{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"AI Governance","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-AI-15","description":"Where the organization provides general-purpose AI models, maintain model technical documentation and information for downstream providers, implement a policy to comply with applicable copyright law including reservation-of-rights opt-outs, and publish a sufficiently detailed summary of training content. For models designated as posing systemic risk, additionally perform state-of-the-art model evaluations including adversarial testing, assess and mitigate systemic risks, track and report serious incidents to the competent authority, and ensure adequate cybersecurity protection for the model and its infrastructure.","details":{"control_category":"administrative","control_type":"preventive","domain":"AI Governance","guidance":[],"members":[{"control_id":"AIA-Art53","coverage":"full","framework":"eu-ai-act","relationship":"superset_of"},{"control_id":"AIA-Art55","coverage":"full","framework":"eu-ai-act","relationship":"superset_of"}],"statement":"Where the organization provides general-purpose AI models, maintain model technical documentation and information for downstream providers, implement a policy to comply with applicable copyright law including reservation-of-rights opt-outs, and publish a sufficiently detailed summary of training content. For models designated as posing systemic risk, additionally perform state-of-the-art model evaluations including adversarial testing, assess and mitigate systemic risks, track and report serious incidents to the competent authority, and ensure adequate cybersecurity protection for the model and its infrastructure.","title":"Fulfill general-purpose AI model provider obligations","unified_id":"UC-AI-15"},"id":"uc:UC-AI-15","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-AI-15","sourceIds":["eu-ai-act"],"sourceUrl":null,"title":"UC-AI-15 — Fulfill general-purpose AI model provider obligations","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1563b2b0bd47636d0d020287282be00abeaa2d66297aab541b39bf02f150bf87","properties":{},"sourceDetailPath":"/data/v1/records/wf-g1-14bc355c.json","sourceId":"wf:G1","targetDetailPath":"/data/v1/records/uc-uc-ai-15-eb9589c6.json","targetId":"uc:UC-AI-15","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:2e616772880bed151fc5f60db21881db6cf377bf05a5a9754373f10b5794845c","properties":{},"sourceDetailPath":"/data/v1/records/wf-r15-c0ebb27c.json","sourceId":"wf:R15","targetDetailPath":"/data/v1/records/uc-uc-ai-15-eb9589c6.json","targetId":"uc:UC-AI-15","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:44c186648e119017a3cd6e1536888d33f9de14741a7ec50e97a64807514e43c9","properties":{"rationale":"Assessing/mitigating systemic risks and reporting serious incidents reduces large-scale harm from powerful models.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-15-eb9589c6.json","sourceId":"uc:UC-AI-15","targetDetailPath":"/data/v1/records/risk-ai-safety-harm-to-people-d02cb500.json","targetId":"risk:ai-safety-harm-to-people","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7a773fb1e78534dc51329b05ae6a49c568389eee53a7cead548ae2dae672337f","properties":{"control_id":"AIA-Art53","coverage":"full","delta":null,"framework":"eu-ai-act","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Regulation (EU) 2024/1689"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-15-eb9589c6.json","sourceId":"uc:UC-AI-15","targetDetailPath":"/data/v1/records/ctrl-eu-ai-act-aia-art53-fd785909.json","targetId":"ctrl:eu-ai-act:AIA-Art53","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7d896e6a2108f3ef129303e21a416aee8ea46d62cb180a34c3c03ed7af50f87b","properties":{"rationale":"Mandated state-of-the-art adversarial testing plus model and infrastructure cybersecurity directly defend against adversarial attacks and model extraction.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-15-eb9589c6.json","sourceId":"uc:UC-AI-15","targetDetailPath":"/data/v1/records/risk-ai-adversarial-poisoning-attacks-ea7df068.json","targetId":"risk:ai-adversarial-poisoning-attacks","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:861d6bff9fa8849ae708758cd4cae4382f01bfcdc47225ebb9ba247113eb62f3","properties":{"rationale":"Directly discharges GPAI transparency/copyright/training-summary duties and, for systemic models, the red-teaming, incident reporting and cybersecurity the risk says are missing.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-15-eb9589c6.json","sourceId":"uc:UC-AI-15","targetDetailPath":"/data/v1/records/risk-ai-gpai-systemic-transparency-7a746323.json","targetId":"risk:ai-gpai-systemic-transparency","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b28ea7bff8a7a69df01a6a4d9b3d714b1e0a06a3413cb514b0e7aa17e4b438dd","properties":{"control_id":"AIA-Art55","coverage":"full","delta":null,"framework":"eu-ai-act","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Regulation (EU) 2024/1689"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-15-eb9589c6.json","sourceId":"uc:UC-AI-15","targetDetailPath":"/data/v1/records/ctrl-eu-ai-act-aia-art55-53ccdfc5.json","targetId":"ctrl:eu-ai-act:AIA-Art55","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c2cc8990d319f6229c728a174b7b58109a22ddcdef54abda54f0ec9704801617","properties":{"rationale":"Model technical documentation and downstream information supply model cards/datasheets for GPAI.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-15-eb9589c6.json","sourceId":"uc:UC-AI-15","targetDetailPath":"/data/v1/records/risk-ai-lack-explainability-transparency-edbd29e2.json","targetId":"risk:ai-lack-explainability-transparency","type":"mitigates"}],"schemaVersion":1}
