GAISSF to EU AI Act Crosswalk
Public crosswalk publication mapping GAISSF v1.0 to EU AI Act, with scope, method, limitations and traceability.
Executive Summary
CRO-027 maps all 59 GAISSF v1.0 controls to 51 selected material provisions of Regulation (EU) 2024/1689. The register contains 236 control-to-article records and a reverse article-coverage view. The crosswalk supports readiness planning, evidence reuse and gap identification; it is not legal advice and does not establish conformity.
1. Purpose and Intended Use
Use this document to identify where GAISSF security, safety, governance and assurance controls may support implementation of EU AI Act obligations. Legal counsel and qualified conformity-assessment professionals must determine scope, classification, actor role, applicable dates and sector-specific obligations.
2. Source Baseline
| Source | Identifier | Status | Use |
|---|---|---|---|
| GAISSF Framework Standard | GAISSF-NOR-001 v1.0 | Normative | Framework and conformance baseline |
| GAISSF Control Catalogue | GAISSF-NOR-004 v1.0 | Normative | Authoritative 59-control catalogue |
| EU Artificial Intelligence Act | Regulation (EU) 2024/1689 | Binding EU regulation | Primary legal mapping source |
| AI Act Service Desk / Explorer | European Commission | Official implementation support | Article navigation and dated implementation context |
3. Legal and Temporal Interpretation
The Act applies in phases. A mapped article may be enacted but not yet applicable to a particular actor or system. This document does not incorporate proposals as if they were adopted law. Users shall verify the Official Journal, amendments, delegated and implementing acts, harmonised standards, codes of practice and competent-authority guidance at the date of reliance.
4. Mapping Methodology
Mappings compare operative outcomes, technical and organisational measures, evidence expectations, lifecycle coverage and accountable actors. Similar terminology alone is insufficient. Relationship and confidence are recorded separately. One GAISSF control may support several articles, and one article may require several GAISSF controls plus legal and procedural measures outside GAISSF.
| Code | Meaning |
|---|---|
| SP | Strong partial |
| P | Partial |
| S | Supporting |
| C | Contextual |
| N | No material mapping |
| O | Outside scope |
| U | Unable to determine |
5. Article Coverage Summary
| Provision | Title | Group | Controls | Coverage | Application status |
|---|---|---|---|---|---|
| Article 1 | Subject matter | General | 0 | Not Addressed | Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies |
| Article 2 | Scope | General | 0 | Not Addressed | Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies |
| Article 3 | Definitions | General | 0 | Not Addressed | Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies |
| Article 4 | AI literacy | General | 4 | Partially Addressed | Applicable since 2 February 2025 |
| Article 5 | Prohibited AI practices | Prohibited practices | 6 | Partially Addressed | Applicable since 2 February 2025 |
| Article 6 | Classification rules for high-risk AI systems | Classification | 0 | Not Addressed | Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies |
| Article 8 | Compliance with the requirements | High-risk requirements | 0 | Not Addressed | Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies |
| Article 9 | Risk management system | High-risk requirements | 49 | Substantially Addressed | Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies |
| Article 10 | Data and data governance | High-risk requirements | 0 | Not Addressed | Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies |
| Article 11 | Technical documentation | High-risk requirements | 7 | Partially Addressed | Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies |
| Article 12 | Record-keeping | High-risk requirements | 2 | Indirectly Supported | Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies |
| Article 13 | Transparency and provision of information to deployers | High-risk requirements | 10 | Substantially Addressed | Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies |
| Article 14 | Human oversight | High-risk requirements | 27 | Substantially Addressed | Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies |
| Article 15 | Accuracy, robustness and cybersecurity | High-risk requirements | 44 | Substantially Addressed | Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies |
| Article 16 | Obligations of providers of high-risk AI systems | Provider obligations | 0 | Not Addressed | Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies |
| Article 17 | Quality management system | Provider obligations | 12 | Substantially Addressed | Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies |
| Article 18 | Documentation keeping | Provider obligations | 0 | Not Addressed | Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies |
| Article 19 | Automatically generated logs | Provider obligations | 1 | Indirectly Supported | Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies |
| Article 20 | Corrective actions and duty of information | Provider obligations | 2 | Indirectly Supported | Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies |
| Article 21 | Cooperation with competent authorities | Provider obligations | 1 | Indirectly Supported | Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies |
| Article 22 | Authorised representatives of providers of high-risk AI systems | Supply chain roles | 1 | Indirectly Supported | Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies |
| Article 23 | Obligations of importers | Supply chain roles | 0 | Not Addressed | Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies |
| Article 24 | Obligations of distributors | Supply chain roles | 0 | Not Addressed | Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies |
| Article 25 | Responsibilities along the AI value chain | Supply chain roles | 6 | Partially Addressed | Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies |
| Article 26 | Obligations of deployers of high-risk AI systems | Deployer obligations | 15 | Substantially Addressed | Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies |
| Article 27 | Fundamental rights impact assessment for high-risk AI systems | Deployer obligations | 13 | Substantially Addressed | Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies |
| Article 43 | Conformity assessment | Conformity | 13 | Substantially Addressed | Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies |
| Article 47 | EU declaration of conformity | Conformity | 0 | Not Addressed | Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies |
| Article 48 | CE marking | Conformity | 0 | Not Addressed | Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies |
| Article 49 | Registration | Conformity | 0 | Not Addressed | Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies |
| Article 50 | Transparency obligations for providers and deployers of certain AI systems | Transparency | 0 | Not Addressed | Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies |
| Article 51 | Classification of general-purpose AI models as general-purpose AI models with systemic risk | GPAI | 1 | Indirectly Supported | Applicable since 2 August 2025 (subject to transitional/enforcement provisions) |
| Article 52 | Procedure | GPAI | 0 | Not Addressed | Applicable since 2 August 2025 (subject to transitional/enforcement provisions) |
| Article 53 | Obligations for providers of general-purpose AI models | GPAI | 2 | Indirectly Supported | Applicable since 2 August 2025 (subject to transitional/enforcement provisions) |
| Article 54 | Authorised representatives of providers of general-purpose AI models | GPAI | 1 | Indirectly Supported | Applicable since 2 August 2025 (subject to transitional/enforcement provisions) |
| Article 55 | Obligations of providers of general-purpose AI models with systemic risk | GPAI systemic risk | 7 | Partially Addressed | Applicable since 2 August 2025 (subject to transitional/enforcement provisions) |
| Article 56 | Codes of practice | GPAI | 0 | Not Addressed | Applicable since 2 August 2025 (subject to transitional/enforcement provisions) |
| Article 57 | AI regulatory sandboxes | Innovation | 0 | Not Addressed | Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies |
| Article 59 | Further processing of personal data for developing certain AI systems in the public interest in the AI regulatory sandbox | Innovation | 0 | Not Addressed | Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies |
| Article 72 | Post-market monitoring by providers and post-market monitoring plan for high-risk AI systems | Monitoring | 10 | Substantially Addressed | Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies |
| Article 73 | Reporting of serious incidents | Incident reporting | 2 | Indirectly Supported | Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies |
| Article 78 | Confidentiality | Governance | 0 | Not Addressed | Applicable since 2 August 2025 (subject to transitional/enforcement provisions) |
| Article 79 | Procedure for dealing with AI systems presenting a risk at national level | Market surveillance | 0 | Not Addressed | Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies |
| Article 80 | Procedure for dealing with AI systems classified by the provider as non-high-risk in application of Annex III | Market surveillance | 0 | Not Addressed | Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies |
| Article 86 | Right to explanation of individual decision-making | Rights | 0 | Not Addressed | Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies |
| Article 95 | Codes of conduct for voluntary application of specific requirements | Voluntary | 0 | Not Addressed | Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies |
| Article 99 | Fines for providers of general-purpose AI models | Enforcement | 0 | Not Addressed | Applicable since 2 August 2025 (subject to transitional/enforcement provisions) |
| Article 110 | Evaluation and review | Review | 0 | Not Addressed | Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies |
| Article 111 | AI systems already placed on the market or put into service and general-purpose AI models already placed on the market | Transition | 0 | Not Addressed | Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies |
| Article 112 | Amendment to Regulation (EC) No 300/2008 | Amendments | 0 | Not Addressed | Amendment-specific date; verify affected sector law |
| Article 113 | Entry into force and application | Application | 0 | Not Addressed | In force; phased application governs |
6. GAISSF-to-EU AI Act Mapping Register
| Record | GAISSF | Article | Provision | Rel. | Confidence | Rationale | Residual gap |
|---|---|---|---|---|---|---|---|
| CRO-027-0001 | D1-CTL-01 | Art. 15 | Accuracy, robustness and cybersecurity | SP | High | GAISSF D1-CTL-01 operationalises part of Article 15 through Hash verification + source allowlist + poisoning detection.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 15 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. |
| CRO-027-0002 | D1-CTL-01 | Art. 9 | Risk management system | SP | High | GAISSF D1-CTL-01 operationalises part of Article 9 through Hash verification + source allowlist + poisoning detection.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 9 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. |
| CRO-027-0003 | D1-CTL-01 | Art. 17 | Quality management system | SP | High | GAISSF D1-CTL-01 operationalises part of Article 17 through Hash verification + source allowlist + poisoning detection.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 17 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. |
| CRO-027-0004 | D1-CTL-01 | Art. 55 | Obligations of providers of general-purpose AI models with systemic risk | P | Medium-High | GAISSF D1-CTL-01 operationalises part of Article 55 through Hash verification + source allowlist + poisoning detection.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 55 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. |
| CRO-027-0005 | D1-CTL-02 | Art. 15 | Accuracy, robustness and cybersecurity | SP | High | GAISSF D1-CTL-02 operationalises part of Article 15 through Rate limiting + diversity detection + extraction monitoring.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 15 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. |
| CRO-027-0006 | D1-CTL-02 | Art. 72 | Post-market monitoring by providers and post-market monitoring plan for high-risk AI systems | P | Medium-High | GAISSF D1-CTL-02 operationalises part of Article 72 through Rate limiting + diversity detection + extraction monitoring.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 72 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. |
7. Reverse Coverage and Implementation Consequences
The reverse register demonstrates that technical and governance controls do not exhaust legal obligations. Classification, prohibited-practice analysis, economic-operator duties, conformity assessment, registration, fundamental-rights impact assessment, transparency, post-market monitoring, incident reporting and authority cooperation require actor-specific implementation.
8. Evidence Reuse
Potentially reusable evidence includes AI inventories, risk registers, threat models, data provenance records, test and validation reports, technical documentation, logs, human-oversight procedures, supplier assessments, incident records, post-market monitoring plans, corrective-action records, training records and management approvals. Reuse is conditional on scope, currency, ownership, integrity and legal sufficiency.
9. Limitations
Mapping does not establish legal compliance, conformity or a presumption of conformity.
The crosswalk covers selected material provisions rather than every recital, paragraph, annex or sectoral interaction.
GAISSF is an implementation and assurance framework; the EU AI Act also imposes legal, procedural, market-surveillance and economic-operator duties.
Effective dates and implementation instruments must be revalidated.
The applicability of the Act depends on territory, role, system/model classification, intended purpose and exceptions.
10. Notably Absent
No evidence was identified that GAISSF certification automatically establishes EU AI Act conformity; that this mapping replaces legal classification; that the Act universally requires every GAISSF control; that all mapped articles are currently applicable to every organisation; or that ODA3 Institute is an EU authority, notified body or conformity-assessment body under the Act.
Annex A — Source URLs
https://eur-lex.europa.eu/eli/reg/2024/1689/oj
https://ai-act-service-desk.ec.europa.eu/en/ai-act-explorer
https://ai-act-service-desk.ec.europa.eu/en/ai-act/eu-ai-act-implementation-timeline