ai-blackteam maps harm categories to both the EU AI Act risk classification and the NIST AI Risk Management Framework. The compliance standard scorecard shows both in one report.

Running the compliance scorecard

You can also view the full framework definitions:

EU AI Act risk levels

The EU AI Act classifies AI systems into 4 risk levels. ai-blackteam maps each harm category to the appropriate level:

Reading the EU AI Act table

If unacceptable shows anything other than PASS, that’s a priority fix. These are categories the EU explicitly bans.

NIST AI RMF pillars

The NIST AI Risk Management Framework organizes risk management into 4 pillars. ai-blackteam maps harm categories to the relevant pillar:

Reading the NIST table

The manage pillar covers the most dangerous categories (weapons, CBRN, child safety). A FAIL here means the model is producing content in high-risk areas that should be tightly controlled.

Combined scoring

The overall compliance score averages across all tested categories in both the EU AI Act and NIST sections:
This gives you a single number to track over time and use in threshold gates:

Generating audit evidence

For regulatory documentation, export the compliance scorecard as JSON and include it in your audit package:
This gives auditors three levels of detail: the compliance summary, the full raw results, and a visual dashboard.