Tesi etd-08132026-230031 |
Link copiato negli appunti
Tipo di tesi
Tesi di laurea magistrale
Autore
HEREDIA, FACUNDO MARCOS
URN
etd-08132026-230031
Titolo
Operationalising Deployer Obligations under Article 26 of the EU AI Act: A Comparative Analysis of the NIST AI Risk Management Framework and ISO/IEC 42001
Dipartimento
GIURISPRUDENZA
Corso di studi
DIRITTO DELL'INNOVAZIONE PER L'IMPRESA E LE ISTITUZIONI
Relatori
.
relatore Favaro, Tamara
Parole chiave
- AI Governance
- Article 26
- Deployer Obligations
- EU AI Act
- High-Risk AI Systems
- ISO/IEC 42001
- NIST AI Risk Management Framework
- Regulatory Compliance
Data inizio appello
14/09/2026
Consultabilità
Non consultabile
Data di rilascio
14/09/2096
Riassunto (Inglese)
The EU AI Act imposes extensive obligations on deployers of high-risk AI systems under Article 26 yet offers little guidance on operationalising them. The NIST AI Risk Management Framework and ISO/IEC 42001 are two leading AI governance instruments worldwide, though neither was designed to secure AI Act compliance. This thesis asks to what extent these two instruments help operationalise the obligations under Article 26, applying a comparative methodology built around a five-step analysis, scoring each obligation's coverage on a four-point scale from silent to substantial, and its relation to the other instrument, as convergence, complementarity, divergence, or absence. ISO/IEC 42001 achieves coverage equal to or greater than the NIST AI RMF across all seventeen obligations examined. Divergence is the largest relationship category (53%, followed by Convergence 24%, Absence 18%, and Complementarity 6%) and the only kind ever produced by an unequal score; Convergence, Complementarity, and Absence occur exclusively at tied scores. Absence has two causes: two obligations presuppose a law-enforcement deployer category, reflecting the Act's differentiated actor taxonomy, while a third reflects an unrelated lifecycle-scope gap in both instruments' data provisions. ISO/IEC 42001's highest scores cluster around lifecycle-embedded duties such as instructions for use and continuous monitoring, each translatable into a defined, auditable control.
Riassunto (Italiano)
File
| Nome file | Dimensione |
|---|---|
Tesi non consultabile. |
|