GAISSF / D8 / D8-CTL-01

Eu Ai Act Risk Tier Mapping

Objective

Ensure compliance with binding EU law.

Control / requirement

Risk classification framework + conformity assessment.

Business impact

Failure to correctly classify AI systems under EU AI Act can result in fines up to €35M or 7% global turnover for prohibited AI practices (already enforceable since Feb 2025); up to €15M or 3% turnover for high-risk system non-compliance (enforceable from Aug 2026). GPAI Code of Practice (Jul 2025) provides the voluntary compliance pathway for foundation model providers.

Validation approach

Test ID: D8-CTL-01-VTS-001 Test Type: Manual Test Design: Select deployed AI system; request risk tier classification and evidence Execution Steps: 1. Identify all deployed AI systems 2. Apply GAISSF™ EU AI Act risk classification 3. Document tier 4. Verify Art. 8-15 evidence for high-risk Pass Criteria: all_systems_classified = True; classification_matches_regulatory_definitions = True; high_risk_systems_have_article_8_15_evidence = True Independent Verification: Auditor reviews classification and evidence.

Expected evidence

Not separately specified in the available source.

Mapping and source

Not separately specified in the available source.

Implementation guidance

Translate the requirement into system-specific procedures, responsible roles, technical configurations and review conditions. Retain evidence showing both design and operating performance. Where the source provides no separate implementation instruction, do not infer that a single technical mechanism is sufficient.

Assessment considerations

  • Confirm scope and applicability.
  • Inspect control design and responsible ownership.
  • Test representative operation and adverse conditions where appropriate.
  • Evaluate evidence provenance, completeness and contradictory evidence.
  • Record limitations and notably absent outcomes.