An Open Knowledge Graph-Based Approach for Mapping Concepts and Requirements between the EU AI Act and International Standards

Julio Hernandez,Delaram Golpayegani,Dave Lewis
2024-08-22
Abstract:The many initiatives on trustworthy AI result in a confusing and multipolar landscape that organizations operating within the fluid and complex international value chains must navigate in pursuing trustworthy AI. The EU's AI Act will now shift the focus of such organizations toward conformance with the technical requirements for regulatory compliance, for which the Act relies on Harmonized Standards. Though a high-level mapping to the Act's requirements will be part of such harmonization, determining the degree to which standards conformity delivers regulatory compliance with the AI Act remains a complex challenge. Variance and gaps in the definitions of concepts and how they are used in requirements between the Act and harmonized standards may impact the consistency of compliance claims across organizations, sectors, and applications. This may present regulatory uncertainty, especially for SMEs and public sector bodies relying on standards conformance rather than proprietary equivalents for developing and deploying compliant high-risk AI systems. To address this challenge, this paper offers a simple and repeatable mechanism for mapping the terms and requirements relevant to normative statements in regulations and standards, e.g., AI Act and ISO management system standards, texts into open knowledge graphs. This representation is used to assess the adequacy of standards conformance to regulatory compliance and thereby provide a basis for identifying areas where further technical consensus development in trustworthy AI value chains is required to achieve regulatory compliance.
Artificial Intelligence,Computers and Society
What problem does this paper attempt to address?
The problem that this paper attempts to solve is: how to establish a consistent mapping of concepts and requirements between the EU AI Act and international standards, so as to ensure that organizations can effectively achieve regulatory compliance, especially during the development and deployment of high - risk AI systems. Specifically, the paper focuses on the following aspects: 1. **Complexity of regulatory compliance**: - The EU AI Act focuses on meeting technical requirements to achieve regulatory compliance, but determining whether standard compliance can fully meet the requirements of the AI Act remains a complex challenge. - Differences in different definitions and requirements may lead to inconsistencies in compliance statements in different organizations, sectors, and applications, thus bringing regulatory uncertainty. 2. **Consistency of terms and requirements**: - There are differences in the conceptual definitions and usage methods between the EU AI Act and harmonized standards, which may affect the consistency of compliance statements. - Especially for small and medium - sized enterprises (SMEs) and public sector institutions, it is particularly important to rely on standard compliance rather than proprietary equivalents to develop and deploy compliant high - risk AI systems. 3. **Application of open knowledge graphs**: - To solve the above problems, the paper proposes an approach based on open knowledge graphs (OKG) for mapping relevant terms and requirements in regulations and standards. - This method can evaluate the sufficiency of standard compliance for regulatory compliance and identify areas where further technical consensus needs to be reached to achieve regulatory compliance. ### Main contributions of the paper - **Provide a simple and repeatable mechanism**: By mapping the normative statements in regulations and standards into open knowledge graphs, it helps organizations assess whether standard compliance is sufficient to meet regulatory requirements. - **Promote interoperability and transparency**: Open knowledge graphs built using W3C standards can increase the possibility of third - party review, thereby enhancing confidence in the completeness and accuracy of the mapping. - **Support multi - jurisdiction compliance management**: By mapping different standards and regulatory requirements, it can help AI providers manage the cost of maintaining compliance in multiple jurisdictions and support equivalent agreements for future trusted AI compliance. ### Conclusion The paper aims to solve the challenges of mapping concepts and requirements between the EU AI Act and international standards through the open knowledge graph approach, thereby providing organizations with a flexible, scalable, and transparent solution to ensure the regulatory compliance of their high - risk AI systems.