AI_ACTArt. 9voice-validated

AI_ACT Art9: Art. 9

AI_ACT

AL
Adam Lundqvist
Founder at SQUR · last verified 2026-10-06

Regulation text

A risk management system shall be established, implemented, documented and maintained in relation to high-risk AI systems. It shall consist of a continuous iterative process planned and run throughout the entire lifecycle of a high-risk AI system, including identification and analysis of known and foreseeable risks, estimation and evaluation of risks that may emerge, and adoption of appropriate risk management measures.

ATT&CK techniques this article tests · 0

TechniqueWhy it mapsConfidence

Defending mitigations · 7

MitigationWhat it doesConfidence
M10321. Art. 9 requires appropriate risk management measures. Multi-factor authentication (M1032) significantly reduces the risk of unauthorized access to AI systems, even if credentials are compromised.
95%
M10491. Art. 9 mandates continuous risk management. Robust user account management (M1049) ensures proper provisioning and deprovisioning, minimizing unauthorized access and privilege escalation risks in AI systems.
90%
M10161. Art. 9 requires identification and analysis of known risks. Comprehensive vulnerability management (M1016) is essential for proactively addressing weaknesses in AI systems and their infrastructure.
95%
M10301. Art. 9's risk management includes limiting impact. Network segmentation (M1030) isolates high-risk AI systems, containing potential breaches and preventing lateral movement by attackers.
85%
M10531. Art. 9 requires measures for risks that may emerge. Data backup (M1053) is a critical risk management measure to ensure recovery and business continuity following data destruction or corruption in AI systems.
90%
M10371. Art. 9 mandates appropriate risk management measures. Access restriction (M1037) limits access to AI system components and data, reducing the attack surface and potential for unauthorized manipulation.
90%
M10471. Art. 9 requires a continuous iterative process for risk management. A robust incident response capability (M1047) is fundamental for detecting, responding to, and recovering from security incidents affecting AI systems.
95%

Underlying weaknesses · 7

CWEWhy it persistsConfidence
CWE-201. Art. 9 requires identifying foreseeable risks. Improper Input Validation (CWE-20) is a fundamental weakness leading to various vulnerabilities, including adversarial attacks on AI models.
95%
CWE-2841. Art. 9 mandates risk identification. Improper Access Control (CWE-284) directly contributes to unauthorized access to AI systems, models, or sensitive data, increasing overall risk.
90%
CWE-3271. Art. 9 requires evaluating risks. Use of a Broken or Risky Cryptographic Algorithm (CWE-327) can compromise the confidentiality and integrity of data within high-risk AI systems.
85%
CWE-4341. Art. 9's risk analysis includes emerging threats. Unrestricted Upload of File with Dangerous Type (CWE-434) can allow attackers to introduce malicious code or poisoned models into AI systems.
80%
CWE-5021. Art. 9 requires identifying foreseeable risks. Deserialization of Untrusted Data (CWE-502) is a critical weakness that can lead to remote code execution within AI system pipelines.
75%
CWE-7981. Art. 9 mandates risk identification. Use of Hard-coded Credentials (CWE-798) significantly increases the risk of unauthorized access if these credentials are discovered by attackers.
80%
CWE-9151. Art. 9 requires evaluating risks that may emerge. Improperly Controlled Modification of Dynamically-Determined Object Attributes (CWE-915) can lead to model poisoning or manipulation in AI systems.
70%

What SQUR Covers

Web application + API pentesting for OWASP Top 10, business logic flaws, authentication bypass, injection attacks, and other application-layer vulnerabilities. €1,995 per scan, 24-hour turnaround, EU-only data.

What SQUR Does Not Cover

Internal network pentesting, endpoint security testing, physical security assessments, social engineering, or ICT third-party concentration risk reviews. Engage a complementary provider for those scope items.

Provenance

Mapped Q2.2026 using gemini-2.5-flash · €0.0194 compute · voice-rubric self-validated