GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

AIG-027 AI Output Validation and Confidence Controls

Tier 2+AIPredictiveProviderDeployerGPAI Model ProviderManaged Service Provider

Description

AI systems that produce outputs acted upon by users or automated processes have defined acceptable output ranges or confidence thresholds. Outputs below the minimum confidence threshold trigger a defined fallback: human review queue, abstention, or escalation, not silent degradation. Output validation logic is documented and version-controlled. For classification tasks, threshold calibration is tested and its impact on precision/recall documented. Output ranges and thresholds are reviewed after any model update.

Rationale

AI systems that act on low-confidence outputs without disclosure or fallback create uncontrolled risk; confidence-gating is a structural quality control unique to probabilistic systems.

Applicability (9 profiles)

SaaS AI Providerstablerequiredcore
Enterprise AI Deployerstablerequiredsatisfied by provider

Threshold calibration and validation logic are the provider's. The deployer sets the fallback in its own workflow, in the AIG-022 oversight design, using the thresholds the instructions for use give.

GPAI Model Providerstablerequiredcore
High-Risk Provider (EU)stablerequiredrisk class duty

Art.15(1) requires an appropriate level of accuracy achieved by design and held consistently across the lifecycle and Art.13(3) requires the accuracy level and the metrics it was measured against to be stated in the instructions for use. Between them they turn the confidence threshold and the calibration result from an internal tuning parameter into a declared figure a deployer relies on and an authority can test the system against, which is also why a threshold changed after a model update has to move in the instructions.

Public Body Deployer (EU)stablerequiredsatisfied by provider

Threshold calibration and validation logic are the provider's. The deployer sets the fallback in its own workflow, in the AIG-022 oversight design, using the thresholds the instructions for use give.

DORA ICT Provider (EU)stablerequiredcore
NIS2 Cloud Provider (EU)stablerequiredcore

Framework Mappings (18)

AIS-10Output Validationpartial
TVM-13Guardrailspartial
EU-AI-Art.13.3Transparency — Mandatory Content of Instructions for Useinformative
EU-AI-Art.14.2Human Oversight — Capabilities Assigned to Oversight Personspartial
EU-AI-Art.15.1Accuracy, Robustness and Cybersecurity — Performance Standardspartial
EU-AI-Art.15.4Accuracy, Robustness and Cybersecurity — Benchmarks and Measurement Methodologiesinformative
EU-AI-Art.15.5Accuracy, Robustness and Cybersecurity — Declaration of Accuracy Levels and Metricsinformative
A.6.2.4AI system verification and validationpartial
AML.M0020Generative AI Guardrailsinformative
AML.M0033Input and Output Validation for AI Agent Componentsinformative
SI-15Information Output Filteringinformative
MG-2.2-001Deployed AI System Value Maintenance | MG-2.2-001partial
MG-3.2-008Pre-Trained Model Monitoring | MG-3.2-008informative
MS-2.6-004AI System Safety Risk Evaluation | MS-2.6-004full
MANAGE 2.4AI System Deactivation and Override Mechanismsinformative
MEASURE 2.3AI System Performance Measurementinformative
LLM07Misinformationfull
LLM10Improper Output Handlingpartial

Evidence (2)

configurationtechnicalautomated

Output validation configuration for AI systems, documenting defined confidence thresholds, fallback behaviour triggered below threshold, and version-controlled validation logic.

Example: Model serving configuration · fraud-classifier-prod (exported from BentoML or Seldon, YAML): confidence_threshold: 0.82, low_confidence_action: route_to_human_review_queue, abstain_below: 0.60, threshold_version: v3 (git commit abc123), last_reviewed: 2026-01-20

Test: Request the output validation configuration for a sample of AI systems acting on outputs. Verify: (1) confidence thresholds are defined per use case (not a single global default), (2) fallback behaviour is configured (human review queue, abstention, or escalation, not silent pass-through), (3) configuration is version-controlled with a dated review record, (4) for classification tasks, threshold calibration results are documented showing precision/recall impact, (5) thresholds were reviewed after the last model update.

logtechnicalautomated

Low-confidence output routing logs demonstrating that outputs below the defined confidence threshold are actually being routed to the defined fallback, rather than passed through silently.

Example: Datadog log query result for fraud-classifier-prod (last 30 days): 2,341 events with confidence < 0.82, action=human_review_queue; 0 events with confidence < 0.82 and action=auto_approve, confirms fallback routing is functioning

Test: Query AI event logs for low-confidence output routing events over a 30-day period. Verify: (1) events with confidence below the configured threshold are present in logs, (2) all such events show the correct fallback action (human review / abstention), (3) no events show auto-approval or silent pass-through below threshold, (4) the volume of low-confidence events is reviewed periodically to inform threshold calibration.

Questions (2)

boolean

Do AI systems whose outputs are acted upon have a defined acceptable output range or confidence threshold?

Net-new control: confidence-gating is a structural quality control unique to probabilistic AI systems, not addressed by existing frameworks at an operational level. Outputs acted upon without confidence validation create uncontrolled downstream risk.

select

What action is taken when an AI output falls below the defined confidence threshold?

Output is escalated with a mandatory review before action is takenOutput is routed to a human review queueThe system abstains and requests additional inputA warning flag is added to the output but no action is requiredOutput is passed through unchangedNo threshold or fallback is defined

Options run from strongest to weakest. Mandatory escalation, human review and abstention all meet the control. Passing a low-confidence output through unchanged does not, because nothing downstream can tell it apart from a confident one.