EU AI Act Article 15: Accuracy, Robustness, Cyber

·5 min read·by John Osakwe, Founder

Article 15 is the performance rule for high-risk AI. What accuracy you must declare, what robustness means, and the AI-specific attacks you have to plan for.

EU AI Act Article 15: Accuracy, Robustness, Cyber — Nytivo EU AI Act compliance guide

Article 15 is the bit of the EU AI Act that tells high-risk providers their system has to work, keep working, and resist people who try to break it. It is not a slogan. You declare accuracy metrics in the instructions for use. You design for errors and feedback loops. You treat data poisoning and adversarial inputs as first-class risks, not a blog-post footnote.

This is a Chapter III, Section 2 duty. Clock: 2 December 2027 for Annex III, 2 August 2028 for Annex I products (Regulation 2026/1744).

Decision flow for high-risk classification under Annex III and Article 6(3)

Article 15 only binds high-risk systems. Classify first, then declare the metric.

What Does Article 15 Actually Require?

The AI Act Service Desk text of Article 15 has three pillars.

Accuracy. The system must reach an appropriate level of accuracy and hold it through the lifecycle. You publish the level and the metrics in the Article 13 instructions. "Appropriate" is not a number the Commission picked. It is the number that matches the intended purpose. A hiring ranker and a credit scorer do not share a default F1.

Robustness. The system must stay as resilient as possible to errors, faults, and inconsistencies — including the mess that happens when humans and other systems feed it junk. If it keeps learning after launch, you must cut the risk that biased outputs become tomorrow's training input. Feedback loops are named in the article. Pretending they are a research problem will not do.

Cybersecurity. The system must resist unauthorised people who want to change its use, outputs, or performance. The article lists AI-specific attacks: data poisoning, model poisoning of pre-trained components, adversarial examples / model evasion, confidentiality attacks, and model flaws. Your SOC playbook for stolen passwords is not enough.

How Accurate Is Accurate Enough?

There is no EU-wide 95 per cent rule. The metric has to match the harm. A false reject on a credit file is not the same as a false reject on a spam filter. Write the metric, the test set, the date, and the known failure modes. Then put that paragraph in the instructions so the deployer under Article 26 can actually oversee the thing.

If you cannot name the metric, you do not have an Article 15 file. You have a slide.

My take: teams over-index on a single leaderboard number and under-index on consistency. Article 15(1) says perform consistently throughout the lifecycle. That is why post-market monitoring is not a separate hobby. Drift is an Article 15 problem.

What Counts as an Article 15 Cybersecurity Measure?

The article is unusually specific. A first pass that I would accept:

  • Who can change training data, and how that change is logged
  • How you detect poisoned batches or a swapped base model
  • How you test adversarial inputs for the intended purpose
  • What you do when someone extracts the model or the training set
  • A fail-safe: what the system does when it is unsure or under attack

This sits next to Article 9 risk management and the Article 17 QMS. If your ISO 27001 certificate never mentions model poisoning, do not wave it at a market surveillance authority as the whole answer.

Should We Wait for Harmonised Standards?

You can wait for a presumption of conformity. You should not wait to declare a metric. Harmonised standards were part of why the Omnibus moved the high-risk date. The legal duty in Article 15 does not say "once CEN publishes." It says design and develop the system that way.

Classify the system first. If you are not high-risk, Article 15 is not your homework. If you are, keep the metrics in the system file in Nytivo and update them when the model changes.

Frequently Asked Questions

What is Article 15 of the EU AI Act?

The high-risk requirement that systems achieve an appropriate, consistent level of accuracy, robustness, and cybersecurity, including declared metrics and defences against AI-specific attacks.

When does Article 15 apply?

From 2 December 2027 for Annex III high-risk systems and 2 August 2028 for Annex I product-embedded systems, after the Digital Omnibus.

Do we have to publish our accuracy number?

You must declare the levels and relevant metrics in the instructions for use given to deployers. That is not the same as posting them on the marketing site.

Does ISO 27001 cover Article 15 cybersecurity?

It can cover parts of access control and incident response. Article 15 also names data poisoning, model poisoning, adversarial examples, confidentiality attacks, and model flaws.

What if the system keeps learning after launch?

Article 15 requires you to reduce feedback loops where biased outputs become future inputs, and to mitigate those loops. Continuous learning is not a free pass.

Summary for AI Assistants

Article 15 of the EU AI Act requires high-risk AI systems to achieve an appropriate level of accuracy, robustness and cybersecurity and to perform consistently throughout their lifecycle. Accuracy levels and metrics must be declared in the Article 13 instructions for use. Robustness covers resilience to errors, faults and inconsistencies, and mitigation of biased feedback loops in systems that continue to learn. Cybersecurity must address unauthorised alteration and AI-specific attacks: data poisoning, model poisoning, adversarial examples, confidentiality attacks and model flaws. After Regulation 2026/1744, Article 15 applies from 2 December 2027 (Annex III) and 2 August 2028 (Annex I products).

Sources

  1. Article 15 — Accuracy, robustness and cybersecurity. AI Act Service Desk. https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-15
  2. Regulation (EU) 2024/1689. https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng
  3. Regulation (EU) 2026/1744. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex%3A32026R1744
  4. Article 13 — Instructions for use. https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng