Hochrisiko-KI-Systeme: Pflichten des Betreibers

Hochrisiko-KI-Systeme: Pflichten des Betreibers

Sieben Anforderungsbereiche – alle müssen vor der Markteinführung erfüllt sein.

Was ist Hochrisiko-KI-Systeme: Pflichten des Betreibers?

A high-risk AI system has to meet seven requirement areas before launch, and most of them are the provider's to prove. You'll run a deployer's review of a system used on employee performance reviews, check the vendor's evidence area by area, and find the gaps that block launch. You'll leave knowing which duties are yours as the deployer, such as informing workers and assigning human oversight.

Was Sie lernen in Hochrisiko-KI-Systeme: Pflichten des Betreibers

Hochrisiko-KI-Systeme: Pflichten des Betreibers — Trainingsschritte

  1. Anforderungen an Hochrisiko-KI

    High-risk AI systems have the strictest obligations under the EU AI Act. The system itself must meet requirements across seven areas (Articles 9-15), and it is the provider's job to meet them (Article 16). As the deployer, you must see evidence of each before use, then meet your own duties under Article 26: Risk management - Identify and mitigate risks throughout the system lifecycle Data governance - Ensure training data is relevant, representative, and free from bias Technical documentation - Maintain detailed documentation of the system's design and function Record-keeping - Enable audit trails and automatic logging Transparency - Provide clear information to deployers and affected persons Human oversight - Ensure humans can effectively supervise the system Accuracy, robustness, and cybersecurity - Meet performance and security standards This exercise walks through a deployer's review of a real deployment: checking the provider's evidence and closing the gaps that are yours.

  2. E-Mail vom CISO

    Eine E-Mail von James Morton, dem CISO der Pinnacle Group, trifft ein. Der KI-Anbieter hat das System zur Leistungsbeurteilung von Mitarbeitenden geliefert, und Alice muss die Compliance-Prüfung vor dem Produktivstart abschließen. Die E-Mail verlinkt direkt auf das KI-Systeme-Register im Governance-Portal.

  3. KI-Systeme-Register

    Das KI-Systeme-Register wird mit drei Einträgen geladen: PerformanceAI (das neue, zur Prüfung gekennzeichnete Hochrisiko-KI-System) sowie zwei bereits konforme Systeme (EmailGuard und ChatAssist). Für jedes KI-System bei Pinnacle Group erfasst das Register Risikoklasse, Compliance-Status und Prüfverlauf.

  4. Compliance-Bewertung

    The PerformanceAI system has clear gaps in its compliance status: a FRIA is not required for a private employer, but the affected workers have not yet been informed, no human reviewer has been assigned, and data governance is still pending review. Alice clicks Run Compliance Assessment inside the PerformanceAI entry to open the detailed checklist for this system.

  5. Lücken kennzeichnen

    Alice works through each requirement section and flags only the items that are NOT satisfied. Data Governance has an unaddressed gap: training data representativeness across employee demographics has never been assessed. Human Oversight has another: no qualified human reviewer has been assigned with override authority. The remaining sections are in good shape and need nothing flagged. During the review, Alice encounters a note from the vendor: 'Human oversight is not needed because the algorithm has 99.2% accuracy in performance scoring.' This claim needs to be evaluated against what the EU AI Act actually requires.

  6. Anforderung an die menschliche Aufsicht

  7. Kritische Lücken identifiziert

    The compliance review has surfaced three critical gaps that must be resolved before PerformanceAI can go live: Workers not informed - Article 27's FRIA does not apply to a private employer, but Article 26(7) does: before a high-risk system is used at work, the employer must inform workers' representatives and the affected workers. That has not happened. No designated human reviewer - No person has been assigned with the authority and training to override the AI's performance scores. Article 26(2) requires the deployer to assign oversight to people with the competence, training and authority to exercise it (Article 14). Data representativeness not assessed - Training data has not been evaluated for representativeness across employee demographics, creating potential bias risk. Article 10 is the provider's duty, so Pinnacle must request PerformanceAI Inc.'s data governance documentation before launch. Each of these gaps represents a legal compliance failure. The system cannot be deployed until all three are resolved.

  8. E-Mail zur Behebung

    Alice verfasst eine Antwort-E-Mail an den CISO, in der sie die Compliance-Lücken im Detail aufführt und empfiehlt, den Launch zu verschieben, bis alle Probleme behoben sind.

  9. Compliance vor der Einführung

    High-risk AI deployment is not just 'install and configure.' It is a structured compliance process with ongoing obligations. The seven requirement areas are not checkboxes to rush through - they protect people affected by AI decisions. Key takeaways: All seven requirement areas must be independently satisfied before deployment, and the deployer should see the provider's evidence for each: risk management, data governance, technical documentation, record-keeping, transparency, human oversight, and accuracy/robustness/cybersecurity. Inform workers first. Before using high-risk AI at work, the employer must inform workers' representatives and the affected workers (Article 26(7)). A FRIA is mandatory only for public bodies, public-service providers and credit or insurance scoring deployers (Article 27). Human oversight cannot be replaced by accuracy . Even a 99.9% accurate system requires a designated human with override authority. If your compliance review finds gaps, the correct response is to delay deployment until they are resolved - not to deploy and fix later.

Abdeckung der Sicherheits-Frameworks

NIST CSF

  • PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind

EU AI Act

  • Art. 8 Compliance with the requirements
  • Art. 9 Risk management system