How AI risk enters scoring
The fixed CVSS of 8.8, why it is higher than privacy's, and where the result surfaces.
Fixed CVSS, as in privacy
AI controls almost never have a matching CVE, so the normal criterion — looking severity up in the public vulnerability database — simply does not apply. The platform adopts here the same pattern already used for privacy: a value fixed by methodology.
All 66 AI controls carry a CVSS of 8.8. It is a declared methodology choice, not a figure inherited from an external source.
Why 8.8 and not 7.5
Privacy uses 7.5 because its risk is regulatory: the consequence of having no defined legal basis is a sanction, not a technical exploit. AI risk carries both natures — model manipulation and training-data poisoning are genuinely exploitable, and the regulatory layer sits on top of that.
8.8 puts it on par with the governance and platform-security families, which is where this kind of exposure sits on the scale.
Where the result surfaces
An AI control answered NO feeds category RC11, which appears in the risk charts alongside the other ten. The pillar's maturity enters the supplier's composite score, with its own weight configurable in your organization's methodology.
One consequence of the fixed CVSS is worth stating: since every control in the pillar weighs the same, the difference between one supplier and another in RC11 comes entirely from how many controls they fail, not which ones. In pillars with real CVSS, both factors combine.