Function: MAP
Is this legally binding?
Guidance. Voluntary guidance. Best practice, not obligation, until a contract or a regulator cites it.
Context-establishing function: categorising AI systems, identifying capabilities, usage contexts and associated risks and impacts.
What this connects to
18 relations. Official relations are the ones the source documents state; anything marked GAGE analysis is our reading, not an agency's.
Cited by1
- External frameworkNote: NIST AI 600-1 Generative AI Profile (July 2024)Guidance
GenAI Profile maps suggested actions to MAP subcategories
Mapped across from17
- SectionArea 2: Determining the Level of Human Involvement in AI-augmented Decision-makingGuidanceGAGE analysis, not official
Risk-based human involvement decisions presuppose MAP context and risk identification
- ObligationPerform threat modelling of agentic workflowsGuidanceGAGE analysis, not official
Agentic workflow threat modelling operationalises the MAP function
- InstrumentPersonal Data Protection Act 2012 (No. 26 of 2012)BindingGAGE analysis, not official
Data protection impact awareness supports MAP context and risk identification
- SectionAnnex A: AI Risk Impact Assessment TemplateGuidanceGAGE analysis, not official
The Annex A risk impact assessment template operationalises MAP-style context analysis
- External frameworkArticle 9: Risk management systemBindingGAGE analysis, not official
Risk management presupposes MAP context and risk identification
- External frameworkArticle 10: Data and data governanceBindingGAGE analysis, not official
Data governance requires mapped data contexts and risks
- External frameworkClause 4: Context of the organizationStandardGAGE analysis, not official
Organisational context parallels MAP context establishment
- External frameworkClause 6: PlanningStandardGAGE analysis, not official
AIMS risk planning corresponds to MAP risk identification
- ConceptRogue actionsGuidanceGAGE analysis, not official
Rogue-action risk identification is a MAP activity for agentic contexts
- ObligationSecure the supply chainGuidanceGAGE analysis, not official
Supply chain risk visibility is a MAP activity
- ObligationStep 1: Conduct a risk assessment focused on agentic AI security risksGuidance
Agentic risk assessment is MAP-function analysis for autonomous systems
- SectionPrinciple 5: Privacy and Data GovernanceGuidanceGAGE analysis, not official
Privacy and data governance risks are surfaced in MAP
- External frameworkArticle 6 + Annex III: High-risk AI systemsBindingGAGE analysis, not official
High-risk categorisation is a MAP-style context classification
- InstrumentPDPC Advisory Guidelines on Use of Personal Data in Generative AI (final, 20 Jul 2026)GuidanceGAGE analysis, not official
PDPC GenAI data guidance supports MAP-stage data risk identification
- SectionStage 1: Planning and DesignGuidanceGAGE analysis, not official
Planning-stage risk assessment is MAP-function work
- ObligationAssess the autonomy level of the systemGuidanceGAGE analysis, not official
Autonomy-level assessment is MAP context establishment for agents
- ObligationIdentify risks associated with the agent's capabilitiesGuidanceGAGE analysis, not official
Capability-centric risk identification is MAP analysis
Verified against the official source on 2026-08-17. GAGE is not affiliated with or endorsed by any agency named here, and nothing on this page is legal advice. How this is built and checked.