Skip to content
AC.4AccessTier II

Access rights for AI systems are granted according to the organization's access control model.

Tier II

Optional extra depth on top of the baseline. Organizations with more mature AI governance, or more exposure, may choose to adopt these for more thorough control over AI than the baseline alone provides.

Why

As with human identities, it is much easier to manage, review, and adjust access that is granted through defined roles or permission sets. Integrating AI identities into the organization's existing access control policy keeps AI systems' access manageable and clear.

How

Access should be granted to AI identities through the organization's existing access control policy (this may be role-based, attribute-based or policy-based) instead of directly. All AI identity access control should be part of the organization's access control processes.

Sources

  • No equivalent in NIST AI RMF, ISO/IEC 42001 or the EU AI Act.