AI_ACTArt. 9voice-validated
AI_ACT Art9: Art. 9
AI_ACT
AL
Founder at SQUR · last verified 2026-10-06
Regulation text
A risk management system shall be established, implemented, documented and maintained in relation to high-risk AI systems. It shall consist of a continuous iterative process planned and run throughout the entire lifecycle of a high-risk AI system, including identification and analysis of known and foreseeable risks, estimation and evaluation of risks that may emerge, and adoption of appropriate risk management measures.
ATT&CK techniques this article tests · 0
| Technique | Why it maps | Confidence |
|---|
Defending mitigations · 7
| Mitigation | What it does | Confidence |
|---|---|---|
| M1032 | 1. Art. 9 requires appropriate risk management measures. Multi-factor authentication (M1032) significantly reduces the risk of unauthorized access to AI systems, even if credentials are compromised. | 95% |
| M1049 | 1. Art. 9 mandates continuous risk management. Robust user account management (M1049) ensures proper provisioning and deprovisioning, minimizing unauthorized access and privilege escalation risks in AI systems. | 90% |
| M1016 | 1. Art. 9 requires identification and analysis of known risks. Comprehensive vulnerability management (M1016) is essential for proactively addressing weaknesses in AI systems and their infrastructure. | 95% |
| M1030 | 1. Art. 9's risk management includes limiting impact. Network segmentation (M1030) isolates high-risk AI systems, containing potential breaches and preventing lateral movement by attackers. | 85% |
| M1053 | 1. Art. 9 requires measures for risks that may emerge. Data backup (M1053) is a critical risk management measure to ensure recovery and business continuity following data destruction or corruption in AI systems. | 90% |
| M1037 | 1. Art. 9 mandates appropriate risk management measures. Access restriction (M1037) limits access to AI system components and data, reducing the attack surface and potential for unauthorized manipulation. | 90% |
| M1047 | 1. Art. 9 requires a continuous iterative process for risk management. A robust incident response capability (M1047) is fundamental for detecting, responding to, and recovering from security incidents affecting AI systems. | 95% |
Underlying weaknesses · 7
| CWE | Why it persists | Confidence |
|---|---|---|
| CWE-20 | 1. Art. 9 requires identifying foreseeable risks. Improper Input Validation (CWE-20) is a fundamental weakness leading to various vulnerabilities, including adversarial attacks on AI models. | 95% |
| CWE-284 | 1. Art. 9 mandates risk identification. Improper Access Control (CWE-284) directly contributes to unauthorized access to AI systems, models, or sensitive data, increasing overall risk. | 90% |
| CWE-327 | 1. Art. 9 requires evaluating risks. Use of a Broken or Risky Cryptographic Algorithm (CWE-327) can compromise the confidentiality and integrity of data within high-risk AI systems. | 85% |
| CWE-434 | 1. Art. 9's risk analysis includes emerging threats. Unrestricted Upload of File with Dangerous Type (CWE-434) can allow attackers to introduce malicious code or poisoned models into AI systems. | 80% |
| CWE-502 | 1. Art. 9 requires identifying foreseeable risks. Deserialization of Untrusted Data (CWE-502) is a critical weakness that can lead to remote code execution within AI system pipelines. | 75% |
| CWE-798 | 1. Art. 9 mandates risk identification. Use of Hard-coded Credentials (CWE-798) significantly increases the risk of unauthorized access if these credentials are discovered by attackers. | 80% |
| CWE-915 | 1. Art. 9 requires evaluating risks that may emerge. Improperly Controlled Modification of Dynamically-Determined Object Attributes (CWE-915) can lead to model poisoning or manipulation in AI systems. | 70% |
What SQUR Covers
Web application + API pentesting for OWASP Top 10, business logic flaws, authentication bypass, injection attacks, and other application-layer vulnerabilities. €1,995 per scan, 24-hour turnaround, EU-only data.
What SQUR Does Not Cover
Internal network pentesting, endpoint security testing, physical security assessments, social engineering, or ICT third-party concentration risk reviews. Engage a complementary provider for those scope items.
Provenance
Mapped Q2.2026 using gemini-2.5-flash · €0.0194 compute · voice-rubric self-validated