🤖AI Workload Compliance EU-AIACT-ART16Rule: AIACT-003high

AI Access Control

Description

High-risk AI systems must enforce least-privilege access (EU AI Act Article 16). EchelonGraph's K8s broad-RBAC detection flags ClusterRoleBindings to AI namespaces granting cluster-admin to non-system subjects.

⚠️ Risk Impact

Over-broad RBAC on AI namespaces = unaudited model swap = supply-chain attack against every consumer of the inference endpoint.

🔍 How EchelonGraph Detects This

AIACT-003Automated scanner rule

EchelonGraph's Tier 1 Cloud Scanner automatically checks for this condition across all connected cloud accounts. Violations are flagged as high-severity findings with remediation guidance.

🔧 Remediation

Audit ClusterRoleBindings on AI namespaces; remove cluster-admin grants; use namespace-scoped Roles with least-privilege.

🔗 Cross-Framework References

CIS-K8S-5.1.1EU-AIACT-ART17

Automate AI Workload Compliance EU-AIACT-ART16 compliance

EchelonGraph continuously monitors this control across all your cloud accounts.

Start Free →