIST AI RMF Functions Coverage
Article 9 A.5.1-A.5.4 GOVERN-1, MAP-1, MAP-2, MEASURE-1 Full Coverage
Article 10 A.7.1-A.7.3, A.6.2 GOVERN-1, MAP-1, MEASURE-2 Full Coverage
Article 11 A.6.2, A.8.1 GOVERN-1, MAP-1, MAP-3 Full Coverage
Article 12 A.8.2-A.8.3, A.9.1-A.9.2 GOVERN-1, MEASURE-3, MANAGE-1 Partial Coverage
Article 14 A.9.1-A.9.2, A.6.1 GOVERN-3, MEASURE-4, MANAGE-2 Full Coverage
Article 15 A.5.4, A.7.1, A.8.1 GOVERN-1, MEASURE-2, MEASURE-4, MANAGE-2 Full Coverage

Detailed Article Mappings

9
Risk Management
Full Coverage

Risk classification of tool calls (LOW → CRITICAL). Enforcement of risk-based blocking policies. Systematic identification and mitigation of AI system risks.

ISO 42001 Controls
A.5.1 Risk management policy
A.5.2 Risk assessment
A.5.3 Risk treatment
A.5.4 Risk monitoring
NIST AI RMF Functions
GOVERN-1 Establish governance structures
MAP-1 Map AI systems and dependencies
MAP-2 Identify impact of AI systems
MEASURE-1 Measure performance
11
Data Governance
Full Coverage

PII redaction across recruiting, finance (PCI-DSS), healthcare (HIPAA), and legal domains. GDPR Article 30 processing manifests. Data erasure support.

ISO 42001 Controls
A.7.1 Data governance
A.7.2 Data quality
A.7.3 Data management
A.6.2 Information security
NIST AI RMF Functions
GOVERN-1 Establish governance structures
MAP-1 Map AI systems and dependencies
MEASURE-2 Measure performance for fairness/bias
11
Technical Documentation
Full Coverage

Structured audit logging of full call graphs: chain → LLM → tool → result. Complete technical documentation of AI system operation.

ISO 42001 Controls
A.6.2 Information security
A.8.1 Documentation and records
NIST AI RMF Functions
GOVERN-1 Establish governance structures
MAP-1 Map AI systems and dependencies
MAP-3 Characterize AI system components
12
Record-Keeping
Partial Coverage

HMAC-SHA256 tamper-evident chains. Cryptographically signed and linked event logs. Partial coverage: retention policies and long-term archive strategies require organizational process enhancements.

ISO 42001 Controls
A.8.2 Records management
A.8.3 Archival and disposal
A.9.1 Incident management
A.9.2 Compliance monitoring
NIST AI RMF Functions
GOVERN-1 Establish governance structures
MEASURE-3 Measure performance for incident detection
MANAGE-1 Manage documented incidents
14
Human Oversight
Full Coverage

Exception-based blocking for critical operations. Humans remain in the decision loop. Full audit trails enable post-hoc review and human accountability.

ISO 42001 Controls
A.9.1 Incident management
A.9.2 Compliance monitoring
A.6.1 Organizational controls
NIST AI RMF Functions
GOVERN-3 Establish supply chain risk management
MEASURE-4 Measure performance for human oversight
MANAGE-2 Manage incidents and risks
15
Robustness & Security
Full Coverage

Injection detection (15+ weighted patterns). RAG write gates with source allowlists and content filtering. Real-time drift detection for retrieval anomalies. Defense-in-depth against adversarial attacks.

ISO 42001 Controls
A.5.4 Risk monitoring
A.7.1 Data governance
A.8.1 Documentation and records
NIST AI RMF Functions
GOVERN-1 Establish governance structures
MEASURE-2 Measure security performance
MEASURE-4 Measure adversarial resilience
MANAGE-2 Manage identified risks

Coverage Definitions

Full Coverage Complete Compliance

AIR Blackbox provides comprehensive controls that fully satisfy the article's requirements. Regulatory compliance is achievable through proper implementation and configuration of the technical controls provided.

Partial Coverage Requires Organizational Processes

AIR Blackbox provides core technical controls, but the article also requires organizational governance, policy, or process enhancements beyond the software. Technical controls alone are insufficient; complementary business processes must be established.

Legal Disclaimer: This is a technical reference document, not legal advice. The mapping presented here reflects AIR Blackbox's technical interpretation of the EU AI Act, ISO 42001, and NIST AI RMF. Actual compliance obligations depend on your specific jurisdiction, industry, and AI system risk classification. Please consult legal counsel to ensure compliance with all applicable regulations. AIR Blackbox is not liable for compliance gaps resulting from reliance on this document.