The organization is required to implement controls ensuring that artificial intelligence systems are operated strictly within their designated scope. The application of any AI system must be confined to the intended purposes that are formally defined and documented by the provider. Any use of the system outside these specified operational parameters is prohibited and must be actively prevented through established governance measures.






The organisation should define and document the characteristics, capabilities, and limitations of performance for each high-risk AI system. This documentation should clearly state the intended purpose of the AI system and be included in the instructions for use provided to deployers.






The organization should establish and implement processes to verify that AI systems are consistently used for their intended purposes, as defined and documented during the development or procurement phase. This includes reviewing usage patterns and comparing them against the documented scope and objectives of the AI system.






The organization must formally define and document its internal processes that govern the responsible use of AI systems by its personnel.
The purpose of these documented processes is to provide clear, actionable rules and guidance to ensure that all use of AI within the organization is ethical, safe, and aligned with legal requirements and organizational policies.
These processes should specify, for example:
Digiturvamallissa kaikki vaatimuskehikkojen vaatimukset kohdistetaan universaaleihin tietoturvatehtäviin, jotta voitte muodostaa yksittäisen suunnitelman, joka täyttää ison kasan vaatimuksia.
.png)