将欧盟人工智能法案要求转化为可操作的验证方法,助力合规落地。
Assessing High-Risk AI Systems under the EU AI Act: From Legal Requirements to Technical Verification
- 从法律条文分解出可执行的验证任务,匹配技术与组织实践。
- 建立全生命周期覆盖的验证活动框架,提升合规一致性。
- 适合监管机构、企业合规团队及AI开发者参考使用。
人工智能法案的实施需要具体的机制来验证法律义务的履行,但现有从高层要求到可验证评估活动的明确、可操作映射仍然有限,导致成员国准备程度不一。本文提出一种结构化映射,将高层级的人工智能法案要求转化为适用于整个AI生命周期的可实施验证活动。该映射通过系统性过程实现:将法律要求分解为可操作的子要求,并基于权威标准和公认实践进行夯实。在此基础上,识别并刻画了两类维度的验证活动:验证类型与适用生命周期阶段。该映射明确连接监管意图与技术和组织保障实践,降低解释歧义,为欧盟人工智能法案下一致、技术无关的合规验证提供可复用参考。
原文摘要 · Abstract (English)
The implementation of the AI Act requires practical mechanisms to verify compliance with legal obligations, yet concrete and operational mappings from high-level requirements to verifiable assessment activities remain limited, contributing to uneven readiness across Member States. This paper presents a structured mapping that translates high-level AI Act requirements into concrete, implementable verification activities applicable across the AI lifecycle. The mapping is derived through a systematic process in which legal requirements are decomposed into operational sub-requirements and grounded in authoritative standards and recognised practices. From this basis, verification activities are identified and characterised along two dimensions: the type of verification performed and the lifecycle target to which it applies. By making explicit the link between regulatory intent and technical and organisational assurance practices, the proposed mapping reduces interpretive uncertainty and provides a reusable reference for consistent, technology-agnostic compliance verification under the AI Act.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。