FREE RESOURCE — EU AI ACT
CAIQ → EU AI Act mapping
A free crosswalk from the CSA Consensus Assessments Initiative Questionnaire (CAIQ v4) — the security questionnaire buyers already send you — to the EU AI Act deployer obligations under Article 26 and the transparency obligations under Article 50 of Regulation (EU) 2024/1689. Each row pairs a CAIQ question with the specific Act requirement it satisfies and the evidence you should hold. Reusable under CC-BY-4.0.
Security and procurement teams already run vendors through the CAIQ. Much of what the CAIQ asks overlaps with what the EU AI Act now requires of deployers of high-risk AI — but the two frameworks use different language, so the overlap is easy to miss. This mapping makes it explicit: answer the CAIQ once, and reuse the same evidence to demonstrate Article 26 and Article 50 readiness.
| CAIQ v4 item | EU AI Act requirement (Art 26 / 50) | Evidence to hold |
|---|---|---|
| GRC-06Do you have a documented acceptable-use / AI use policy governing how AI systems may be operated, and who is authorised to oversee them? | Art 26(1)-(2)The deployer must use the high-risk AI system in line with the provider's instructions for use, and assign human oversight to natural persons who have the necessary competence, training and authority to supervise, intervene and, where needed, suspend the system. | AI use policy referencing the provider's instructions for use; named human-oversight role with a written role description and documented authority to intervene or suspend. |
| AIS-09Are users informed, at the point of interaction, when they are interacting with an AI system rather than a human? | Art 50(1)AI systems intended to interact directly with natural persons must be designed so those persons are informed they are interacting with an AI system, unless obvious from context. The information must be provided at the first interaction and in a clear, machine-readable, accessible form. | Screenshot / DOM export of the first-interaction disclosure; the machine-readable marking (e.g. metadata or accessible label); an accessibility check of the notice placement. |
| LOG-05Do you retain automatically generated audit logs, and for how long are incidents and system events tracked? | Art 26(5)-(6)The deployer must monitor operation on the basis of the instructions for use and, where under its control, keep the logs automatically generated by the high-risk AI system for at least six months, unless other Union or national law (notably GDPR) provides otherwise; serious incidents are reported under Article 73. | Log-export procedure; retention policy stating the six-month (or longer) window; immutable-storage evidence; incident log with timestamps and escalation path to provider and market-surveillance authority. |
| A&A-02Do staff who operate or oversee the system receive role-appropriate training, and are training records kept? | Art 4Providers and deployers must ensure, to their best extent, a sufficient level of AI literacy of staff and other persons operating AI systems on their behalf, considering their technical knowledge, experience, education and the context of use. In application since 2 February 2025. | Role-based AI-literacy matrix; dated per-person training records; refresher cadence tied to system or version changes. |
| SEF-03Do you have an incident-response process, and do you notify affected parties and authorities within defined timeframes? | Art 26(5) + Art 73Where the deployer has reason to consider that use may present a risk under Article 79(1), it must inform the provider/distributor and the market-surveillance authority without undue delay and suspend use; serious incidents are reported to the provider and, where applicable, the authority under Article 73. | Incident-response runbook; suspension procedure; notification templates and a log evidencing timeliness of notification to provider and authority. |
| DSP-07Do you govern the quality and representativeness of input data used with the system, to the extent you control it? | Art 26(4)To the extent the deployer exercises control over the input data, it must ensure that input data is relevant and sufficiently representative in view of the intended purpose of the high-risk AI system. | Data-governance policy; control inventory identifying which input fields the deployer (vs. provider) owns; documented data-quality checks on the controlled fields. |
| HRS-08Before deploying a system that affects staff in the workplace, do you inform workers' representatives and affected workers? | Art 26(7)Employers who are deployers of a high-risk AI system in the workplace must, before putting it into service or use, inform workers' representatives and the affected workers that they will be subject to its use. | Works-council briefing minute; dated written notice to affected employees before go-live; intranet publication evidence. |
| GRC-11Where the system makes or assists decisions about individuals, are those individuals told they are subject to it? | Art 26(11)Deployers of Annex III high-risk systems that make, or assist in making, decisions related to natural persons must inform the persons concerned that they are subject to the use of the high-risk AI system. | Standardised disclosure text embedded in decision communications (offer, rejection, review); audit trail showing the disclosure was sent. |
| DSP-14Do you run a data-protection impact assessment (DPIA) where personal data is processed, using provider-supplied information? | Art 26(9)Where applicable, deployers must use the information provided under Article 13 to comply with their DPIA obligation under Article 35 GDPR. The DPIA remains the deployer's responsibility. | DPIA document explicitly referencing the provider's Article 13 instructions; DPO sign-off; periodic-review cadence. |
| STA-05Do you cooperate with regulators and produce records on request in relation to the systems you operate? | Art 26(12)Deployers must cooperate with the relevant competent authorities on any action those authorities take in relation to the high-risk AI system to implement the Regulation. | Single point of contact identified; document-production playbook; legal-hold procedure for AI-system records. |
| AIS-12For AI-generated or manipulated media, do you disclose that the content is artificially generated? | Art 50(4)Deployers of an AI system that generates or manipulates image, audio or video content constituting a deep fake, or that generates text published to inform the public on matters of public interest, must disclose the artificial generation (with limited exemptions). Applies from 2 August 2026. | Standard disclosure caption; editorial workflow check; exemption-rationale memo where an Article 50(4) exemption is relied upon. |
| IPY-03Can you export your data and logs in a portable, machine-readable format if you change or exit the provider? | Art 26(6) (supporting)Log retention under the deployer's control presupposes the deployer can actually obtain and hold those logs; portability of logs and records underpins the six-month retention and any authority request under Article 26(12). | Documented export path (format + procedure) for logs and records; test export retained as evidence. |
GRC-06 → Art 26(1)-(2)
CAIQ: Do you have a documented acceptable-use / AI use policy governing how AI systems may be operated, and who is authorised to oversee them?
AI Act: The deployer must use the high-risk AI system in line with the provider's instructions for use, and assign human oversight to natural persons who have the necessary competence, training and authority to supervise, intervene and, where needed, suspend the system.
Evidence: AI use policy referencing the provider's instructions for use; named human-oversight role with a written role description and documented authority to intervene or suspend.
AIS-09 → Art 50(1)
CAIQ: Are users informed, at the point of interaction, when they are interacting with an AI system rather than a human?
AI Act: AI systems intended to interact directly with natural persons must be designed so those persons are informed they are interacting with an AI system, unless obvious from context. The information must be provided at the first interaction and in a clear, machine-readable, accessible form.
Evidence: Screenshot / DOM export of the first-interaction disclosure; the machine-readable marking (e.g. metadata or accessible label); an accessibility check of the notice placement.
LOG-05 → Art 26(5)-(6)
CAIQ: Do you retain automatically generated audit logs, and for how long are incidents and system events tracked?
AI Act: The deployer must monitor operation on the basis of the instructions for use and, where under its control, keep the logs automatically generated by the high-risk AI system for at least six months, unless other Union or national law (notably GDPR) provides otherwise; serious incidents are reported under Article 73.
Evidence: Log-export procedure; retention policy stating the six-month (or longer) window; immutable-storage evidence; incident log with timestamps and escalation path to provider and market-surveillance authority.
A&A-02 → Art 4
CAIQ: Do staff who operate or oversee the system receive role-appropriate training, and are training records kept?
AI Act: Providers and deployers must ensure, to their best extent, a sufficient level of AI literacy of staff and other persons operating AI systems on their behalf, considering their technical knowledge, experience, education and the context of use. In application since 2 February 2025.
Evidence: Role-based AI-literacy matrix; dated per-person training records; refresher cadence tied to system or version changes.
SEF-03 → Art 26(5) + Art 73
CAIQ: Do you have an incident-response process, and do you notify affected parties and authorities within defined timeframes?
AI Act: Where the deployer has reason to consider that use may present a risk under Article 79(1), it must inform the provider/distributor and the market-surveillance authority without undue delay and suspend use; serious incidents are reported to the provider and, where applicable, the authority under Article 73.
Evidence: Incident-response runbook; suspension procedure; notification templates and a log evidencing timeliness of notification to provider and authority.
DSP-07 → Art 26(4)
CAIQ: Do you govern the quality and representativeness of input data used with the system, to the extent you control it?
AI Act: To the extent the deployer exercises control over the input data, it must ensure that input data is relevant and sufficiently representative in view of the intended purpose of the high-risk AI system.
Evidence: Data-governance policy; control inventory identifying which input fields the deployer (vs. provider) owns; documented data-quality checks on the controlled fields.
HRS-08 → Art 26(7)
CAIQ: Before deploying a system that affects staff in the workplace, do you inform workers' representatives and affected workers?
AI Act: Employers who are deployers of a high-risk AI system in the workplace must, before putting it into service or use, inform workers' representatives and the affected workers that they will be subject to its use.
Evidence: Works-council briefing minute; dated written notice to affected employees before go-live; intranet publication evidence.
GRC-11 → Art 26(11)
CAIQ: Where the system makes or assists decisions about individuals, are those individuals told they are subject to it?
AI Act: Deployers of Annex III high-risk systems that make, or assist in making, decisions related to natural persons must inform the persons concerned that they are subject to the use of the high-risk AI system.
Evidence: Standardised disclosure text embedded in decision communications (offer, rejection, review); audit trail showing the disclosure was sent.
DSP-14 → Art 26(9)
CAIQ: Do you run a data-protection impact assessment (DPIA) where personal data is processed, using provider-supplied information?
AI Act: Where applicable, deployers must use the information provided under Article 13 to comply with their DPIA obligation under Article 35 GDPR. The DPIA remains the deployer's responsibility.
Evidence: DPIA document explicitly referencing the provider's Article 13 instructions; DPO sign-off; periodic-review cadence.
STA-05 → Art 26(12)
CAIQ: Do you cooperate with regulators and produce records on request in relation to the systems you operate?
AI Act: Deployers must cooperate with the relevant competent authorities on any action those authorities take in relation to the high-risk AI system to implement the Regulation.
Evidence: Single point of contact identified; document-production playbook; legal-hold procedure for AI-system records.
AIS-12 → Art 50(4)
CAIQ: For AI-generated or manipulated media, do you disclose that the content is artificially generated?
AI Act: Deployers of an AI system that generates or manipulates image, audio or video content constituting a deep fake, or that generates text published to inform the public on matters of public interest, must disclose the artificial generation (with limited exemptions). Applies from 2 August 2026.
Evidence: Standard disclosure caption; editorial workflow check; exemption-rationale memo where an Article 50(4) exemption is relied upon.
IPY-03 → Art 26(6) (supporting)
CAIQ: Can you export your data and logs in a portable, machine-readable format if you change or exit the provider?
AI Act: Log retention under the deployer's control presupposes the deployer can actually obtain and hold those logs; portability of logs and records underpins the six-month retention and any authority request under Article 26(12).
Evidence: Documented export path (format + procedure) for logs and records; test export retained as evidence.
How to use this mapping
- For each high-risk AI system in your inventory, walk the rows and mark each as Present / Partial / Missing.
- Attach your existing CAIQ answer and the document reference in the evidence column — most rows reuse evidence you already produced for security due diligence.
- Missing rows become work-package tickets with an owner and target date. Partial rows either close or trigger an accepted-risk note signed by the executive owner.
- Re-run after every provider version upgrade, every Article 73 serious-incident report and at least annually.
Scope and caveats
- This mapping covers deployer obligations (Article 26) and shared transparency obligations (Article 50), plus the Article 4 AI-literacy overlay. Provider obligations (Articles 16-21), conformity assessment and Annex IV technical documentation are out of scope here.
- CAIQ IDs follow the CSA CAIQ v4.0.2 control-domain prefixes. Questions are paraphrased for length; always check against the official CAIQ workbook for exact wording.
- Article 50 transparency obligations apply from 2 August 2026. Article 4 AI-literacy has applied since 2 February 2025. The Annex III / Article 26 high-risk regime timing follows the Digital Omnibus deferral — confirm the current applicable date for your system before relying on any single row.
- This is a compliance aid, not legal advice. Applicability of each row depends on your specific deployment context.
Sources
- Regulation (EU) 2024/1689 (AI Act), Articles 4, 26, 50, 73, 79 and Annex III — eur-lex.europa.eu/eli/reg/2024/1689/oj
- Cloud Security Alliance — Consensus Assessments Initiative Questionnaire (CAIQ) v4.0.2, aligned to CCM v4.
- Regulation (EU) 2016/679 (GDPR), Articles 13, 35.
License — CC-BY-4.0. This crosswalk is published under the Creative Commons Attribution 4.0 International license. You are free to copy, adapt and redistribute it — including commercially — provided you give appropriate credit.
Suggested attribution: “CAIQ → EU AI Act mapping, PowerQuant ApS (Alexander Englund), powerquant.eu/caiq-ai-act-mapping — CC-BY-4.0.” Published 23 July 2026.
Note: PowerQuant ApS (CVR 46274067) supplies software and documentation for use in your internal compliance process — not legal advice. Author and editorial owner: Alexander Englund.
PowerQuant Module 1
Turn this mapping into a signed evidence pack: AI inventory, Article 4 register and the Article 26 / 50 evidence a buyer's CAIQ actually asks for — EU-hosted, Ed25519-signed, delivered in 5 working days. Fixed fee, no subscription.
Start Module 1