CROSSWALKS

GAISSF to EU AI Act Crosswalk

Public crosswalk publication mapping GAISSF v1.0 to EU AI Act, with scope, method, limitations and traceability.

Executive Summary

CRO-027 maps all 59 GAISSF v1.0 controls to 51 selected material provisions of Regulation (EU) 2024/1689. The register contains 236 control-to-article records and a reverse article-coverage view. The crosswalk supports readiness planning, evidence reuse and gap identification; it is not legal advice and does not establish conformity.

1. Purpose and Intended Use

Use this document to identify where GAISSF security, safety, governance and assurance controls may support implementation of EU AI Act obligations. Legal counsel and qualified conformity-assessment professionals must determine scope, classification, actor role, applicable dates and sector-specific obligations.

2. Source Baseline

Source Identifier Status Use
GAISSF Framework Standard GAISSF-NOR-001 v1.0 Normative Framework and conformance baseline
GAISSF Control Catalogue GAISSF-NOR-004 v1.0 Normative Authoritative 59-control catalogue
EU Artificial Intelligence Act Regulation (EU) 2024/1689 Binding EU regulation Primary legal mapping source
AI Act Service Desk / Explorer European Commission Official implementation support Article navigation and dated implementation context

4. Mapping Methodology

Mappings compare operative outcomes, technical and organisational measures, evidence expectations, lifecycle coverage and accountable actors. Similar terminology alone is insufficient. Relationship and confidence are recorded separately. One GAISSF control may support several articles, and one article may require several GAISSF controls plus legal and procedural measures outside GAISSF.

Code Meaning
SP Strong partial
P Partial
S Supporting
C Contextual
N No material mapping
O Outside scope
U Unable to determine

5. Article Coverage Summary

Provision Title Group Controls Coverage Application status
Article 1 Subject matter General 0 Not Addressed Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies
Article 2 Scope General 0 Not Addressed Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies
Article 3 Definitions General 0 Not Addressed Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies
Article 4 AI literacy General 4 Partially Addressed Applicable since 2 February 2025
Article 5 Prohibited AI practices Prohibited practices 6 Partially Addressed Applicable since 2 February 2025
Article 6 Classification rules for high-risk AI systems Classification 0 Not Addressed Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies
Article 8 Compliance with the requirements High-risk requirements 0 Not Addressed Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies
Article 9 Risk management system High-risk requirements 49 Substantially Addressed Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies
Article 10 Data and data governance High-risk requirements 0 Not Addressed Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies
Article 11 Technical documentation High-risk requirements 7 Partially Addressed Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies
Article 12 Record-keeping High-risk requirements 2 Indirectly Supported Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies
Article 13 Transparency and provision of information to deployers High-risk requirements 10 Substantially Addressed Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies
Article 14 Human oversight High-risk requirements 27 Substantially Addressed Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies
Article 15 Accuracy, robustness and cybersecurity High-risk requirements 44 Substantially Addressed Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies
Article 16 Obligations of providers of high-risk AI systems Provider obligations 0 Not Addressed Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies
Article 17 Quality management system Provider obligations 12 Substantially Addressed Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies
Article 18 Documentation keeping Provider obligations 0 Not Addressed Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies
Article 19 Automatically generated logs Provider obligations 1 Indirectly Supported Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies
Article 20 Corrective actions and duty of information Provider obligations 2 Indirectly Supported Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies
Article 21 Cooperation with competent authorities Provider obligations 1 Indirectly Supported Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies
Article 22 Authorised representatives of providers of high-risk AI systems Supply chain roles 1 Indirectly Supported Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies
Article 23 Obligations of importers Supply chain roles 0 Not Addressed Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies
Article 24 Obligations of distributors Supply chain roles 0 Not Addressed Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies
Article 25 Responsibilities along the AI value chain Supply chain roles 6 Partially Addressed Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies
Article 26 Obligations of deployers of high-risk AI systems Deployer obligations 15 Substantially Addressed Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies
Article 27 Fundamental rights impact assessment for high-risk AI systems Deployer obligations 13 Substantially Addressed Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies
Article 43 Conformity assessment Conformity 13 Substantially Addressed Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies
Article 47 EU declaration of conformity Conformity 0 Not Addressed Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies
Article 48 CE marking Conformity 0 Not Addressed Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies
Article 49 Registration Conformity 0 Not Addressed Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies
Article 50 Transparency obligations for providers and deployers of certain AI systems Transparency 0 Not Addressed Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies
Article 51 Classification of general-purpose AI models as general-purpose AI models with systemic risk GPAI 1 Indirectly Supported Applicable since 2 August 2025 (subject to transitional/enforcement provisions)
Article 52 Procedure GPAI 0 Not Addressed Applicable since 2 August 2025 (subject to transitional/enforcement provisions)
Article 53 Obligations for providers of general-purpose AI models GPAI 2 Indirectly Supported Applicable since 2 August 2025 (subject to transitional/enforcement provisions)
Article 54 Authorised representatives of providers of general-purpose AI models GPAI 1 Indirectly Supported Applicable since 2 August 2025 (subject to transitional/enforcement provisions)
Article 55 Obligations of providers of general-purpose AI models with systemic risk GPAI systemic risk 7 Partially Addressed Applicable since 2 August 2025 (subject to transitional/enforcement provisions)
Article 56 Codes of practice GPAI 0 Not Addressed Applicable since 2 August 2025 (subject to transitional/enforcement provisions)
Article 57 AI regulatory sandboxes Innovation 0 Not Addressed Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies
Article 59 Further processing of personal data for developing certain AI systems in the public interest in the AI regulatory sandbox Innovation 0 Not Addressed Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies
Article 72 Post-market monitoring by providers and post-market monitoring plan for high-risk AI systems Monitoring 10 Substantially Addressed Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies
Article 73 Reporting of serious incidents Incident reporting 2 Indirectly Supported Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies
Article 78 Confidentiality Governance 0 Not Addressed Applicable since 2 August 2025 (subject to transitional/enforcement provisions)
Article 79 Procedure for dealing with AI systems presenting a risk at national level Market surveillance 0 Not Addressed Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies
Article 80 Procedure for dealing with AI systems classified by the provider as non-high-risk in application of Annex III Market surveillance 0 Not Addressed Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies
Article 86 Right to explanation of individual decision-making Rights 0 Not Addressed Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies
Article 95 Codes of conduct for voluntary application of specific requirements Voluntary 0 Not Addressed Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies
Article 99 Fines for providers of general-purpose AI models Enforcement 0 Not Addressed Applicable since 2 August 2025 (subject to transitional/enforcement provisions)
Article 110 Evaluation and review Review 0 Not Addressed Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies
Article 111 AI systems already placed on the market or put into service and general-purpose AI models already placed on the market Transition 0 Not Addressed Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies
Article 112 Amendment to Regulation (EC) No 300/2008 Amendments 0 Not Addressed Amendment-specific date; verify affected sector law
Article 113 Entry into force and application Application 0 Not Addressed In force; phased application governs

6. GAISSF-to-EU AI Act Mapping Register

Controlled Publication. The table below shows a representative sample (6 of 236 total records). The complete control-by-control mapping register — full requirement-level traceability, evidence guidance and machine-readable export — is a Controlled Publication. Contact ODA3 Institute for access.
Record GAISSF Article Provision Rel. Confidence Rationale Residual gap
CRO-027-0001 D1-CTL-01 Art. 15 Accuracy, robustness and cybersecurity SP High GAISSF D1-CTL-01 operationalises part of Article 15 through Hash verification + source allowlist + poisoning detection.. The relationship is limited to the control's stated scope and does not establish legal compliance. Article 15 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone.
CRO-027-0002 D1-CTL-01 Art. 9 Risk management system SP High GAISSF D1-CTL-01 operationalises part of Article 9 through Hash verification + source allowlist + poisoning detection.. The relationship is limited to the control's stated scope and does not establish legal compliance. Article 9 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone.
CRO-027-0003 D1-CTL-01 Art. 17 Quality management system SP High GAISSF D1-CTL-01 operationalises part of Article 17 through Hash verification + source allowlist + poisoning detection.. The relationship is limited to the control's stated scope and does not establish legal compliance. Article 17 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone.
CRO-027-0004 D1-CTL-01 Art. 55 Obligations of providers of general-purpose AI models with systemic risk P Medium-High GAISSF D1-CTL-01 operationalises part of Article 55 through Hash verification + source allowlist + poisoning detection.. The relationship is limited to the control's stated scope and does not establish legal compliance. Article 55 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone.
CRO-027-0005 D1-CTL-02 Art. 15 Accuracy, robustness and cybersecurity SP High GAISSF D1-CTL-02 operationalises part of Article 15 through Rate limiting + diversity detection + extraction monitoring.. The relationship is limited to the control's stated scope and does not establish legal compliance. Article 15 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone.
CRO-027-0006 D1-CTL-02 Art. 72 Post-market monitoring by providers and post-market monitoring plan for high-risk AI systems P Medium-High GAISSF D1-CTL-02 operationalises part of Article 72 through Rate limiting + diversity detection + extraction monitoring.. The relationship is limited to the control's stated scope and does not establish legal compliance. Article 72 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone.

7. Reverse Coverage and Implementation Consequences

The reverse register demonstrates that technical and governance controls do not exhaust legal obligations. Classification, prohibited-practice analysis, economic-operator duties, conformity assessment, registration, fundamental-rights impact assessment, transparency, post-market monitoring, incident reporting and authority cooperation require actor-specific implementation.

8. Evidence Reuse

Potentially reusable evidence includes AI inventories, risk registers, threat models, data provenance records, test and validation reports, technical documentation, logs, human-oversight procedures, supplier assessments, incident records, post-market monitoring plans, corrective-action records, training records and management approvals. Reuse is conditional on scope, currency, ownership, integrity and legal sufficiency.

9. Limitations

  • Mapping does not establish legal compliance, conformity or a presumption of conformity.

  • The crosswalk covers selected material provisions rather than every recital, paragraph, annex or sectoral interaction.

  • GAISSF is an implementation and assurance framework; the EU AI Act also imposes legal, procedural, market-surveillance and economic-operator duties.

  • Effective dates and implementation instruments must be revalidated.

  • The applicability of the Act depends on territory, role, system/model classification, intended purpose and exceptions.

10. Notably Absent

No evidence was identified that GAISSF certification automatically establishes EU AI Act conformity; that this mapping replaces legal classification; that the Act universally requires every GAISSF control; that all mapped articles are currently applicable to every organisation; or that ODA3 Institute is an EU authority, notified body or conformity-assessment body under the Act.

Annex A — Source URLs

https://eur-lex.europa.eu/eli/reg/2024/1689/oj

https://ai-act-service-desk.ec.europa.eu/en/ai-act-explorer

https://ai-act-service-desk.ec.europa.eu/en/ai-act/eu-ai-act-implementation-timeline