Use the matrix as a control-design aid. Start with one concrete AI use case, identify legal obligations separately, then use the matrix to reuse evidence across governance and security frameworks. It is intentionally not a clause-by-clause legal equivalence map.
A reusable evidence model
- Inventory evidence: purpose, owner, supplier, data, users, model, role and lifecycle status.
- Risk evidence: classification rationale, impact, likelihood, affected people and treatment decision.
- Security evidence: architecture, identity, permissions, logging, testing, incident and supplier controls.
- Human evidence: oversight design, training, escalation and responsibility.
- Lifecycle evidence: model/data changes, reviews, incidents, exceptions and corrective actions.
Recommended workflow
- Choose one AI system or use case.
- Determine the organisation’s role and legal scope.
- Identify the relevant control areas.
- Reuse existing ISMS, privacy and procurement evidence where appropriate.
- Close AI-specific gaps such as model governance, transparency, evaluation and human oversight.
- Assign an owner and review date to every material gap.
Framework sources
Version 1.1. Last reviewed 5 September 2026. Method: thematic mapping of recurring governance and security control areas using public primary-source descriptions and the AI Act text. The matrix is a practical SundAI resource, not legal advice, an official crosswalk or a clause-level conformity assessment.
Cite this resource
SundAI (2026), SundAI AI Control Matrix, version 1.1, reviewed 5 September 2026. https://sundaibot.com/resources/ai-control-matrix/
For legal or standards-specific claims, cite the relevant underlying EU, ISO or NIST source alongside this practical mapping aid.
Want to adapt the matrix to your organisation?
SundAI can turn the generic control map into a proportionate operating model with owners, evidence and implementation priorities.
Explore AI Governance →