AI_ACTArt. 14voice-validated

AI_ACT Art14: Art. 14

AI_ACT

AL
Adam Lundqvist
Founder at SQUR · last verified 2026-10-06

Regulation text

High-risk AI systems shall be designed and developed in such a way that they can be effectively overseen by natural persons during the period in which they are in use. Human oversight measures aim at preventing or minimising the risks to health, safety, or fundamental rights that may emerge when a high-risk AI system is used in accordance with its intended purpose or under conditions of reasonably foreseeable misuse.

ATT&CK techniques this article tests · 0

TechniqueWhy it mapsConfidence

Defending mitigations · 0

MitigationWhat it doesConfidence

Underlying weaknesses · 6

CWEWhy it persistsConfidence
CWE-10041. Sensitive Data Storage in improperly protected memory regions directly creates risks to fundamental rights. 2. Art. 14 requires human oversight to minimize such risks, implying that design and development must address secure data handling.
80%
CWE-10211. Improper Restriction of Excessive Authentication Attempts enables brute-force attacks, undermining security. 2. Art. 14's mandate for preventing foreseeable misuse necessitates robust authentication mechanisms that human oversight can rely upon.
70%
CWE-10781. Inconsistent Interpretation of Policy directly hinders effective human oversight. 2. Art. 14 requires clear design for oversight, meaning policies must be unambiguous and consistently applied to prevent varied interpretations leading to risks.
90%
CWE-10901. Trusting All Input by Default makes AI systems vulnerable to malicious data, leading to misuse. 2. Art. 14 requires design to prevent risks from foreseeable misuse, which includes validating all inputs under human oversight.
80%
CWE-11141. Inappropriate Encoding for Output can lead to data corruption or information disclosure, impacting fundamental rights. 2. Human oversight, as per Art. 14, must ensure that AI system outputs are correctly and securely encoded to prevent such risks.
70%
CWE-11191. Incomplete List of Disallowed Inputs allows for foreseeable misuse by exploiting unhandled inputs. 2. Art. 14 mandates design to prevent risks from foreseeable misuse, requiring comprehensive input validation under human oversight.
80%

What SQUR Covers

Web application + API pentesting for OWASP Top 10, business logic flaws, authentication bypass, injection attacks, and other application-layer vulnerabilities. €1,995 per scan, 24-hour turnaround, EU-only data.

What SQUR Does Not Cover

Internal network pentesting, endpoint security testing, physical security assessments, social engineering, or ICT third-party concentration risk reviews. Engage a complementary provider for those scope items.

Provenance

Mapped Q2.2026 using gemini-2.5-flash · €0.0197 compute · voice-rubric self-validated