AI_ACTArt. 10voice-validated
AI_ACT Art10: Art. 10
AI_ACT
AL
Founder at SQUR · last verified 2026-10-06
Regulation text
High-risk AI systems making use of techniques involving training of models with data shall be developed on the basis of training, validation and testing data sets that meet quality criteria. Data governance and management practices shall address relevance, representativeness, freedom from errors, biases that could impact health, safety or fundamental rights, and appropriate statistical properties.
ATT&CK techniques this article tests · 15
| Technique | Why it maps | Confidence |
|---|---|---|
| T1190 | 1. Unpatched data ingestion APIs or data management portals can be exploited, directly violating the "quality criteria" and "data governance" requirements of Art. 10. | 90% |
| T1566 | 1. Social engineering to gain access to data sources or systems managing training data directly undermines the integrity and governance mandated by Art. 10. | 80% |
| T1078 | 1. Compromised legitimate accounts provide unauthorized access to data, enabling manipulation or exfiltration, contrary to Art. 10's data governance. | 90% |
| T1547 | 1. Malicious scripts or services persisting on data processing infrastructure can continuously corrupt or exfiltrate data, violating Art. 10's quality and governance. | 70% |
| T1068 | 1. Gaining higher privileges on data management systems allows attackers to bypass controls and manipulate critical training data, directly impacting Art. 10's quality criteria. | 80% |
| T1027 | 1. Attackers can obfuscate malicious data injections or modifications within training datasets, evading detection and violating Art. 10's freedom from errors and biases. | 70% |
| T1003 | 1. Stealing credentials for data access systems enables unauthorized data manipulation or exfiltration, directly undermining the data governance required by Art. 10. | 80% |
| T1083 | 1. Discovering sensitive training, validation, or testing data sets is a precursor to their manipulation or exfiltration, impacting Art. 10's data quality and governance. | 70% |
| T1005 | 1. Collecting training data from local systems for exfiltration or modification directly compromises the data integrity and governance mandated by Art. 10. | 80% |
| T1071 | 1. Using common application protocols for C2 allows attackers to control data manipulation or exfiltration, bypassing data governance controls under Art. 10. | 70% |
| T1041 | 1. Exfiltrating sensitive training data via C2 channels directly violates data governance and can expose biases or errors, contrary to Art. 10. | 90% |
| T1485 | 1. Destroying training, validation, or testing data directly prevents the AI system from meeting quality criteria and impacts its availability, violating Art. 10. | 90% |
| T1486 | 1. Encrypting critical AI training data for ransom directly impacts the system's ability to meet quality criteria and disrupts operations, violating Art. 10. | 90% |
| T1561 | 1. Wiping disks containing training or validation data leads to irreversible data loss, directly preventing compliance with Art. 10's data quality and availability requirements. | 80% |
| T1490 | 1. Attacking backup systems or recovery mechanisms for training data prevents restoration, ensuring data quality and availability requirements of Art. 10 cannot be met. | 80% |
Defending mitigations · 6
| Mitigation | What it does | Confidence |
|---|---|---|
| M1031 | 1. Isolating data processing and storage environments reduces the attack surface, protecting training data integrity as required by Art. 10. | 90% |
| M1035 | 1. Restricting network access to data sources and AI training infrastructure directly supports data governance and prevents unauthorized data manipulation, per Art. 10. | 90% |
| M1047 | 1. Regular auditing of data access and modification logs helps detect and prevent unauthorized changes to training data, ensuring compliance with Art. 10's quality criteria. | 90% |
| M1028 | 1. Secure configuration of operating systems hosting data processing prevents privilege escalation and unauthorized access to training data, supporting Art. 10's quality requirements. | 80% |
| M1050 | 1. Regularly scanning data management systems for vulnerabilities helps identify and remediate weaknesses that could compromise data quality or governance, as mandated by Art. 10. | 80% |
| M1017 | 1. Strict user account management, including least privilege and regular reviews, prevents unauthorized access and manipulation of training data, aligning with Art. 10's data governance. | 90% |
Underlying weaknesses · 7
| CWE | Why it persists | Confidence |
|---|---|---|
| CWE-20 | 1. Lack of validation on input data can introduce errors or biases into training datasets, directly violating Art. 10's requirement for freedom from errors and biases. | 90% |
| CWE-287 | 1. Weak authentication mechanisms allow unauthorized access to data management systems, enabling manipulation or exfiltration of training data, contrary to Art. 10's governance. | 90% |
| CWE-269 | 1. Over-privileged accounts or systems can lead to unauthorized modification or destruction of training data, directly impacting the quality criteria of Art. 10. | 90% |
| CWE-352 | 1. CSRF vulnerabilities in data management web interfaces could allow attackers to force legitimate users to make unwanted changes to data, impacting Art. 10's data integrity. | 70% |
| CWE-502 | 1. Processing untrusted serialized data can lead to remote code execution, allowing attackers to compromise data processing systems and manipulate training data, violating Art. 10. | 80% |
| CWE-798 | 1. Hard-coded credentials for data access systems create a single point of failure, enabling unauthorized access and manipulation of training data, contrary to Art. 10's governance. | 80% |
| CWE-732 | 1. Improper file or directory permissions on training data sets allow unauthorized modification or deletion, directly undermining the quality and integrity mandated by Art. 10. | 90% |
What SQUR Covers
Web application + API pentesting for OWASP Top 10, business logic flaws, authentication bypass, injection attacks, and other application-layer vulnerabilities. €1,995 per scan, 24-hour turnaround, EU-only data.
What SQUR Does Not Cover
Internal network pentesting, endpoint security testing, physical security assessments, social engineering, or ICT third-party concentration risk reviews. Engage a complementary provider for those scope items.
Provenance
Mapped Q2.2026 using gemini-2.5-flash · €0.0183 compute · voice-rubric self-validated · 1 hallucination(s) dropped at validation